Vervet ← Back

Privacy notice

What we hold, and what we don't.

Vervet monitors public regulatory registers. It is a product about firms, not about people, and it is built to hold as little personal data as the job allows. This notice says plainly what that means.

Last updated 30 July 2026

Who we are

Vervet is a UK compliance-monitoring service operated from the United Kingdom. For anything in this notice, including any request about your data, write to opeyemi@vervethq.com. We are the controller for the data described under “Visiting this site” and “Contacting us”. For data inside a customer's account, the customer is the controller and Vervet is their processor.

Visiting this site

This page sets no cookies, runs no analytics, embeds no tracking pixels and loads nothing from a third party. Our fonts are served from our own servers rather than a font CDN, specifically so that visiting this page does not disclose your IP address to anyone else. Our hosting provider keeps ordinary server logs, including IP addresses, for security and troubleshooting.

Contacting us

If you email us, we keep that correspondence so we can reply and keep a record of what was agreed. Our lawful basis is legitimate interests — responding to someone who chose to contact us about their business.

If you are a customer

Inside an account we hold: your organisation's name; the email addresses you nominate to receive alerts; an API key, stored only as a SHA-256 hash so we cannot read it back; the reference numbers of the firms you choose to monitor; and an append-only audit log of what was checked, what changed and what we sent you.

The monitoring data itself comes from the FCA Financial Services Register and from published regulator material. That is public information about firms. It can include the names of approved persons, which the regulator publishes on the public register; we copy it, we do not enrich it, and we do not combine it with anything else about those individuals.

We do not process your customers' data. Vervet holds no payment transactions, no end-customer identities and no KYC files.

Who else sees it

Provider Purpose What reaches them
Railway Hosting and database Everything stored, at rest
Resend Sending alert email Recipient addresses and message contents
Anthropic Drafting impact notes on new regulator publications Published regulator text only — never account or customer data

Some of these providers operate outside the UK, so data may be transferred internationally under the safeguards in their terms. We will tell existing customers before adding or changing a provider on this list.

How long we keep it

The audit log is append-only and retained for the life of the account, because its whole purpose is to evidence a continuous history — a record with pieces removed cannot do the job it exists for. On cancellation we deactivate access, stop all monitoring and email, and provide a complete export. We will delete an account's data on request, subject to any period we are legally required to retain it.

Your rights

Under UK data protection law you may ask for a copy of your personal data, ask us to correct or delete it, or object to how we use it. Email opeyemi@vervethq.com and we will respond within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk.

If your data appears on the FCA Register and you want it changed, that is a matter for the FCA — we mirror the register, we cannot alter it. We will tell you so plainly rather than let you think the request has been actioned.