Privacy Policy

Privacy Policy

Last updated: 25 April 2026

T-3 Consultants Ltd (trading as VerifAI) is committed to protecting your personal data and being transparent about how we use it. This policy explains what we collect, why we collect it, who we share it with, and what rights you have.


1. Who we are

T-3 Consultants Ltd (trading as VerifAI) is the data controller for personal data processed through the VerifAI platform.

  • Registered name: T-3 Consultants Ltd
  • Trading as: VerifAI
  • Registered in: England and Wales
  • Company number: 13034838
  • Registered address: 20-22 Wenlock Road, London, N1 7GU, United Kingdom
  • ICO registration: registration with the UK Information Commissioner's Office is in progress; our registration number will be published here once it is issued.
  • Privacy contact: privacy@verifai.t-3.ai

VerifAI is a B2B SaaS platform that helps procurement professionals search, compare, and evaluate AI vendors. We process personal data only to the extent necessary to provide this service.


2. What data we collect

Account and identity data

Provided by your organisation's administrator when your account is created:

  • Full name
  • Work email address
  • Job title and role
  • Organisation name

Usage data

Collected automatically when you use VerifAI:

  • Search queries you enter
  • Vendor comparisons you make
  • Saved searches you create
  • Features and pages you use within the platform

Technical data

Collected automatically to keep the platform secure and running:

  • IP address
  • Browser type and version
  • Session identifiers (via httpOnly cookies — see Cookies)
  • Login timestamps and authentication events

What we do not collect

  • Payment card data or financial information
  • Sensitive personal data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, or similar)
  • Data from children or minors
  • Advertising identifiers or tracking data
  • Consumer data — VerifAI is an invite-only B2B platform

PurposeData usedLegal basis
Creating and managing your accountName, email, role, organisationContract performance (Art 6(1)(b) UK GDPR)
Providing search and vendor comparison featuresSearch queries, comparison history, saved searchesContract performance (Art 6(1)(b) UK GDPR)
Sending transactional emails (invitations, password resets)Email address, invitation tokensContract performance (Art 6(1)(b) UK GDPR)
Authenticating your identity and managing sessionsSession cookies, login timestampsContract performance (Art 6(1)(b) UK GDPR)
Monitoring platform security and preventing fraudIP address, authentication logs, audit logsLegitimate interest (Art 6(1)(f) UK GDPR)
Monitoring platform performance and reliabilityApplication logs, performance metricsLegitimate interest (Art 6(1)(f) UK GDPR)

We do not rely on consent as a lawful basis for any processing. All processing is either necessary to provide the service you have contracted for, or based on our legitimate interest in keeping the platform secure and reliable.


4. How we use your data

We use your data to:

  • Provide and maintain the VerifAI platform
  • Authenticate your identity and manage your account
  • Enable search, vendor comparison, and saved search features
  • Send transactional emails — invitations and password resets only
  • Monitor platform security and investigate suspicious activity
  • Monitor platform performance and diagnose technical issues
  • Comply with our legal obligations

What we do not do

  • We do not sell your data to any third party, ever.
  • We do not use your data to train AI models. Your search queries, comparisons, and account data are never used to train or fine-tune any AI or machine learning model.
  • We do not share your data with advertisers. VerifAI has no advertising relationships.
  • We do not use your data for profiling or automated decision-making. No decisions about you are made solely by automated means.
  • We do not send marketing emails. The only emails we send are transactional — invitations and password resets.

Automated decision-making: VerifAI does not make automated decisions with legal or similarly significant effects about you. All decisions that affect your access to the platform or your rights are made by humans.


5. Who we share it with

We share your data only with the sub-processors listed below, and only to the extent necessary for them to provide their services to us. We have a Data Processing Agreement (DPA) in place with each sub-processor.

Sub-processorPurposeLocationData processed
Amazon Web Services (AWS)Cloud infrastructure — hosting, storage, computeUK (eu-west-2, London)All platform data
Amazon SESTransactional email deliveryUK (eu-west-2, London)Email addresses, invitation tokens
New RelicApplication performance monitoring and observabilityUSApplication logs, performance metrics, IP addresses — transferred under UK IDTA safeguards
Exa AIAI-powered search capabilitiesUSSearch queries — transferred under UK IDTA safeguards
Amazon BedrockAI model inference for taxonomy enrichment (internal only)EU (eu-west-1)Taxonomy content only — no user personal data

We will notify you at least 30 days before adding any new sub-processor.

