Pritect Veil is operated by White Label Consultancy Group. This notice explains what White Label Consultancy AS does with personal data for which it decides the purpose, which means the website, an invitation to a trial we send you, your account, our correspondence with you and our billing records.
It deliberately does not cover the contents of the documents you process. That distinction is the most important thing on this page, so it is the first section.
1The two roles, and which one applies
1.1We are the controller for your relationship with us
When you browse this site, receive a trial invitation from us, sign up, sign in, email us or pay an invoice, we decide why that personal data is processed. For that data we are the data controller and this notice applies.
1.2We are a processor for what you upload
When you open a case and upload documents, your organisation decides why that personal data is processed and we act only on your instructions. For that data your organisation is the controller and we are the processor.
Our obligations there are set by the Data processing agreement, not by this notice. That is also where you will find what happens to the personal data of third parties who appear in your documents and who have no relationship with us at all.
1.3Who to write to
White Label Consultancy AS, Fjordalleen 16, 0250 Oslo, Norway, is the controller for everything in this notice. Contact privacy@pritect.ai or +45 71 74 74 54.
2What we collect and why
2.1When you visit the website
The consent banner on the public pages is Pritect Beacon, the consent platform from our own product family, and it loads on the public pages only. It keeps your decision in your browser, as the Cookie notice sets out, and sends a record of that decision and its timestamp to Beacon's consent log. The log is how we evidence the choice you made. To show the right banner, your browser also asks Beacon for its settings and for which privacy regime applies to your location. All of this runs in a Supabase project of Beacon's own, separate from the one this service uses, which Supabase hosts in Ireland, in the European Union.
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Technical data such as IP address, browser and device type | Serving the site securely, mitigating abuse | Legitimate interests in operating a functioning and secure website | For the duration of the request and in short-lived operational logs |
| Consent record and its timestamp | Evidencing the choice you made about cookies | Legal obligation under ePrivacy and Article 7(1) GDPR | 12 months |
2.2When you hold an account
When you create an organisation, we record against that organisation the campaign, the page of this site and the host of the referring site that brought you here, which describes the link you followed rather than you, and which is done without storing anything on your device.
When we erase your account, we delete your name, email address and authentication data. The audit record of what was done in your organisation's cases is kept, because it is the accountability evidence the product exists to produce, but it no longer identifies you.
You can erase your account yourself under Settings, Security, or ask us to erase it. If you are the only owner of an organisation, you must first make another member its owner or, if you are its only member, ask for the organisation to be closed.
If you do not, we erase your account automatically 90 days after your last membership of an organisation ends, which includes when the organisation is closed, or 90 days after you signed up if you never joined one.
Erasing your account also deletes your memberships. Our record of which version of our Terms of service was accepted on your organisation's behalf is kept until three years after closing your organisation completes, and our record of the version you accepted when you signed up until three years after your account is erased. Once your account is erased, neither identifies you.
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Name, work email, organisation, role | Creating and operating your account, tenant membership, authorisation | Performance of a contract | While you are a member of an organisation, then 90 days after your last membership ends, or 90 days after you signed up if you never joined one. Sooner if you erase your account or ask us to erase it |
| Authentication data including password hash and multi-factor secrets | Signing you in, and protecting the account | Performance of a contract, and legitimate interests in account security | For the life of the account |
| Audit records of actions you take in the product | Accountability, security investigation, and giving your organisation the evidence trail the product exists to produce | Legitimate interests in the integrity of a governance tool, and legal obligation | Six years. When your account is erased, the record keeps a random identifier in place of your account, and nothing in our systems links that identifier back to you. |
| Record of acceptance of our Terms of service: which version, its effective date and when it was accepted | Evidence that the Terms were accepted, and which version | Performance of a contract, Article 6(1)(b) GDPR | While the agreement it evidences lasts, then for three years, the general limitation period, then deleted. For an acceptance made for an organisation, that agreement ends when closing the organisation completes. For the acceptance you make when you sign up, it ends when your account is erased. Once your account is erased, the record no longer identifies you |
| Support correspondence | Answering you, and improving the product | Legitimate interests in supporting customers | Three years after the case closes |
2.3When your organisation pays us
Card details are entered directly with our payment processor and never reach our systems.
