Privacy Policy
Last updated: 25 April 2026
T-3 Consultants Ltd (trading as VerifAI) is committed to protecting your personal data and being transparent about how we use it. This policy explains what we collect, why we collect it, who we share it with, and what rights you have.
1. Who we are
T-3 Consultants Ltd (trading as VerifAI) is the data controller for personal data processed through the VerifAI platform.
- Registered name: T-3 Consultants Ltd
- Trading as: VerifAI
- Registered in: England and Wales
- Company number: 13034838
- Registered address: 20-22 Wenlock Road, London, N1 7GU, United Kingdom
- ICO registration: registration with the UK Information Commissioner's Office is in progress; our registration number will be published here once it is issued.
- Privacy contact: privacy@verifai.t-3.ai
VerifAI is a B2B SaaS platform that helps procurement professionals search, compare, and evaluate AI vendors. We process personal data only to the extent necessary to provide this service.
2. What data we collect
Account and identity data
Provided by your organisation's administrator when your account is created:
- Full name
- Work email address
- Job title and role
- Organisation name
Usage data
Collected automatically when you use VerifAI:
- Search queries you enter
- Vendor comparisons you make
- Saved searches you create
- Features and pages you use within the platform
Technical data
Collected automatically to keep the platform secure and running:
- IP address
- Browser type and version
- Session identifiers (via httpOnly cookies — see Cookies)
- Login timestamps and authentication events
What we do not collect
- Payment card data or financial information
- Sensitive personal data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, or similar)
- Data from children or minors
- Advertising identifiers or tracking data
- Consumer data — VerifAI is an invite-only B2B platform
3. Why we collect it and our legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and managing your account | Name, email, role, organisation | Contract performance (Art 6(1)(b) UK GDPR) |
| Providing search and vendor comparison features | Search queries, comparison history, saved searches | Contract performance (Art 6(1)(b) UK GDPR) |
| Sending transactional emails (invitations, password resets) | Email address, invitation tokens | Contract performance (Art 6(1)(b) UK GDPR) |
| Authenticating your identity and managing sessions | Session cookies, login timestamps | Contract performance (Art 6(1)(b) UK GDPR) |
| Monitoring platform security and preventing fraud | IP address, authentication logs, audit logs | Legitimate interest (Art 6(1)(f) UK GDPR) |
| Monitoring platform performance and reliability | Application logs, performance metrics | Legitimate interest (Art 6(1)(f) UK GDPR) |
We do not rely on consent as a lawful basis for any processing. All processing is either necessary to provide the service you have contracted for, or based on our legitimate interest in keeping the platform secure and reliable.
4. How we use your data
We use your data to:
- Provide and maintain the VerifAI platform
- Authenticate your identity and manage your account
- Enable search, vendor comparison, and saved search features
- Send transactional emails — invitations and password resets only
- Monitor platform security and investigate suspicious activity
- Monitor platform performance and diagnose technical issues
- Comply with our legal obligations
What we do not do
- We do not sell your data to any third party, ever.
- We do not use your data to train AI models. Your search queries, comparisons, and account data are never used to train or fine-tune any AI or machine learning model.
- We do not share your data with advertisers. VerifAI has no advertising relationships.
- We do not use your data for profiling or automated decision-making. No decisions about you are made solely by automated means.
- We do not send marketing emails. The only emails we send are transactional — invitations and password resets.
Automated decision-making: VerifAI does not make automated decisions with legal or similarly significant effects about you. All decisions that affect your access to the platform or your rights are made by humans.
5. Who we share it with
We share your data only with the sub-processors listed below, and only to the extent necessary for them to provide their services to us. We have a Data Processing Agreement (DPA) in place with each sub-processor.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure — hosting, storage, compute | UK (eu-west-2, London) | All platform data |
| Amazon SES | Transactional email delivery | UK (eu-west-2, London) | Email addresses, invitation tokens |
| New Relic | Application performance monitoring and observability | US | Application logs, performance metrics, IP addresses — transferred under UK IDTA safeguards |
| Exa AI | AI-powered search capabilities | US | Search queries — transferred under UK IDTA safeguards |
| Amazon Bedrock | AI model inference for taxonomy enrichment (internal only) | EU (eu-west-1) | Taxonomy content only — no user personal data |
We will notify you at least 30 days before adding any new sub-processor.
We never sell your data to third parties. We do not share your data with any party for marketing, advertising, or any purpose not listed above.
