Privacy Policy
Last updated: 23 June 2026
This policy explains what we do with the email address you give us when you request private access to VerityIQ, why we collect it, how long we keep it, and the rights you have under the EU/UK General Data Protection Regulation (GDPR).
Contents
1. Who we are
VerityIQ is a product operated by ARCsoft Kabushiki Kaisha (株式会社 ARCsoft) (“we”, “us”, “our”). For the purposes of the GDPR, ARCsoft Kabushiki Kaisha is the data controller of the personal data described in this policy.
Data controller: ARCsoft Kabushiki Kaisha (株式会社 ARCsoft), a company incorporated in Japan and based in Tokyo. You can reach us about privacy at hello@verityiq.io. Our full registered address is available on request.
2. What personal data we collect
When you submit the waitlist form to request access, we collect and store:
- Your email address — the only piece of information you actively enter.
- Submission timestamp — the date and time you signed up.
- The page path you submitted from (for example /).
- Your browser's user-agent string — basic technical info about the browser/device that made the request.
- Country — derived from your IP address by our infrastructure provider at the moment of the request. We do not store your IP address itself.
We do not ask for, or intentionally collect, any special-category data (such as health, ethnicity, or political opinions). Please don't include such information in the email field.
3. Why we collect it, and our legal basis
We collect your email for one purpose: to contact you about private access to VerityIQ — to let you know when a spot opens, and to share information directly related to that access.
Our legal basis under Article 6(1) GDPR is your consent: you actively choose to submit your email to join the waitlist. You can withdraw that consent at any time (see “Your rights” below); withdrawing it does not affect anything we did lawfully before you withdrew.
4. How we use it
- To email you about private access and onboarding when a place becomes available.
- To prevent spam and abuse of the signup form (for example, a hidden honeypot field that we discard).
We do not use your email for unrelated marketing, we do not sell or rent it, and we do not share it with advertisers or data brokers.
5. Who we share it with
We keep the data in our own account on our infrastructure provider; we do not pass it to third-party mailing-list or marketing platforms. The only third party that processes it on our behalf (a data processor) is:
- Cloudflare, Inc. — provides our website hosting, serverless functions, key-value storage (where the waitlist is held), and network/CDN. Cloudflare processes the data under its data processing terms. See Cloudflare's privacy policy at cloudflare.com/privacypolicy.
We may also disclose data if required to by law, regulation, or a valid legal request.
6. Where your data is stored & international transfers
The waitlist is stored on Cloudflare's globally distributed infrastructure, which may process data on servers outside your country, including outside the European Economic Area (EEA) or the UK. Where personal data is transferred internationally, it is protected by appropriate safeguards — such as the European Commission's Standard Contractual Clauses and Cloudflare's Data Processing Addendum.
7. How long we keep it
We keep your email only as long as needed for the waitlist purpose — until you ask us to delete it, until you tell us you're no longer interested, or until we decide not to proceed with the private-access programme. When the data is no longer needed, we delete it within a reasonable period (no longer than 90 days after the purpose ends), unless we're legally required to keep it longer.
8. Cookies & tracking
This website does not use advertising or analytics cookies, and we do not track your activity across other sites. We don't set any non-essential cookies. The signup form sends only what you type, plus the technical details listed in section 2.
9. Your rights under the GDPR
If you're in the EEA or the UK, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure (“right to be forgotten”) — have your data deleted.
- Restriction — ask us to limit how we use your data.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to our processing.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Complain — lodge a complaint with your local data protection authority (in the EEA) or the Information Commissioner's Office (in the UK).
10. How to exercise your rights
Email us at hello@verityiq.io from the address you signed up with. We'll respond within one month, as required by the GDPR. To delete your email or withdraw consent, just ask — no reason needed. There's no charge for a reasonable request.
11. Security
We limit the data we collect to the minimum, store it in access-controlled infrastructure, and transmit it over encrypted (HTTPS) connections. No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your data.
12. Children
VerityIQ is a business tool intended for adults and is not directed at children. We don't knowingly collect data from anyone under 16. If you believe a child has given us their data, contact us and we'll delete it.
13. Changes to this policy
We may update this policy from time to time. We'll change the “last updated” date at the top, and for material changes we'll take reasonable steps to let affected sign-ups know.
14. Contact
Questions about this policy or your data? Email hello@verityiq.io and we'll help.