HomePrivacy Policy

Legal

Privacy Policy

Document Reference: GEO-SPEC-001 · System Architecture Version: 2.0 (Pure Prompt Inversion Model) · Effective Date: July 3, 2026

1. General Introduction and Data Protection Framework

VerifiedLayer (“VerifiedLayer”, “We”, “Us”, or “Our”) is committed to protecting the privacy of individuals who interact with our platform. This Privacy Policy (“Policy”) describes how we collect, use, disclose, and safeguard information when you visit verifiedlayer.tech (the “Site”), claim a vendor profile, write a review, or access our authenticated user and vendor dashboards.

This Policy applies across all global privacy frameworks, including the European Union General Data Protection Regulation (“GDPR”), the United Kingdom GDPR, and state-level United States privacy regulations (such as the California Consumer Privacy Act, “CCPA”, as amended by the CPRA).

2. Scope and Exclusion of Public Corporate Entity Data

2.1: Corporate Metadata vs. Personal Data

VerifiedLayer generates its AI Visibility Index by orchestrating programmatic, structured prompts across independent third-party AI platforms. These prompts instruct AI engines to analyze public, enterprise-level signals, including but not limited to public API registries, open engineering documentation schemas, developer repositories, user-generated public forum discussions, and Large Language Model citation ratios.

2.2: Processing Exclusion

Because these signals consist exclusively of public-domain, non-confidential corporate properties and aggregate market awareness, they do not relate to an identified or identifiable natural person. Therefore, Public Corporate Entity Data does not constitute Personal Data (Personally Identifiable Information, or “PII”) under applicable data protection laws. VerifiedLayer does not store, parse, or manage localized PII data dumps within its algorithmic index.

3. Information We Collect (User and Account-Level Data)

We collect and process personal data directly from you when you interact with the Site or create an account. This is divided into the following categories:

3.1: Account Registration & Profile Data

  • Reviewers/Buyers/Evaluators: When you create an evaluation account or access software directories, we collect your name, corporate email address, professional title, and company name.
  • Vendor Representatives: To claim a company profile page (/company/{slug}), you must provide your legal name, verified corporate email address, corporate phone number, and administrative credentials. We may also collect technical verification tokens (such as DNS TXT record strings or corporate registration proofs) to validate your authorization.

3.2: System Interaction & Technical Data

When you navigate the Site, our servers automatically log technical metadata transmitted by your browser. This includes:

  • Internet Protocol (IP) address, browser type, browser version, operating system, and routing logs.
  • Device identifiers, time-stamp logs, and interaction paths (e.g., specific leaderboards, metrics, or vendor comparisons viewed).

4. Legal Basis for Processing (GDPR / UK GDPR Compliance)

If you reside within the European Economic Area (EEA) or the United Kingdom, we process your Personal Data under the following lawful bases:

  • Performance of a Contract / Explicit Value Exchange: To provide access to premium B2B benchmarking intelligence. When you request third-party corporate details or alternative product matrices, our performance of that data delivery is conditioned on your explicit, contractual agreement to share your corporate contact metrics with our partner ecosystem.
  • Consent: Where you explicitly click and accept our contextual intent data-sharing gate to view restricted comparison profiles.
  • Legitimate Interests: To maintain the security, structural integrity, and functional health of our programmatic prompt-orchestration pipelines.

5. How We Process and Share Your Information

5.1: Third-Party AI Engine Orchestration

To generate our monthly Confidence Scores, your corporate profile identifier (e.g., Company Name, public documentation URL) is included inside our structured prompt streams transmitted via APIs to third-party AI platforms (including Anthropic Claude, OpenAI GPT, Google Gemini, and Microsoft Copilot). These third-party processors handle this corporate data in accordance with their respective developer enterprise privacy commitments, which strictly restrict the use of API-transmitted data for foundational model training.

5.2: The Explicit Data Gate and Contextual Lead Generation Model

VerifiedLayer functions as a professional data exchange network. We do not broadcast generalized marketing directories or open user-contact lists. Our system enforces a strict, Hard-Gated Contextual Intent Trigger:

  • The Sharing Condition: Access to granular competitive analytics, comparison scorecards, tier breakdowns, and internal profile information belonging to other tracked companies is structurally locked by default.
  • The Affirmative Consent Action: VerifiedLayer will unlock and display alternative or competing corporate profiles if and only if you click to accept and explicitly agree to share your professional account credentials (name, corporate email, job title, and the context of your query) as an active business lead with the specific Vendor whose profiles or data sets you are attempting to review.
  • System Masking: If you decline to click-to-share, your personal data is completely masked, and no commercial transmission occurs. Concurrently, our platform will withhold the requested alternative or competing corporate data layers.

