Legal

Privacy Policy

Last updated: 1 March 2026

Verispect Ltd, registered in the United Kingdom, is the data controller for personal data processed through the Netract platform. This policy explains what we collect, why, who we share it with, and how long we keep it.

1. Data we collect

Account data: name, email address, phone number, role, and authentication identifiers.

Business and KYB data:legal entity name, registration number, registered address, business sector, beneficial ownership details, and supporting verification documents.

Transaction data: invoice metadata, client names and contact details you enter, collection references, settlement notifications, balances, conversion rates, fees, and payout beneficiary identifiers.

Technical data: IP address, device and browser information, session timestamps, and audit logs of actions performed in the platform.

2. Why we process it

To provide the service under our contract with you; to meet legal obligations including anti-money-laundering, counter-terrorist-financing, sanctions screening, and record-keeping duties; to prevent and detect fraud and abuse as a matter of legitimate interest; and to secure, monitor, and improve the platform.

3. Who we share it with

We share the minimum necessary data with our regulated banking partners and licensed regional payment gateways in order to issue collection accounts, reconcile settlements, and execute payouts. We also use identity-verification providers for KYB and KYC checks, cloud infrastructure and database providers for hosting, and email delivery providers for transactional notifications.

We disclose data to regulators, law enforcement, or courts where legally required. We do not sell personal data, and we do not use it for third-party advertising.

4. International transfers

Because the platform is cross-border by design, data may be transferred outside the United Kingdom and the European Economic Area. Such transfers are protected by appropriate safeguards, including UK International Data Transfer Agreements or Standard Contractual Clauses with an accompanying transfer risk assessment.

5. Retention

Compliance and transaction records are retained for a minimum of five years after the end of the business relationship or the date of the transaction, whichever is later, as required by financial record-keeping rules. Account and technical data are retained for as long as your account is active and for a reasonable period afterwards for dispute resolution and audit purposes.

6. Security

Data is encrypted in transit and at rest. Access to production systems is restricted on a least-privilege basis, ledger writes are append-only and auditable, and inbound settlement callbacks are verified using HMAC signatures before any balance is affected.

7. Your rights

Subject to legal limits, you may request access to your personal data, request correction or deletion, object to or request restriction of processing, and request portability. Where processing is necessary to meet anti-money-laundering or record-keeping obligations, we may be unable to delete records on request.

You may lodge a complaint with the UK Information Commissioner's Office if you believe your data has been handled improperly.

8. Contact

Privacy enquiries and data-subject requests can be sent to the Verispect Ltd data protection contact at privacy@netract.io. We respond within one calendar month.