veriastra_
Legal

GDPR & Compliance

Last updated August 19, 2026

Veriastra, operated by White Cats Software, LLC, processes data that can be personal (emails, phone numbers, IP addresses). This page summarises how we support GDPR/UK-GDPR and similar regimes. It complements our Privacy Policy, Subprocessors list, and Acceptable Use Policy.

Controller / processor roles

For data you submit through the API about third parties (e.g. your customers), you are the controller and Veriastra is a processor acting on your instructions. You must ensure you have a lawful basis (e.g. legitimate interest, consent) before submitting such data. For our own website and account data, Veriastra is the controller.

Lawful basis

We process lookup inputs to perform the service you request (contract / your instructions) and maintain aggregate reputation and abuse-prevention signals (legitimate interest, balanced against individual rights via minimisation and retention limits).

Data subject rights

Individuals may request access, rectification, erasure, restriction, portability, or object to processing. Send requests to [email protected]. If we processed the data on a customer's behalf, we will refer the request to that customer (controller) and assist as processor.

A phone erasure request deletes the number from the live store we control: reputation, cache, ordinary jobs, dashboard history, hashed reverse-lookup audit rows, and leftover logs that still carry it. It does not delete a do-not-call legal record we hold for a customer under 16 CFR 310.5, a job still inside its retainUntil window, or a public government list we did not collect from the requester. The operator response lists each slice. Rotated backups are not rewritten; they age out within seven days. Details are in the Privacy Policy.

Data minimisation & retention

We retain the minimum needed: result cache is short-lived, bulk job data ~30 days unless a job is on a later retainUntil clock, IP reputation ~180 days, and we run automated purges on this schedule. Do-not-call records stay five years because the statute says so. We do not sell personal data or use lookup inputs for advertising.

Sub-processors

We publish the parties that may process personal data on our behalf, including infrastructure, sign-in, payment, and optional data providers, on the Subprocessors page, along with how we notify you of changes. Lookups also query public infrastructure (DNS, DNSBLs, SMTP, public numbering data) only as needed to answer a request.

International transfers & security

Data is encrypted in transit (TLS). Where data crosses borders, we rely on appropriate safeguards. API keys are stored hashed and the Service runs isolated with least-privilege access.

Your obligations as controller

Because you choose what to submit and why, GDPR puts the controller duties on you: having a lawful basis, covering validation by a service provider in your privacy notice, honouring the rights of the people in your data, and not sending us special-category data. Our Acceptable Use Policy sets out the purposes we will not support at all, whatever basis you claim.

Data Processing Agreement (DPA)

A DPA is available for business customers who need one, covering processing scope, our instructions-only commitment, confidentiality, security measures, sub-processor terms, assistance with data-subject requests, breach notification, and deletion or return at the end of the term. Request it at [email protected] and we will send it for signature.

Personal data breach

If a breach affects personal data we process on your behalf, we will notify you without undue delay once we have confirmed it, with what we know about scope, likely consequences, and the steps we are taking, so you can meet your own 72-hour obligation. Reports and questions: [email protected].