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Billing contact, billing address, VAT identifier | Invoicing, tax compliance | Performance of a contract, and legal obligation | As required by accounting law, generally five years |
| Usage counts such as documents processed | Metering, invoicing and plan enforcement | Performance of a contract | Six years |
2.4What we deliberately do not collect
- No advertising identifiers, no advertising tags, no cross-site tracking and no profiling of visitors on this domain. Analytics is the one measurement we run, on the public pages only and only if you consent to it, and clause 2.5 sets out exactly what that stores
- No document content in any log. Logs carry identifiers, counts, enumerated states and durations, and a continuous integration rule blocks raw string interpolation into a logger so this stays true
- No use of your data, or your documents, to train or improve any machine learning model, ours or anyone else's
- No special category data about you as a user is sought. What appears inside your documents is a matter for the Data processing agreement
2.5Analytics on the public pages
We measure how the public pages of veil.pritect.ai are used, so we can tell which of them answer a question and which do not.
Clicks on the sign-up and pricing calls to action are measured in the same way and under the same consent, and such a click carries the path of the page it happened on and, on the pricing page, the plan the card names, and nothing else.
This runs on the public pages and nowhere else. No page of the signed-in application, of sign-in or of onboarding loads a measurement tag, so nothing you do inside a case is measured. That is a property of where the tag is mounted in the code, not a setting that could be toggled by accident.
Nothing loads until you consent. The Google consent signals are set to denied before any script executes, and the analytics tag is requested only once the consent banner has recorded your agreement to the analytics category. If you decline, or never answer, the tag is never fetched and no analytics cookie is set.
The measurement is Google Analytics 4. Google Ireland Limited acts as our processor for it. Google Analytics runs on Google's global infrastructure, including the United States, so this data is transferred outside the European Economic Area, and the transfers are governed by the Standard Contractual Clauses that Google's own data processing terms incorporate. Advertising features are switched off in the configuration we send: no Google Signals, no advertising personalisation, no advertising identifiers, no user id and no linking of your visit across domains. We do not use this data for advertising and we do not sell it.
You can change your mind at any time through the cookie preferences link in the footer of any public page. Withdrawing sets the consent signal back to denied and switches the tag off for the rest of the visit, and any page you open afterwards does not load it at all.
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Pages viewed on the public site, the referring page, browser and device type, and an approximate location derived from the IP address of the request | Understanding which public pages are read and which are not, so the site can be improved | Your consent, Article 6(1)(a) GDPR, and consent under Article 5(3) of the ePrivacy Directive for the cookies themselves | Event data is retained in our Google Analytics property for 14 months |
| A randomly generated visitor and session identifier, held in the two Google cookies named in the Cookie notice | Telling a repeat visit from a new one, and counting the page views in one visit as one visit | Your consent, Article 6(1)(a) GDPR | 13 months from your last visit, then the cookie expires |
2.6When we invite you to a trial, before you hold an account
We may invite a person at an organisation to a trial of the service by email. We decide to send the invitation, and we choose the plan and how long the trial lasts. There is no form on this site that sends one, and we send an invitation only to a person who has asked us for a trial or who is already in contact with us about one.
We use your email address for one purpose only, which is delivering that invitation and managing it until it ends. We pass it to our email provider, Resend, which is named in the Sub-processor list, to send the message. We also store the address, encrypted, so that the members of our staff who send trial invitations can see which address each invitation went to, send it again or revoke it, and avoid inviting the same person twice. Nobody else can see it: it is not shown to any customer, and it is not written to our logs or to any audit record. Beside it we store a hash of the address: a fixed-length fingerprint, computed one way, that we can compare with an address but cannot turn back into one. The hash is how the invitation is tied to you. The link in the email starts a trial only for an account registered with the same address, so a link forwarded to anyone else does nothing.
