Pritect Veil is operated by White Label Consultancy Group. This notice explains what White Label Consultancy AS does with personal data for which it decides the purpose, which means the website, your account, our correspondence with you and our billing records.
It deliberately does not cover the contents of the documents you process. That distinction is the most important thing on this page, so it is the first section.
1The two roles, and which one applies
1.1We are the controller for your relationship with us
When you browse this site, sign up, sign in, email us or pay an invoice, we decide why that personal data is processed. For that data we are the data controller and this notice applies.
1.2We are a processor for what you upload
When you open a case and upload documents, your organisation decides why that personal data is processed and we act only on your instructions. For that data your organisation is the controller and we are the processor.
Our obligations there are set by the Data processing agreement, not by this notice. That is also where you will find what happens to the personal data of third parties who appear in your documents and who have no relationship with us at all.
If you are a member of the public whose personal data appears in a document a customer uploaded, we are that customer's processor. Direct your rights request to them. If you do not know who they are, write to us and we will pass the request on without disclosing the document contents.
1.3Who to write to
White Label Consultancy AS, Fjordalleen 16, 0250 Oslo, Norway, is the controller for everything in this notice. Contact privacy@pritect.ai or +45 71 74 74 54.
2What we collect and why
2.1When you visit the website
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Technical data such as IP address, browser and device type | Serving the site securely, mitigating abuse | Legitimate interests in operating a functioning and secure website | For the duration of the request and in short-lived operational logs |
| Consent record and its timestamp | Evidencing the choice you made about cookies | Legal obligation under ePrivacy and Article 7(1) GDPR | 12 months |
2.2When you hold an account
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Name, work email, organisation, role | Creating and operating your account, tenant membership, authorisation | Performance of a contract | For the life of the account, then 90 days |
| Authentication data including password hash and multi-factor secrets | Signing you in, and protecting the account | Performance of a contract, and legitimate interests in account security | For the life of the account |
| Audit records of actions you take in the product | Accountability, security investigation, and giving your organisation the evidence trail the product exists to produce | Legitimate interests in the integrity of a governance tool, and legal obligation | Six years |
| Support correspondence | Answering you, and improving the product | Legitimate interests in supporting customers | Three years after the case closes |
2.3When your organisation pays us
Card details are entered directly with our payment processor and never reach our systems.
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Billing contact, billing address, VAT identifier | Invoicing, tax compliance | Performance of a contract, and legal obligation | As required by accounting law, generally five years |
| Usage counts such as documents processed | Metering, invoicing and plan enforcement | Performance of a contract | Six years |
2.4What we deliberately do not collect
- No analytics, no advertising identifiers, no cross-site tracking on this domain
- No document content in any log. Logs carry identifiers, counts, enumerated states and durations, and a continuous integration rule blocks raw string interpolation into a logger so this stays true
- No use of your data, or your documents, to train or improve any machine learning model, ours or anyone else's
- No special category data about you as a user is sought. What appears inside your documents is a matter for the Data processing agreement
3Who else sees it
3.1
Personal data covered by this notice may be shared with other companies in the group for administration, with the service providers listed in the Sub-processor list, and with professional advisers such as auditors and lawyers where necessary.
We disclose personal data to a public authority only where we are legally obliged to. Where we are permitted to tell you, we will.
3.2International transfers
Processing takes place in the European Union. Where a provider's corporate structure creates the possibility of access from a third country, that access is governed by the European Commission's Standard Contractual Clauses together with technical measures. A copy of the safeguards is available on request.
4Your rights
4.1
For personal data where we are the controller, you have the rights below. We will respond within one month, and we will tell you if we need longer and why.
- To be informed about what we hold and what we do with it
- To access a copy of your personal data
- To have inaccurate or incomplete data corrected
- To have data erased where there is no overriding reason to keep it
- To restrict how we process it in defined circumstances
- To receive it in a portable, machine-readable form
- To object to processing based on legitimate interests, and to direct marketing at any time
- To withdraw consent at any time, without affecting processing that already happened
- To complain to a supervisory authority. Ours is the Norwegian Data Protection Authority, Datatilsynet, and you may also complain to the authority where you live or work
4.2
To exercise a right, write to privacy@pritect.ai. We may ask you to confirm your identity, and we will ask for no more than we need to do so.
4.3Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects on the basis of automated processing alone, and we do not profile you.
The product does use automated detection over documents, but that processing is instructed by our customer, is subject to human review of every flagged entity, and is governed by the Data processing agreement.
5Security and changes
5.1
We apply the technical and organisational measures described in Annex 2 of the Data processing agreement to personal data covered by this notice as well. A summary is on the security page.
5.2
If we change this notice materially, we will publish the new version with a new effective date and, where the change affects account holders, tell them before it takes effect.
White Label Consultancy AS also operates whitelabelconsultancy.com and pritect.ai. Personal data processed through those sites is covered by the notices published there.
Questions about this document
Write to legal@pritect.ai, or to privacy@pritect.ai for anything about personal data. White Label Consultancy AS, Fjordalleen 16, 0250 Oslo, Norway.