VERIGAGE - PRIVACY POLICY
https://verigage.ai/privacy
Last Updated: July 13, 2026
Verigage LLC ("Verigage," "we," "our") operates an AI-powered compliance platform for life sciences companies at verigage.ai (the "Platform"). This Privacy Policy describes how we collect, use, disclose, and protect information in connection with the Platform. It applies to all users of the Platform and visitors to our website.
If your organization has a Platform Subscription Agreement ("PSA") with Verigage, the PSA's data processing provisions govern our handling of data submitted through the Platform. This Privacy Policy supplements but does not override the PSA.
1. Information We Collect
1.1 Account Information. When your organization's administrator creates your account, we collect your name, email address, job title, and organizational role. We collect this from your administrator or from you at registration.
1.2 Platform Data. Data submitted to the Platform by authorized users on behalf of their organization ("Customer Data") is governed by the PSA between your organization and Verigage. Customer Data may include HCP names, titles, affiliations, specialties, compensation rates, engagement details, and compliance documentation. We process Customer Data as a data processor on your organization's behalf and per their instructions. Your organization, as the data controller, is responsible for ensuring it has a lawful basis for the Customer Data it submits and for providing any legally required notices to individuals, including HCPs, whose information it processes through the Platform.
1.3 Usage Data. We automatically collect aggregated, de-identified information about how the Platform is used, including feature interactions, session duration, page views, and performance metrics. Usage Data does not identify you or your organization and does not include Customer Data.
1.4 Device and Log Data. We collect standard log information when you access the Platform, including IP address, browser type, operating system, referring URL, and access timestamps. We use this for security monitoring, troubleshooting, and service improvement.
1.5 Cookies and Similar Technologies. We use strictly necessary cookies to maintain your session and authentication state. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. If this changes, we will update this policy and provide notice.
2. How We Use Information
We use the information we collect for the following purposes:
(a) Provide the Platform. Process Customer Data to generate AI-powered compliance analyses, maintain workflows, and produce audit trails, per the PSA.
(b) Operate and improve. Maintain, secure, monitor, and improve Platform performance and reliability using Usage Data and log data.
(c) AI analysis improvement. Use De-Identified Data (as defined in the PSA) to evaluate and refine the accuracy of the Platform's AI-assisted analyses, including prompt engineering and validation testing, and to develop industry benchmarks, subject to the Suppression Rules described in Section 4 below. Verigage does not train or fine-tune third-party AI models on Customer Data.
(d) Support. Respond to support requests and communicate service-related information.
(e) Security. Detect, prevent, and respond to security incidents, fraud, and abuse.
(f) Legal compliance. Comply with applicable laws and respond to lawful legal process.
3. Data We Do Not Collect
The Platform is not designed for and must not be used to process: (a) protected health information (PHI) as defined under HIPAA; (b) patient-level clinical data; (c) Social Security numbers; (d) financial account numbers or payment card data; or (e) data subject to ITAR, EAR, or classified information restrictions.
HCP professional information (names, titles, affiliations, specialties, compensation rates) processed in the context of engagement compliance review is business data, not regulated health information, and is permitted on the Platform. Verigage is not a HIPAA covered entity or business associate, and does not offer or maintain Business Associate Agreements.
4. De-Identified Data and Benchmarks
Verigage may create de-identified data from Customer Data for use in AI model improvement and industry benchmarking. De-identified data must satisfy all three of the following requirements before use outside any single customer's account:
(a) Minimum population: based on data from at least five separate contributing customers.
(b) Concentration cap: no single customer's data exceeds 25% of any statistic's weighted contribution.
(c) Aging: data is at least three months old from the underlying engagement event.
De-identified data is never used to re-identify any individual, customer, or specific HCP engagement. Benchmark products derived from de-identified data are available only to Verigage platform subscribers and are not sold to the general public.
5. How We Share Information
5.1 Service Providers. We share Customer Data, account information, and log data with the subprocessors listed at verigage.ai/subprocessors, each of which processes data on our behalf as necessary to operate the Platform. We also use service providers that support our business operations but do not process Customer Data, including GitHub, Inc. (source code hosting and CI/CD), Google LLC (business communications and support operations), and Cal.com, Inc. (demo scheduling).
5.2 Your Organization. We share your account activity and Platform usage with your organization's administrators as necessary for them to manage the Platform subscription.
5.3 Legal Requirements. We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of Verigage, our users, or others.
5.4 No Sale. We do not sell, rent, or share personal information or Customer Data for advertising, marketing, or any purpose unrelated to providing the Platform.
6. Data Retention
Customer Data is retained during the term of your organization's PSA and for a ninety (90) day export period following termination. After the export period, Customer Data is deleted within thirty (30) days unless your organization has requested extended regulatory retention (up to seven years for compliance records, subject to the PSA). Account information is retained as long as your account is active, then deleted upon request or within ninety (90) days of account closure. Usage Data and log data are retained for up to twelve (12) months for operational purposes, then aggregated or deleted.
7. Security
We implement technical and organizational safeguards including encryption at rest (AES-256) and in transit (TLS 1.2+), row-level database security, role-based access controls, and security assessments including application-level vulnerability review. No system is completely secure, and we cannot guarantee absolute security, but we are committed to protecting your data using industry-standard measures.
8. AI Processing Transparency
The Platform uses AI models provided by Anthropic, PBC to analyze compliance data submitted by your organization. When you use AI Features, your inputs are transmitted to Anthropic's API for processing under Anthropic's commercial API terms. AI outputs are returned to the Platform for your review. Information about Anthropic's data handling practices is available at anthropic.com/legal/commercial-terms.
Certain Platform computations (aggregate spend, FMV range checks, frequency counts, regulatory thresholds) are performed by deterministic logic without AI involvement. These calculations are not transmitted to any third-party AI provider.
9. Your Rights
Depending on your jurisdiction, you may have rights regarding your personal information, including the right to access, correct, delete, or port your data, and the right to opt out of certain processing. Because Verigage processes Customer Data on behalf of your organization (as a data processor), requests regarding Customer Data should be directed to your organization's administrator, who can instruct us accordingly.
For requests regarding your individual account information, or to exercise rights under the California Consumer Privacy Act (CCPA) or other applicable state privacy laws, contact us at privacy@verigage.ai. We will respond within the timeframes required by applicable law.
We do not sell personal information as defined under the CCPA. We do not process personal information for targeted advertising. We do not discriminate against individuals who exercise their privacy rights.
10. Children
The Platform is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will delete it promptly.
11. International Transfers
The Platform and all subprocessors are hosted in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States. Where required by applicable data protection law, cross-border transfer mechanisms are addressed in the agreement between Verigage and your organization. For organizations subject to GDPR or other international data protection laws, transfer mechanisms will be addressed in the agreement between Verigage and your organization where applicable.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy at verigage.ai/privacy and, for registered users, by email notification at least thirty (30) days before the effective date of material changes. Your continued use of the Platform after the effective date constitutes acceptance.
13. Contact
Verigage LLC
Privacy inquiries: privacy@verigage.ai
General inquiries: support@verigage.ai