The encrypted address is personal data. The hash is still personal data too, because anyone who already holds your address could compute the same fingerprint, and we treat both as personal data. When the invitation is accepted, revoked or expires, we erase the address and its hash together, so nothing we keep connects the invitation to your address. An invitation expires 14 days after it is sent, so neither is kept for longer than that. If you accept it, you then hold an account and clause 2.2 applies from that moment.
We do not add the address to any mailing list and we do not use it for anything else. If you do not want the trial, ignore the email and the invitation expires by itself, or write to privacy@pritect.ai and we will revoke it, which erases the address at once.
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Your email address, stored encrypted, and a hash of it | Delivering a trial invitation we have chosen to send you; letting the staff who send invitations see where each one went, send it again or revoke it, and avoid inviting you twice; and making sure only an account with the same address can use it | Legitimate interests, Article 6(1)(f) GDPR, in offering a trial of the service to a person at an organisation that has asked about it, and in managing that invitation properly while it is open. The interest is proportionate because the address is encrypted, is visible only to the staff who send invitations, is used for nothing else, and is erased with the invitation | The encrypted address and its hash until the invitation is accepted, revoked or expires, and no longer than 14 days. The address also in Resend's delivery records for the period its service keeps them |
3Who else sees it
3.1
Personal data covered by this notice may be shared with other companies in the group for administration, with the service providers listed in the Sub-processor list, and with professional advisers such as auditors and lawyers where necessary.
The analytics provider named in clause 2.5 receives website usage data only. It is not a sub-processor of the data you put into the product, and the Sub-processor list says so beside its entry: it is named there because one complete list is easier to check than a list with a provider left off it, and it is the only entry on that list which touches nothing belonging to a case.
Where your organisation configures the product to send event notifications to a system it chooses, those notifications carry identifiers, statuses and counts only, and never document content or anyone's name.
We disclose personal data to a public authority only where we are legally obliged to. Where we are permitted to tell you, we will.
3.2International transfers
The personal data this notice covers is processed in the European Union, including the consent log in clause 2.1, which Supabase hosts in Ireland. There is one qualification: the analytics in clause 2.5 runs on Google's global infrastructure, including the United States, under the Standard Contractual Clauses described there.
Where a provider's corporate structure creates the possibility of access from a third country, that access is governed by the European Commission's Standard Contractual Clauses together with technical measures. A copy of the safeguards is available on request.
4Your rights
4.1
For personal data where we are the controller, you have the rights below. We will respond within one month, and we will tell you if we need longer and why.
- To be informed about what we hold and what we do with it
- To access a copy of your personal data
- To have inaccurate or incomplete data corrected
- To have data erased where there is no overriding reason to keep it
- To restrict how we process it in defined circumstances
- To receive it in a portable, machine-readable form
- To object to processing based on legitimate interests, and to direct marketing at any time
- To withdraw consent at any time, without affecting processing that already happened
- To complain to a supervisory authority. Ours is the Norwegian Data Protection Authority, Datatilsynet, and you may also complain to the authority where you live or work
4.2
To exercise a right, write to privacy@pritect.ai. We may ask you to confirm your identity, and we will ask for no more than we need to do so.
4.3Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects on the basis of automated processing alone, and we do not profile you.
The product does use automated detection over documents, but that processing is instructed by our customer, is subject to human review of every flagged entity, and is governed by the Data processing agreement.
5Security and changes
5.1
We apply the technical and organisational measures described in Annex 2 of the Data processing agreement to personal data covered by this notice as well. A summary is on the security page.
5.2
If we change this notice materially, we will publish the new version with a new effective date and, where the change affects account holders, tell them before it takes effect.
White Label Consultancy AS also operates whitelabelconsultancy.com and pritect.ai. Personal data processed through those sites is covered by the notices published there.
Questions about this document
Write to legal@pritect.ai, or to privacy@pritect.ai for anything about personal data. White Label Consultancy AS, Fjordalleen 16, 0250 Oslo, Norway.