Privacy Policy
Last updated: 17 July 2026
This Privacy Policy explains how NOETIKOS LTD ("we", "us"), registered at 66 Paul Street, London, EC2A 4NA, United Kingdom, processes personal data in connection with the Verimetriq platform ("Service").
1. Data we process
Account data (we act as controller)
- Name, email address and password hash of registered users.
- Organisation name and settings.
- Billing records (processed by Stripe; we do not store card numbers).
- Technical logs necessary to operate and secure the Service (timestamps, IP addresses, actions).
Connected-source data (we act as processor)
- Marketing metrics retrieved from sources you connect (e.g. GA4, Google Ads, Search Console, Merchant Center, CRM) using your own credentials, solely on your instructions.
- API credentials and OAuth tokens you provide — stored encrypted (AES-256-GCM) and never shared between organisations.
2. Purposes and legal bases
- Providing the Service (performance of contract).
- Billing and accounting (legal obligation, performance of contract).
- Security, abuse prevention and service improvement (legitimate interest).
- We do not sell personal data and do not use your analytics data for advertising.
3. Where data is stored
Service data is stored in PostgreSQL databases hosted on dedicated infrastructure in the European Union. Encrypted backups follow the same residency.
4. Third parties
- Google APIs — we retrieve data from Google services you connect, under your OAuth consent; usage complies with the Google API Services User Data Policy, including Limited Use requirements.
- Stripe — payment processing.
- Infrastructure providers under data-processing agreements.
5. Retention
- Account data — for the life of the account and up to 12 months after closure, unless a longer period is required by law.
- Connected-source metrics — per your plan's history depth; deleted upon organisation deletion.
- Credentials — deleted immediately when you remove a connection or delete the organisation.
6. Your rights (GDPR)
You may request access, rectification, erasure, restriction, portability, or object to processing, and lodge a complaint with a supervisory authority. Contact us at support@verimetriq.com.
7. Security
Encryption in transit (TLS) and at rest for credentials, tenant isolation at the application and database level, least-privilege access, and audit logging.
8. Changes
We will notify registered users of material changes to this Policy by email or in-product notice before they take effect.