Skip to main content
← Back to Vetta

Legal

Privacy Policy

Last updated: 29 July 2026

1. Who we are

Vetta ("Vetta", "we", "us", "our") is an on-demand marketplace matching SMEs to certified, accredited inspectors and auditors, operated by [Company Name], of [Registered Address].

For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), we are the data controllerof the personal data described in this policy. Our data protection registration with the Information Commissioner's Office (ICO) is [ICO Registration Number].

If you have questions about this policy or how we handle your data, contact us at [email protected].

2. Information we collect

We collect the following categories of information, from both SME clients and accredited auditors:

  • Account information: email address and password (hashed), and company or professional details you provide when you sign up.
  • Auditor accreditation data: your registered scopes, accreditation scheme, accreditation body, certificate and expiry details, and rates and availability — collected during onboarding and kept current so the matching gate can enforce it.
  • Job and booking data: inspection requests, match results, booking slots, and scheduling information.
  • In-app messages and documents: job-scoped messages and evidence or report files exchanged between an SME and an auditor through the document hub.
  • Payment and escrow information: your subscription plan, billing history, and escrow transaction records. Card details are collected and stored directly by our payment processor, Stripe — we do not store full card numbers ourselves.
  • Technical and device data: IP address, browser type, device identifiers, and similar diagnostic data, collected for security and error monitoring.
  • Usage data: pages visited and features used, collected via our analytics provider once one is enabled.

3. How we use your information

We use your information to:

  • Create and manage your account, and authenticate you when you log in;
  • Verify auditor accreditation against the issuing body, and enforce the accreditation gate;
  • Run the matching engine and present ranked, eligible shortlists;
  • Facilitate booking, scheduling, in-app messaging, and document sharing for a job;
  • Process escrow payments and auditor payouts, and manage billing;
  • Run AI-assisted quality checks on submitted reports before release;
  • Maintain the append-only audit trail used for dispute resolution;
  • Monitor, secure, and improve the service, including diagnosing errors and preventing fraudulent or unaccredited use; and
  • Communicate with you about your account and service updates.

5. AI-assisted report QA

When an auditor submits a report, we send its contents to our AI processing provider to check completeness against the required accredited scope and flag inconsistencies before release. We do not permit this provider to use submitted reports to train their own models. The AI engine assists and flags issues; the accredited auditor remains accountable for the report's content and sign-off — see our Terms of Service for more.

6. Accreditation verification

To operate the accreditation gate, we share an auditor's credential details with the relevant issuing or accreditation body to confirm they are genuine, current, and cover the scope of a given job. This is necessary to keep the matching engine trustworthy for every SME on the platform.

7. Who we share your information with

We share personal data with the following categories of recipient, only as needed to run the service:

  • Our cloud database and authentication provider — to store your account data securely.
  • Stripe — to process escrow payments, subscriptions, and auditor payouts.
  • Our AI processing provider — to run report QA checks, as described above.
  • Accreditation and certification bodies — to verify an auditor's credentials.
  • Analytics and error-monitoring providers — to understand product usage and diagnose bugs.
  • Professional advisers and regulators — where required by law, or to establish, exercise, or defend legal claims.

We do not sell your personal data.

8. International transfers

Some of our service providers process data outside the UK. Where this happens, we rely on adequacy regulations or standard contractual clauses approved by the ICO to ensure your data continues to receive an equivalent level of protection.

9. How long we keep your data

  • Account, job, and messaging history is kept for as long as your account is active.
  • Escrow, payment, and audit-trail records are retained for as long as required to meet our legal and accounting obligations, even after an account is closed.
  • If you close your account, we delete or anonymise your remaining personal data within 90 days, except where we need to retain limited data to comply with a legal obligation or resolve disputes.

10. Cookies

We use a small number of cookies to run the service:

  • Strictly necessary: to keep you signed in and, while the site is in pre-launch mode, to remember that you've unlocked the holding page. These can't be switched off, as the service won't function without them.
  • Analytics: to understand how the product is used, so we can improve it — only if and when an analytics provider is enabled for the service.

We don't use third-party advertising cookies.

11. Your rights

Under UK data protection law, you have the right to:

  • Ask us for a copy of the personal data we hold about you;
  • Ask us to correct inaccurate or incomplete data;
  • Ask us to delete your data, subject to our record-keeping obligations above;
  • Ask us to restrict or object to certain processing;
  • Ask for your data in a portable format; and
  • Withdraw consent at any time, where we rely on consent.

To exercise any of these rights, email [email protected]. You also have the right to complain to the Information Commissioner's Office (ICO) if you think we haven't handled your data properly.

12. Security

We use industry-standard measures to protect your data, including encryption of data in transit and at rest, access controls restricting who can view your records, and an append-only audit trail for matches, bookings, messages, QA decisions, and sign-offs. No system is completely secure, but we monitor our service for vulnerabilities and respond promptly to any incidents.

13. Children

Vetta is a business-to-business service intended for use by SME representatives and professional auditors aged 18 and over. We do not knowingly collect personal data from children.

14. Changes to this policy

We may update this policy from time to time, for example as our service or legal obligations change. We'll update the "last updated" date above, and if the changes are significant, we'll notify you by email or an in-app notice.

15. Contact us

If you have any questions about this policy or how we handle your data, contact us at [email protected].

Looking for our Terms of Service?