VH / VERAHELMPRIVACY NOTICE · EFFECTIVE 2026-07-21 · REV 1

MINIMUM PUBLIC-SITE DATA

Privacy boundary.

Effective July 21, 2026. This notice governs the public website and access-verification service. Separate customer projects require written data-handling and commercial terms.

1. What this site does not collect

The public site does not request or accept source code, confidential client files, passwords, recovery phrases, biometrics, payment-card numbers, medical data, regulated data, or proprietary workload inputs. Do not send those materials through this site or ordinary email.

2. Access and proposal-request records

When you request a code, the service processes your normalized email address, verification state, accepted terms version, acknowledged privacy version, optional marketing choice, selected service category, and timestamps. The verified proposal form uses that verified email as its only contact method and also processes the business context you provide, such as name, organization, role, optional website, requested service, decision, current state, desired outcome, success criteria, timing, procurement stage, expected data classification, named compliance requirements, and constraints.

Pending codes expire after ten minutes. Codes are stored only as keyed verification values and are subject to attempt and resend limits. Verified emails and proposal details are encrypted at rest; keyed values support lookup and abuse controls.

3. Sessions and security

Successful verification creates a random, short-lived session. The browser receives an HttpOnly, SameSite cookie; the service stores only a keyed token hash. Infrastructure providers necessarily process ordinary request metadata such as IP address, timing, browser headers, and security events.

4. Purposes

5. Service providers

The current public service uses Cloudflare for DNS, hosting, edge security, serverless request processing, human-verification support, and the access database. Resend delivers verification, proposal-confirmation, and internal intake-notification email.

Each provider processes limited data for its assigned function under its own terms. Verahelm does not collect payment-card details through the public Site.

6. Retention

Pending access records expire automatically. Active public sessions expire after 24 hours. Verified email, consent, and proposal-request records are retained only while needed for access, requested follow-up, security, legal obligations, or a documented business purpose. Paid-engagement retention, return, and deletion obligations are established in the applicable written agreement.

7. Marketing choice

Marketing is optional and is not required for access. Transactional access or security messages are separate. Every production marketing message must provide a working unsubscribe mechanism.

8. Deletion and questions

Verified users may select DELETE ACCESS to request deletion of the public access, consent, proposal-request, and current-session records held by this service, subject to records retained for security, legal, or contractual obligations. For privacy questions or a manual request, contact [email protected]. Identity verification may be required before acting on a request.

9. Security and limitations

Verahelm uses data minimization, encryption, hashed lookup values, bounded request bodies, access controls, and short-lived sessions. These measures reduce risk but cannot make any internet service absolutely secure. Additional security, incident, and notification duties for paid work are stated in the applicable written agreement.