Privacy notice
What we hold, and what we don't.
Vervet monitors public regulatory registers. It is a product about firms, not about people, and it is built to hold as little personal data as the job allows. This notice says plainly what that means.
Last updated 30 July 2026
Who we are
Vervet is a UK compliance-monitoring service operated from the United Kingdom. For anything in this notice, including any request about your data, write to opeyemi@vervethq.com. We are the controller for the data described under “Visiting this site” and “Contacting us”. For data inside a customer's account, the customer is the controller and Vervet is their processor.
Visiting this site
This page sets no cookies, runs no analytics, embeds no tracking pixels and loads nothing from a third party. Our fonts are served from our own servers rather than a font CDN, specifically so that visiting this page does not disclose your IP address to anyone else. Our hosting provider keeps ordinary server logs, including IP addresses, for security and troubleshooting.
Contacting us
If you email us, we keep that correspondence so we can reply and keep a record of what was agreed. Our lawful basis is legitimate interests — responding to someone who chose to contact us about their business.
If you are a customer
Inside an account we hold: your organisation's name; the email addresses you nominate to receive alerts; an API key, stored only as a SHA-256 hash so we cannot read it back; the reference numbers of the firms you choose to monitor; and an append-only audit log of what was checked, what changed and what we sent you.
The monitoring data itself comes from the FCA Financial Services Register and from published regulator material. That is public information about firms. It can include the names of approved persons, which the regulator publishes on the public register; we copy it, we do not enrich it, and we do not combine it with anything else about those individuals.
We do not process your customers' data. Vervet holds no payment transactions, no end-customer identities and no KYC files.
Who else sees it
| Provider | Purpose | What reaches them |
|---|---|---|
| Railway | Hosting and database | Everything stored, at rest |
| Resend | Sending alert email | Recipient addresses and message contents |
| Anthropic | Drafting impact notes on new regulator publications | Published regulator text only — never account or customer data |
Some of these providers operate outside the UK, so data may be transferred internationally under the safeguards in their terms. We will tell existing customers before adding or changing a provider on this list.
How long we keep it
The audit log is append-only and retained for the life of the account, because its whole purpose is to evidence a continuous history — a record with pieces removed cannot do the job it exists for. On cancellation we deactivate access, stop all monitoring and email, and provide a complete export. We will delete an account's data on request, subject to any period we are legally required to retain it.
Your rights
Under UK data protection law you may ask for a copy of your personal data, ask us to correct or delete it, or object to how we use it. Email opeyemi@vervethq.com and we will respond within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk.
If your data appears on the FCA Register and you want it changed, that is a matter for the FCA — we mirror the register, we cannot alter it. We will tell you so plainly rather than let you think the request has been actioned.