We never sell your data to third parties. We do not share your data with any party for marketing, advertising, or any purpose not listed above.


6. Where your data is stored

Your data is stored primarily on AWS eu-west-2 (London, UK). This means your personal data stays within the UK by default.

Two sub-processors are based in the United States:

  • New Relic — application monitoring data is transferred to the US under a UK International Data Transfer Agreement (IDTA), which provides equivalent protections to the EU Standard Contractual Clauses.
  • Exa AI — search queries are transferred to the US under a UK IDTA.

We do not transfer your personal data outside the UK or EEA except as described above, and only with appropriate safeguards in place.


7. How long we keep it

Data typeRetention period
Account data (name, email, role, organisation)Duration of your account, plus 30 days after account closure
Search queries12 months from the date of the query, then anonymised or deleted
Saved searchesDuration of your account, plus 30 days after account closure
Authentication logs (login events)90 days
Audit logs (compliance-relevant actions)7 years (required for ISO 27001 and SOC 2 compliance)
Invitation tokens7 days from issue, or until used — whichever comes first
Password reset tokens1 hour from issue, or until used — whichever comes first
Backups30-day rolling window

When your account is closed, we delete your personal data within 30 days. Please note that deleted data may persist in encrypted backups for up to 30 days before being overwritten.


8. Your rights

Under UK GDPR, you have the following rights in relation to your personal data:

Right of access — You can request a copy of the personal data we hold about you.

Right to rectification — You can ask us to correct inaccurate or incomplete data.

Right to erasure — You can ask us to delete your personal data. We will comply unless we have a legal obligation to retain it (for example, audit logs required for ISO 27001 compliance).

Right to data portability — You can request your data in a structured, machine-readable format so you can transfer it to another service.

Right to restriction — You can ask us to limit how we process your data while a dispute is being resolved.

Right to object — You can object to processing based on our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.

How to exercise your rights

Email us at privacy@verifai.t-3.ai with your request. We will respond within one month (as required by UK GDPR). We may ask you to verify your identity before processing the request.

Right to complain

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

If you are based in the EU, you may also complain to your local supervisory authority.


9. Cookies

VerifAI uses only essential cookies. We do not use advertising cookies, analytics cookies, or any third-party tracking cookies.

Cookies and local storage items used by VerifAI
Cookie / Local Storage itemPurposeExpiry
Access token (httpOnly cookie — JWT)Authenticates your session15 minutes
Refresh token (httpOnly cookie — JWT)Renews your session without requiring you to log in again7 days
cookie_consent (localStorage item)Records your consent preference — stored in your browser's localStorage, not as a cookiePersistent until cleared

Both JWT tokens are stored as httpOnly cookies, which means they cannot be accessed by JavaScript. This is a deliberate security measure to protect against cross-site scripting (XSS) attacks.

When you first visit VerifAI, we ask for your consent to use cookies. You can withdraw your consent at any time using the button below.

Checking consent preferences…


10. Security

We take the security of your data seriously. Our security measures include:

  • Encryption in transit: All data is encrypted using TLS 1.2 or higher.
  • Encryption at rest: All stored data is encrypted.
  • Access controls: Role-based access control (RBAC) ensures that staff can only access data they need to do their job.
  • Audit logging: All significant actions are logged for security monitoring and compliance purposes.
  • ISO 27001 alignment: Our information security management practices are aligned with ISO 27001.
  • Cyber Essentials Plus: We hold Cyber Essentials Plus certification.
  • SOC 2: We are working towards SOC 2 compliance.

Breach notification

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the ICO within 72 hours of becoming aware of the breach.
  • Notify affected users without undue delay.

11. Changes to this policy

We will notify you by email at least 30 days before any material changes to this policy take effect. Material changes include changes to what data we collect, how we use it, who we share it with, or your rights.

Minor changes — such as updating contact details or correcting typographical errors — will be made without advance notice. The "last updated" date at the top of this page will always reflect the most recent version.


12. Contact us

For privacy enquiries, data subject requests, or Data Processing Agreement (DPA) requests:

Email: privacy@verifai.t-3.ai

Post:

T-3 Consultants Ltd (trading as VerifAI)
20-22 Wenlock Road
London, N1 7GU
United Kingdom

We aim to respond to all privacy enquiries within 5 business days.

For formal data subject requests (access, erasure, portability, etc.), we will respond within one month as required by UK GDPR.

ICO: If you wish to make a complaint about our data handling, you can contact the ICO at ico.org.uk or on 0303 123 1113.