Legal
Privacy Policy
Last updated: 1 March 2026
Verispect Ltd, registered in the United Kingdom, is the data controller for personal data processed through Netract. This policy explains what we collect, why, who we share it with, and how long we keep it.
1. Data we collect
Account data: name, email address, phone number, role, and authentication identifiers.
Business and KYB data:legal entity name, registration number, registered address, business sector, beneficial ownership details, and supporting verification documents.
cross-channel activity activity metadata: commit SHAs, pull request links, associated timestamps, GitHub organisation and repository identifiers, and human client sign-off flags. Netract never reads, parses, or retains the contents of your proprietary source code, only public activity metadata delivered via standard GitHub webhooks is processed.
Procurement data: invoice metadata, client names and contact details you enter, procurement references, settlement notifications, balances, fee calculations, and formal local bank Foreign Currency Retention Account details.
Technical data: IP address, device and browser information, session timestamps, and audit logs of actions performed in the platform.
2. Why we process it
To provide the service under our contract with you; to compile the Compliance Passport audit trail mapping engineering delivery markers to procurement data; to meet legal obligations including anti-money-laundering, counter-terrorist- financing, sanctions screening, and record-keeping duties; to prevent and detect fraud and abuse as a matter of legitimate interest; and to secure, monitor, and improve the platform.
3. Who we share it with
We share the minimum necessary data with our Tier-1 licensed banking partners (including Airwallex and Wise) in order to execute settlement and final-mile clearing on their own licences. We also use identity-verification providers for KYB checks, cloud infrastructure and database providers for hosting, and email delivery providers for transactional notifications.
We disclose data to regulators, law enforcement, or courts where legally required. We do not sell personal data, and we do not use it for third-party advertising.
4. International transfers
Because the platform serves cross-border B2B procurement relationships, data may be transferred outside the United Kingdom and the European Economic Area. Such transfers are protected by appropriate safeguards, including UK International Data Transfer Agreements or Standard Contractual Clauses with an accompanying transfer risk assessment.
5. Retention
Compliance Passport audit archives, the unalterable machine-readable PDF/JSON records of engineering delivery markers, sign-off, and procurement data, are retained for a minimum of five years after the end of the business relationship or the date of the underlying record, whichever is later, as required by financial record-keeping rules. Account and technical data are retained for as long as your account is active and for a reasonable period afterwards for dispute resolution and audit purposes.
6. Security
Data is encrypted in transit and at rest. Access to production systems is restricted on a least-privilege basis, Compliance Passport writes are append-only and auditable, and inbound GitHub and banking-partner webhooks are verified using signature checks before any record is affected.
7. Your rights
Subject to legal limits, you may request access to your personal data, request correction or deletion, object to or request restriction of processing, and request portability. Where processing is necessary to meet anti-money-laundering or record-keeping obligations, we may be unable to delete records on request.
You may lodge a complaint with the UK Information Commissioner's Office if you believe your data has been handled improperly.
8. Contact
Privacy enquiries and data-subject requests can be sent to the Verispect Ltd data protection contact at privacy@netract.io. We respond within one calendar month.