5.3: Infrastructure Service Providers

We share user-level metadata and account logs with trusted operational sub-processors who assist us in delivering the Site. These include cloud infrastructure hosts, database management platforms, identity verification services, and security firewalls. All such providers are bound by strict Data Processing Agreements (DPAs).

5.4: Statutory Disclosures

We may disclose your Personal Data if required to do so by applicable international laws, court subpoenas, or valid regulatory enforcement requests.

6. U.S. State Privacy Rights & the Right to Opt-Out (CCPA/CPRA)

6.1: Notice of Commercial “Sale” and “Sharing”

Under the California Consumer Privacy Act (CCPA) and subsequent revisions, the monetization of your professional account history and contact metrics via the explicit consent gate described in Section 5.2 is classified as a “Sale” or “Sharing” of personal information for commercial purposes.

6.2: The Right to Opt-Out and Access Tiers

If you are a resident of California or another U.S. state providing equivalent consumer privacy regulations, you retain the right to opt-out of the sale or sharing of your personal data. You can execute this right by choosing “Decline / Opt-Out” at the interface prompt gate or via our footer link: “Do Not Sell or Share My Personal Information”.

Operational Effect of Opt-Out: In full compliance with California Civil Code § 1798.125, choosing to opt-out or refusing to authorize data sharing will never cause you to be denied general access to the Site. However, because the delivery of specialized competitor scorecards, advanced comparison metrics, and private data layers is fundamentally contingent upon a value-exchange lead-generation mechanism, refusing to share your data will mean the platform remains locked for those premium features. This structural distinction represents a standard differential pricing and service utility framework tied directly to the value provided by your consumer data.

7. International Data Transfers

VerifiedLayer operates globally, and our operational infrastructure is primarily located in the United States and the European Union. If you are accessing the Site from the EEA, UK, or Switzerland, your account-level Personal Data may be transferred to, stored, and processed in the United States.

To ensure an adequate level of data protection, we utilize standard contractual clauses (“SCCs”) approved by the European Commission and the UK Information Commissioner’s Office (ICO) with all infrastructure service providers and receiving corporate buyers handling international personal data flows.

8. Data Security and Retention Policy

8.1: Security Protocols

We implement enterprise-grade technical and organizational security controls designed to prevent the unauthorized alteration, loss, exposure, or destruction of your account data. This includes TLS encryption for all data in transit, AES-256 encryption at rest for internal account databases, and strict role-based access management.

8.2: Retention Limits

  • Active Accounts: Personal data collected to maintain your authenticated account is retained for as long as your account remains active on the platform.
  • Deactivated Accounts: Upon an explicit request for account deletion, we delete or anonymize all associated account credentials, access tokens, and administrative data within thirty (30) business days, unless applicable statutory regulations require extended preservation. Lead data previously routed or sold to third-party software vendors prior to your deletion request is subject to the retention and privacy policies of those independent corporate entities.

9. Your Data Protection Rights

Depending on your geographic location, you possess specific statutory rights regarding your personal information. These include:

  • The Right to Access: You have the right to request copies of the personal data we hold about you.
  • The Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or incomplete.
  • The Right to Erasure (The Right to Be Forgotten): You can request that we erase your personal account data under certain conditions.
  • The Right to Object/Restrict Processing: You have the right to object to our legitimate interest processing or request restriction of your data.
  • The Right to Data Portability: You can request that we transfer your collected data to another organization or directly to you in a machine-readable format.

To exercise any of your privacy rights, please submit a formal request to our privacy team at privacy@verifiedlayer.ai.

10. Privacy Rights and the Logic of Entity Data Persistence

10.1: Profile Deletion Requests

As established in Section 2, the public-domain corporate scores and category leaderboards displayed on VerifiedLayer do not constitute Personal Data (PII).

10.2: Data Persistence

Accordingly, while an individual Vendor Representative may request the absolute deletion of their personal user login or authentication account, such requests do not oblige VerifiedLayer to remove, take down, delete, or alter the public corporate entity profile page (/company/{slug}) or its historical score rankings (/history/*). The objective algorithmic index remains a persistent, public database asset of VerifiedLayer.

11. Policy Modifications and Updates

VerifiedLayer reserves the right to amend this Privacy Policy at any time to reflect updates in global data protection regulations, changes to our automated prompt orchestration frameworks, or modifications to our lead-generation mechanisms. When changes are made, the “Effective Date” at the top of this document will be updated. Your continued use of the platform after updates are published constitutes your acceptance of the revised policy terms.