Privacy Policy

At VeraPiù, safeguarding privacy and securing educational and institutional data is foundational to everything we engineer. This policy details how we treat personal information across our platforms, web portals, mobile apps, and enterprise services.

Effective Date: September 24, 2026
GDPR & EU Data Regulation Compliant
Version 2.4 · Enterprise Master Standard

1. Introduction & Scope

VeraPiù ("we", "us", or "our") provides high-performance custom digital systems, modular educational technology platforms, and SaaS portals for schools, technical institutes, academies, and enterprise organizations.

This Privacy Policy applies to all personal data collected through our public website (verapiu.com), our educational portals (Student, Teacher, Family, and Admin portals), and our bespoke application deployments, unless covered under a distinct enterprise Data Processing Agreement (DPA).

When institutions deploy VeraPiù to manage school rosters, grades, and attendance, the institution serves as the Data Controller, and VeraPiù acts strictly as the Data Processor in accordance with Article 28 of the EU General Data Protection Regulation (GDPR).

2. Information We Collect

Depending on how you interact with VeraPiù, we collect the following categories of data:

Account & Identification Data

Full names, institutional email addresses, phone numbers, role assignments (e.g. Student, Teacher, Parent/Guardian, Administrator), and hashed authentication credentials.

Academic & Operational Data (Institutional Portal)

Gradebook entries, attendance and absence records, class assignments, course schedules, academic communications, and behavioral notations uploaded by designated institutional staff.

Technical & Telemetry Information

IP addresses, device identifiers, browser types, operating systems, session timestamps, and crash logs collected strictly for security auditing, fraud prevention, and performance monitoring.

3. Purposes of Processing

We process collected data exclusively for explicit, legitimate purposes:

  • Delivering modular educational portals and ensuring role-isolated access for authorized stakeholders.
  • Enabling real-time attendance alerts, automated notifications, and gradebook management.
  • Maintaining enterprise-grade infrastructure security, detecting unauthorized access, and upholding audit trails.
  • Providing dedicated institutional support, SLA guarantees, and platform maintenance.

We NEVER sell personal data, monetize student or institutional records, or use educational data for behavioral advertising.

5. Sub-processors & Cloud Infrastructure

We maintain strict oversight of our technology partners and cloud vendors. All infrastructure providers are bound by Data Processing Agreements and EU Standard Contractual Clauses (SCCs):

ProviderServiceData Location
Cloudflare, Inc.DDoS Mitigation, CDN & Edge SecurityGlobal / EU Edge
Supabase, Inc.Managed PostgreSQL & Real-time DatabaseFrankfurt, Germany (EU-Central)
Vercel, Inc.Serverless Edge & Next.js Application HostingFrankfurt, Germany (EU-Central)
Stripe Payments EuropePayment Gateway & Billing InvoicingDublin, Ireland (EU)

6. Data Retention & Erasure

Personal data is retained only for the duration necessary to satisfy institutional agreements, legal retention mandates, or legitimate operational requirements:

  • Institutional Records: Maintained for the active term of the institution's agreement plus 90 days following contract termination to enable secure migration.
  • Audit & Security Logs: Retained for a rolling period of 12 months for forensic and compliance auditing.
  • Billing Records: Retained for 10 years in compliance with EU statutory fiscal and tax regulations.

7. Your Rights Under GDPR

Under Chapter III of the GDPR, data subjects have significant legal rights regarding their personal information:

Right of Access (Art. 15): Request a copy of all personal data held about you.
Right to Rectification (Art. 16): Correct inaccurate or incomplete records.
Right to Erasure (Art. 17):Request deletion of data ("Right to be Forgotten").
Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
Right to Restriction (Art. 18): Restrict the processing of your personal information.
Right to Object (Art. 21): Object to processing carried out under legitimate interests.

8. Technical & Organizational Security

We maintain defense-in-depth security measures to protect data from accidental loss, unauthorized access, alteration, or disclosure:

Encryption: AES-256 encryption at rest; TLS 1.3 encryption in transit for all network traffic.
Multi-Tenant Isolation: Logical data segregation with Row-Level Security (RLS) enforced at the database kernel level.
Access Control: Zero-trust administrative policies, mandatory Multi-Factor Authentication (MFA), and least-privilege RBAC.

9. Contact & Data Protection Officer (DPO)

If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or require an institutional Data Processing Agreement, contact our Data Protection Office:

VeraPiù Data Protection Office

Email: dpo@verapiu.com

Legal Inquiries: legal@verapiu.com

You also retain the right to lodge a complaint with your local EU supervisory authority (e.g., Garante per la protezione dei dati personali in Italy or your relevant national authority).

VeraPiù Legal & Data Protection Office

For formal data subject requests, law enforcement inquiries, or customized Data Processing Addendums (DPA) for your school or enterprise:

General Legal Counsellegal@verapiu.com
Data Protection Officer (DPO)dpo@verapiu.com