Legal

Privacy Policy

Data protection obligations to provide information pursuant to the GDPR and the TKG.

Legal overview

How we protect your data
A concise summary of our obligations, contacts, and the most important things to know before you read the full policy.

Last updated

Controller

Vertify GmbH, Sandgasse 36/IV, 8010 Graz, Austria

Privacy policy

The protection of your personal data is of utmost importance to us. We therefore process your data exclusively on the basis of the statutory provisions (GDPR, TKG 2003). In this data protection information, we inform you of the most important aspects of data processing within the scope of this website.

Access to the website does not require the provision of personal data. Vertify GmbH processes personal data when you actively submit it via the waitlist form and provide informed consent for that processing. Technical access data may be processed by our hosting provider as described below.

Vertify GmbH acts as the controller for this site and appoints vetted processors to operate hosting and communications.

A record of processing activities is available upon request.

Technically necessary cookies

This website uses technically necessary cookies (ARRAffinity and ARRAffinitySameSite) provided by Microsoft Azure to ensure the secure and reliable operation of the website, in particular for load balancing.

  • ARRAffinity
  • ARRAffinitySameSite

These cookies are required for the operation of the website, do not track users, and do not require consent.

HubSpot forms and waitlist

When you join the VertifyMed waitlist or use our contact forms, we collect the information you enter (email, first and last name, country, your consent choice, and whether you are a medical professional) and submit it to our CRM provider HubSpot for the purpose of providing the requested updates.

Legal basis: your consent (GDPR Art. 6(1)(a)). Double opt-in is used: HubSpot will send you a confirmation email, and your subscription is active only after you confirm. You can withdraw consent at any time via the unsubscribe link in emails or by contacting us.

HubSpot acts as our processor for form handling, email delivery, and consent records.

Context we send with the form includes the page URL and name and a time-to-submit token to protect against abuse. We do not log the form payload server-side beyond short-lived processing.

We collect and process only the minimum data needed to provide the requested updates and protect the service; no additional personal data is gathered for these purposes.

Retention: waitlist data is stored until you withdraw consent.

Abuse prevention and rate limiting

To prevent automated abuse of our forms, we verify a signed time-to-submit token and apply per-IP rate limiting. IP addresses are hashed in-memory (SHA-256) solely for this purpose and are discarded after the 10-minute rate-limit window; no raw IPs or hashes are persisted to logs. We keep only the hashed IP during the window to enforce limits.

We use short-lived, hashed identifiers solely to enforce rate limits and discard them after the window.

Legal basis: legitimate interest in service protection (GDPR Art. 6(1)(f)).

Contact with Vertify

If you get in touch with Vertify via e-mail, the data you provide will be stored for up to six months for the purpose of processing your request and for follow-up inquiries. We do not disclose this data to third parties without your consent. Should a contract result from the inquiry, the statutory retention periods apply. The data processing is based on Article 6 paragraph 1 subsection b (contract fulfillment) and Article 6 paragraph 1 subsection a (informed consent) of the GDPR.

Hosting and technical access data

This website is hosted on Microsoft Azure Static Web Apps. Microsoft acts as a processor. When accessing the website, technical access data may be processed by our hosting provider as part of the secure and reliable operation of the service. This data can include:

  • the IP address
  • the date and time of access
  • the requested pages
  • browser and device information

Vertify GmbH does not actively collect, store, or analyze this data itself.

Web analytics (Simple Analytics)

We use Simple Analytics, a privacy-friendly web analytics service, to understand how visitors use our website (e.g., page views and general usage statistics) and to improve our website.

Simple Analytics does not use cookies and does not store information on users' devices. We do not collect personal data such as names, email addresses, or persistent identifiers for this purpose. IP addresses are not stored in a way that allows identification of individual users.

The processing is based on our legitimate interest in understanding and improving the performance and usability of our website (GDPR Art. 6(1)(f)).

Service providers / processors

For web analytics, we use Simple Analytics B.V. (Netherlands) as a processor.

Your rights

With regard to your data stored by Vertify, you are generally entitled to the rights of information, correction, deletion, restriction, data portability, revocation and objection. If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you can file a complaint with us or the data protection authority.

You can reach us at dataprotection@vertifymed.com. You can submit a DSAR at any time to exercise these rights.