6. Where your data is stored
Your data is stored primarily on AWS eu-west-2 (London, UK). This means your personal data stays within the UK by default.
Two sub-processors are based in the United States:
- New Relic — application monitoring data is transferred to the US under a UK International Data Transfer Agreement (IDTA), which provides equivalent protections to the EU Standard Contractual Clauses.
- Exa AI — search queries are transferred to the US under a UK IDTA.
We do not transfer your personal data outside the UK or EEA except as described above, and only with appropriate safeguards in place.
7. How long we keep it
| Data type | Retention period |
|---|---|
| Account data (name, email, role, organisation) | Duration of your account, plus 30 days after account closure |
| Search queries | 12 months from the date of the query, then anonymised or deleted |
| Saved searches | Duration of your account, plus 30 days after account closure |
| Authentication logs (login events) | 90 days |
| Audit logs (compliance-relevant actions) | 7 years (required for ISO 27001 and SOC 2 compliance) |
| Invitation tokens | 7 days from issue, or until used — whichever comes first |
| Password reset tokens | 1 hour from issue, or until used — whichever comes first |
| Backups | 30-day rolling window |
When your account is closed, we delete your personal data within 30 days. Please note that deleted data may persist in encrypted backups for up to 30 days before being overwritten.
8. Your rights
Under UK GDPR, you have the following rights in relation to your personal data:
Right of access — You can request a copy of the personal data we hold about you.
Right to rectification — You can ask us to correct inaccurate or incomplete data.
Right to erasure — You can ask us to delete your personal data. We will comply unless we have a legal obligation to retain it (for example, audit logs required for ISO 27001 compliance).
Right to data portability — You can request your data in a structured, machine-readable format so you can transfer it to another service.
Right to restriction — You can ask us to limit how we process your data while a dispute is being resolved.
Right to object — You can object to processing based on our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
How to exercise your rights
Email us at privacy@verifai.t-3.ai with your request. We will respond within one month (as required by UK GDPR). We may ask you to verify your identity before processing the request.
Right to complain
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
If you are based in the EU, you may also complain to your local supervisory authority.
9. Cookies
VerifAI uses only essential cookies. We do not use advertising cookies, analytics cookies, or any third-party tracking cookies.
| Cookie / Local Storage item | Purpose | Expiry |
|---|---|---|
| Access token (httpOnly cookie — JWT) | Authenticates your session | 15 minutes |
| Refresh token (httpOnly cookie — JWT) | Renews your session without requiring you to log in again | 7 days |
| cookie_consent (localStorage item) | Records your consent preference — stored in your browser's localStorage, not as a cookie | Persistent until cleared |
Both JWT tokens are stored as httpOnly cookies, which means they cannot be accessed by JavaScript. This is a deliberate security measure to protect against cross-site scripting (XSS) attacks.
When you first visit VerifAI, we ask for your consent to use cookies. You can withdraw your consent at any time using the button below.
Checking consent preferences…
10. Security
We take the security of your data seriously. Our security measures include:
- Encryption in transit: All data is encrypted using TLS 1.2 or higher.
- Encryption at rest: All stored data is encrypted.
- Access controls: Role-based access control (RBAC) ensures that staff can only access data they need to do their job.
- Audit logging: All significant actions are logged for security monitoring and compliance purposes.
- ISO 27001 alignment: Our information security management practices are aligned with ISO 27001.
- Cyber Essentials Plus: We hold Cyber Essentials Plus certification.
- SOC 2: We are working towards SOC 2 compliance.
Breach notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the ICO within 72 hours of becoming aware of the breach.
- Notify affected users without undue delay.
11. Changes to this policy
We will notify you by email at least 30 days before any material changes to this policy take effect. Material changes include changes to what data we collect, how we use it, who we share it with, or your rights.
Minor changes — such as updating contact details or correcting typographical errors — will be made without advance notice. The "last updated" date at the top of this page will always reflect the most recent version.
12. Contact us
For privacy enquiries, data subject requests, or Data Processing Agreement (DPA) requests:
Email: privacy@verifai.t-3.ai
Post:
T-3 Consultants Ltd (trading as VerifAI)20-22 Wenlock Road
London, N1 7GU
United Kingdom
We aim to respond to all privacy enquiries within 5 business days.
For formal data subject requests (access, erasure, portability, etc.), we will respond within one month as required by UK GDPR.
ICO: If you wish to make a complaint about our data handling, you can contact the ICO at ico.org.uk or on 0303 123 1113.