VH / VERAHELMPRIVACY NOTICE · EFFECTIVE 2026-07-21

MINIMUM PUBLIC-SITE DATA

Privacy boundary.

Effective July 21, 2026. This notice governs the public website and access-verification service. Separate customer projects require written data-handling and commercial terms.

1. What this site does not collect

The public site does not request or accept source code, confidential client files, passwords, recovery phrases, biometrics, payment-card numbers, medical data, regulated data, or proprietary workload inputs. Do not send those materials through this site or ordinary email.

2. Access records

When you request a code, the service processes your normalized email address, verification state, accepted terms version, acknowledged privacy version, optional marketing choice, and timestamps. Service options appear after the initial request; the selected service category is recorded only when the email code is verified.

Pending codes expire after ten minutes. Codes are stored only as keyed verification values and are subject to attempt and resend limits.

3. Sessions and security

Successful verification creates a random, short-lived session. The browser receives an HttpOnly, SameSite cookie; the service stores only a keyed token hash. Infrastructure providers necessarily process ordinary request metadata such as IP address, timing, browser headers, and security events.

4. Purposes

5. Service providers

The current public service uses Cloudflare for DNS, hosting, edge security, serverless request processing, human-verification support, and the access database. Resend provides transactional email.

Each provider processes limited data for its assigned function under its own terms. Verahelm does not currently collect payment-card details through the public Site.

6. Retention

Pending access records expire automatically. Active public sessions expire after 24 hours. Verified email and consent records are retained only while needed for access, requested communications, security, legal obligations, or a documented business purpose. Paid-engagement retention, return, and deletion obligations are established in the applicable written agreement.

7. Marketing choice

Marketing is optional and is not required for access. Transactional access or security messages are separate. Every production marketing message must provide a working unsubscribe mechanism.

8. Deletion and questions

Verified users may select DELETE ACCESS to request deletion of the public access record and current session. For privacy questions or a manual request, contact [email protected]. Identity verification may be required before acting on a request.

9. Security and limitations

Verahelm uses data minimization, encryption, hashed lookup values, bounded request bodies, access controls, and short-lived sessions. These measures reduce risk but cannot make any internet service absolutely secure. Additional security, incident, and notification duties for paid work are stated in the applicable written agreement.