Skip to main content

Legal

Privacy Policy

Last updated: March 6, 2026

1. Data Controller

Pomper.Dev e.U.

Owner: Julian Pomper

Weingartenallee 6/86

1220 Vienna, Austria

Email: hello@veritos.io

VAT ID: ATU79917057

Pomper.Dev e.U. operates the website veritos.io and the web application app.veritos.io (collectively the "Service" or "Veritos"). The protection of your personal data is very important to us. We process your data exclusively on the basis of applicable legal provisions (EU General Data Protection Regulation / GDPR, Austrian Telecommunications Act 2003). This privacy policy explains the key aspects of how we process your data.

2. Encrypted Transmission

This website and the web application use SSL/TLS encryption for security purposes, preventing third parties from intercepting and reading the data you transmit. You can recognize active encryption by the lock icon in your browser's address bar.

3. Server Logs

When you visit our website, the server automatically stores the following information in log files:

  • Time of the request
  • IP address of the accessing device
  • Referrer URL (the page from which you arrived)
  • Operating system
  • Browser type and version

This data is used exclusively for technical monitoring (load, error detection, security) and is not merged with other data sources. It is deleted after three months.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and proper operation of the website).

4. Contact

When you contact us by email or other means, the data you provide (name, email address, content of the inquiry) is stored for the purpose of processing the inquiry and in case of follow-up questions for one year. If the inquiry leads to a contractual relationship, the statutory retention periods apply. We do not share this data without your consent.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(a) GDPR (consent).

5. Registration and User Account

Using Veritos (app.veritos.io) requires creating a user account. The following data is collected:

  • Name
  • Email address
  • Organization and team affiliation (if provided)

This data is used to provide and manage your account, including authentication and access control.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

6. GitHub Integration

Veritos connects to your repositories via a GitHub App. When you authorize this connection, we gain access to:

  • Repository metadata (name, branches)
  • File contents within the .claude/ directory
  • Information required to create and manage pull requests

We only access repositories you have explicitly connected and only the content necessary for the sync process. Unconnected repositories or content outside the sync scope are not accessed.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(a) GDPR (consent via GitHub authorization).

7. Content You Create

Library items (rules, skills, subagents, MCPs), Knowledge Base documents, and other content you create within the Service are stored and processed on our servers to provide the Service, in particular for versioning and syncing to your repositories.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

8. Payment Data

Payments for paid plans are processed through third-party payment providers. We do not store complete credit card numbers or bank details. The payment provider processes your payment data according to its own privacy policy. We only receive information about the payment status, amount, and associated subscription ID.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

9. Cookies

Our website and web application use cookies. These are small text files stored on your device.

Strictly necessary cookies

These cookies are required for the operation of the Service (e.g., session cookies for authentication). You can disable these cookies in your browser settings, but doing so may limit the functionality of the Service.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the proper functioning of the Service).

Optional cookies

Additional cookies (e.g., for analytics purposes) are only set with your explicit consent.

Legal basis: Art. 6(1)(a) GDPR (consent).

10. Data Retention

For accounting purposes, we store the following customer data: name, address, email address, and VAT ID. This data is not shared with third parties, except for transmission to payment providers for payment processing and to our tax advisor to fulfill tax obligations.

All data from a contractual relationship is retained until the expiration of the statutory retention period (7 years under Austrian tax law). Account data is deleted within 30 days of account deletion, unless a legal retention obligation applies.

Legal basis: Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(b) GDPR (performance of a contract).

11. Sharing with Third Parties

We do not sell your personal data. Data is shared only in the following cases:

  • Data processors: Third-party providers who process data on our behalf (hosting, email delivery, payment processing), bound by data processing agreements pursuant to Art. 28 GDPR.
  • GitHub: When you authorize the connection, data is exchanged via the GitHub API as required for the sync functionality.
  • Legal obligation: Where required by law or to protect our legitimate interests.
  • Business transfer: In the event of a merger or acquisition, your data may be transferred as part of the transaction. You will be notified in advance.

We only engage companies that comply with the GDPR or are bound by the EU Commission's Standard Contractual Clauses.

12. Data Transfers to Third Countries

Some of our service providers are based outside the EU/EEA (e.g., GitHub, Inc. in the USA). In these cases, we ensure an adequate level of data protection through appropriate safeguards, in particular the EU Commission's Standard Contractual Clauses or adequacy decisions (e.g., the EU-U.S. Data Privacy Framework).

13. Your Rights

Under the GDPR, you have the following rights:

  • Access (Art. 15 GDPR): You can request information about the personal data we process about you.
  • Rectification (Art. 16 GDPR): You can request the correction of inaccurate data.
  • Erasure (Art. 17 GDPR): You can request the deletion of your data, provided no legal retention obligation applies.
  • Restriction (Art. 18 GDPR): You can request the restriction of processing.
  • Data portability (Art. 20 GDPR): You can request your data in a machine-readable format.
  • Objection (Art. 21 GDPR): You can object to the processing of your data.
  • Withdrawal of consent (Art. 7(3) GDPR): You can withdraw consent at any time. The lawfulness of processing carried out before the withdrawal remains unaffected.

To exercise any of these rights, please contact: hello@veritos.io

14. Right to Lodge a Complaint

If you believe that the processing of your data violates data protection law or your data protection rights have been infringed, you can lodge a complaint with the competent supervisory authority. In Austria, this is the Austrian Data Protection Authority (Barichgasse 40-42, 1030 Vienna).

15. Minors

The Service is not directed at persons under 16 years of age. We do not knowingly collect personal data from minors under 16. If you become aware that a minor has provided us with personal data, please contact us so we can delete it.

16. Changes to This Privacy Policy

We may update this privacy policy from time to time. For material changes, we will notify you by email or through a notice in the Service. The current version is always available on this page.

17. Contact

Questions about data protection? Contact us at hello@veritos.io.