Privacy Policy

Last updated: 22 June 2026

Overview

Vernitium (Singapore UEN 53523325J) builds and operates software for small and medium-sized enterprises (SMEs) that consolidates business data, automates manual processes, and applies AI to generate insights. This Privacy Policy explains what data we collect, how we use it, and how we protect it.

The policy is divided into two parts. Part A covers this public website. Part B covers the Vernitium application that our business clients log into, including how we handle data accessed through Google services. Our users are our business clients themselves; the application is used by and on behalf of the client whose account it belongs to.

Part A • This Website

Information We Collect

We collect only the information you provide directly through our contact form: your name, email address, phone number, and a message. We do not employ analytics tools, tracking pixels, or third-party cookies on this site.

How We Use Your Information

Information submitted via the contact form is used solely to respond to your enquiry and, where applicable, to schedule a discovery call. We do not sell, rent, or share your personal data with any third party for marketing or commercial purposes.

Who Has Access

Submissions are accessible to Vernitium founders and any future internal staff only. The sole third-party processor involved is EmailJS, which transmits form submissions to our inbox. For details on how EmailJS handles data in transit, refer to the EmailJS Privacy Policy.

Data Storage & Retention

Submissions are delivered directly to our inbox and are not stored in any external database. We retain emails for as long as is necessary to fulfil the relevant enquiry. You may request deletion of your data at any time.

Cookies

This site does not use cookies or any form of local tracking storage.

Part B • The Vernitium Application

Scope of This Part

This part applies to the Vernitium application made available to our business clients. Because our engagements are business to business, the application is operated by the client organisation that owns the account, and access is granted by that organisation to its own authorised users. Each client is responsible for the data it chooses to connect to the application.

Google User Data We Access

Where a client chooses to connect their Google account, the application requests access to the client's Gmail data through Google's OAuth consent flow. We access only the data necessary to provide the features the client has enabled, for example, reading and organising the messages required to consolidate information and generate the insights the client has requested. We request the narrowest Gmail scope that supports those features.

We also request basic sign-in information through Google (your name, email address, and profile identifier) for the sole purpose of authenticating you and creating your account. This information is not used for any other purpose.

Access is granted only after the user explicitly authorises it on Google's consent screen, and it can be revoked by the user at any time through their Google Account permissions.

How We Use Google User Data

Gmail data accessed through the application is used solely to provide and improve the user-facing features the client has enabled within their own account, such as consolidating data, automating manual workflows, and generating insights for that same client. We do not use Google user data for advertising, and we do not sell it.

We do not transfer Google user data to any third party except as necessary to provide or improve these features at the client's direction, to comply with applicable law, or as part of a merger or acquisition with prior notice. Google user data is never shared with other clients.

AI Processing of Google User Data

Some features apply artificial intelligence to generate insights from a client's data. Where Gmail data is processed by AI, it is used only to produce results for that same client within the application. We do not use Google user data to develop, train, or improve generalised or independent AI or machine-learning models. Any AI processing occurs strictly to deliver the requested feature back to the user whose data it is.

Each client chooses which AI provider processes their data. The available options are OpenAI, Anthropic, or a self-hosted model that Vernitium operates on its own infrastructure. Gmail data is sent to an AI provider only when the client actively uses a feature that requires it, and only the data needed for that specific request is sent. When a client selects OpenAI or Anthropic, that data is sent to the chosen provider solely to generate the requested result, and its processing by that provider is governed by the provider's own terms, which the client reviews and accepts before using the application. When a client selects the self-hosted option, all AI processing takes place on infrastructure we control and no Gmail data is sent to an external AI provider.

Service Providers

We rely on a limited set of service providers to operate the application, namely Amazon Web Services (AWS) and Cloudflare for cloud hosting and storage, and the AI providers described above. These providers process Google user data only on our instructions and on the client's behalf, solely to deliver the enabled features, and are contractually bound to handle the data in a manner consistent with this policy and the Limited Use requirements. We do not otherwise transfer Google user data to any third party.

International Transfers

Our service providers, including those named above, may store or process data on infrastructure located outside Singapore, such as in the United States. Where Google user data is transferred overseas, we take reasonable steps to ensure it receives a standard of protection comparable to that required under the Singapore Personal Data Protection Act 2012, including through contractual safeguards with our providers.

Limited Use Disclosure

Vernitium's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage, Retention & Deletion

We store the minimum Google user data required to provide the enabled features, and we retain it only for as long as the client's account remains active and the relevant feature is in use. When a user revokes access, or a client terminates their engagement, the associated Google user data is deleted within 30 days. You can revoke the application's access at any time from your Google Account permissions. A user or client may also request deletion of their Google user data at any time by contacting us at team@vernitium.com. Following deletion, residual copies may remain in our encrypted backups for a limited period and are removed in the ordinary course of our backup rotation.

Security

Google user data is encrypted in transit and at rest. Access within Vernitium is restricted to authorised personnel on a need-to-know basis, and we apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data. In the event of a data breach that is likely to result in significant harm, we will notify the affected individuals and the relevant authorities as required under applicable law.

Children's Data

The Vernitium application is a business tool intended for use by organisations and their authorised personnel. It is not directed to, and we do not knowingly collect personal data from, individuals under the age of 16.

General

Your Rights Under the PDPA

Under the Singapore Personal Data Protection Act 2012, you have the right to request access to, correction of, or deletion of personal data we hold about you. To exercise any of these rights, or to raise any concern about how we handle personal data, you may contact our Data Protection Officer at team@vernitium.com. We will respond within a reasonable timeframe.

Modifications

We reserve the right to update this policy from time to time. The date at the top of this page reflects the most recent revision. Continued use of the website or application following any changes constitutes acceptance of the revised policy.

Contact

For any questions about this Privacy Policy or our data practices, contact us at team@vernitium.com.