Privacy Policy
Created: September 9, 2026 · Last Updated: September 9, 2026
Article 1. Introduction and Scope
Veren Digital Solutions Limited ("Veren Digital," "the Company," "we," "us," or "our") is a company registered in Nigeria under RC 9664851, with its registered address at 20 Kingdom Abadi Close, Old Etegwe Road, Yenagoa, Bayelsa State, Nigeria. Veren Digital is an AI infrastructure and consulting company that helps businesses design, deploy, and operate artificial-intelligence systems across their sales, marketing, and operations functions. This Privacy Policy ("Policy") applies to verendigital.com (the "Site") and to Veren Digital's services generally, including but not limited to our AI consulting engagements and our PCAA (Prince Charming AI Android) lead-recovery offer, cited here only as one example among the services this Policy covers, not as this Policy's subject.
This Policy describes how we collect, use, disclose, and safeguard personal data when you visit the Site, submit our contact form, request one of our lead-magnet resources, book a call with us, or otherwise interact with us directly as a prospective or existing client, vendor, or member of the public. It does not govern our processing of a client's own end-customer or lead data once you have engaged us for a service that involves handling that data on your behalf — that relationship, and our role as a data processor within it, is addressed separately in our Data Processing page and, where one exists, the Data Processing Addendum within your signed service agreement, which controls over this Policy for that specific processing.
By accessing or using the Site, you acknowledge that you have read and understood this Policy. If you do not agree with how we describe our practices here, you should not use the Site or provide us with personal data. We may process personal data belonging to individuals located in Nigeria, the European Union, the United Kingdom, the United States, and elsewhere; where a specific jurisdiction's law grants you rights beyond what is described generally in this Policy, Article 10 addresses that jurisdiction specifically.
Article 2. Definitions
In this Policy, the following capitalized terms have the meanings given below. Terms not defined here carry their ordinary meaning under Applicable Data Protection Laws (defined below).
- "Personal Data" means any information relating to an identified or identifiable natural person, such as a name, email address, phone number, or an identifier that can be linked to a person even indirectly.
- "Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, use, disclosure, and deletion.
- "Data Subject," "You," or "Your" means the natural person to whom Personal Data relates — a Site visitor, a contact-form submitter, a lead-magnet recipient, or another individual whose Personal Data we Process under this Policy.
- "Controller" means the entity that determines the purposes and means of Processing Personal Data. For the Personal Data described in this Policy, Veren Digital is the Controller.
- "Processor" means an entity that Processes Personal Data on a Controller's behalf and instructions. Where Veren Digital acts as a Processor of a client's data — for example, in delivering PCAA — that relationship is governed by the Data Processing page and the applicable service agreement, not this Policy.
- "Services" means Veren Digital's AI consulting, advisory, and technology services generally, including PCAA and any other offer Veren Digital makes available from time to time.
- "Site" means verendigital.com and its subdomains.
- "Consent" means a freely given, specific, informed, and unambiguous indication of Your wishes, given by a clear affirmative act — such as checking an unchecked checkbox — by which You signal agreement to the Processing described at the point Consent is requested.
- "Sub-processor" means a third-party service provider we engage to Process Personal Data on our behalf in order to operate the Site or deliver the Services.
- "Applicable Data Protection Laws" means, as relevant to a given Data Subject, the Nigeria Data Protection Act 2023 and its implementing regulations (including the Nigeria Data Protection Regulation, together "NDPR"), the EU General Data Protection Regulation ("GDPR"), the UK General Data Protection Regulation as it forms part of UK law ("UK-GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the US Telephone Consumer Protection Act ("TCPA"), each to the extent it applies to the Processing in question.
Article 3. Categories of Personal Data We Collect
3.1 Personal Data You Provide Directly
We collect Personal Data you choose to give us directly through the following channels:
- Contact form: your name, email address, phone number, company name, and the content of your message.
- Consent record: whether you have checked the box consenting to receive calls and messages from us, including for marketing purposes, and the timestamp at which you did so.
- Lead-magnet requests: your name, email address, phone number, and preferred contact method, along with a consent checkbox that is never pre-checked on your behalf — you must actively check it for us to treat it as given.
- Any other information you volunteer when corresponding with us by email, phone, or otherwise outside the Site's forms.
3.2 Personal Data We Collect Automatically
We collect a limited amount of Personal Data automatically as you browse the Site, and only some of it depends on your consent:
- Google Analytics ("GA4") — loaded, and its cookies set, only after you click "Accept" on our cookie banner. We track a fixed, specific set of events: cta_click, booking_completed, contact_form_started, contact_form_submitted, and contact_form_error. None of these events carries your name, email address, phone number, or message content as a parameter — only categorical labels describing what happened.
- Vercel Analytics and Vercel Speed Insights — aggregate, cookie-free page-view and performance data that does not identify you individually and runs regardless of your cookie choice, because it does not rely on cookies or any persistent identifier.
3.3 Personal Data We Receive From Third Parties
If you book a call with us, our scheduling provider, Calendly, collects your name, email address, and booking details directly from you as part of its own service. We receive the booking details necessary to conduct the call. Calendly's own privacy policy governs its collection and handling of your data before it reaches us.
Article 4. Purposes and Legal Bases of Processing
We Process Personal Data only for the purposes described below, and, where the GDPR, UK-GDPR, or an analogous NDPR principle applies, only where we can identify a valid legal basis for doing so:
| Purpose | Legal Basis |
|---|---|
| Responding to inquiries submitted through the contact form | Legitimate interest — replying to people who contact us directly |
| Sending marketing calls, texts, WhatsApp messages, or emails | Consent — only where you have affirmatively opted in |
| Scheduling and conducting a booked call | Contract necessity / steps taken at your request prior to a contract |
| Delivering a requested lead-magnet resource | Consent, and performance of the request you made |
| Loading Google Analytics and recording analytics events | Consent — only after you accept the cookie banner |
| Performing a Service once you have engaged us | Contract necessity |
| Maintaining records sufficient to demonstrate consent was given | Legal obligation / legitimate interest in compliance |
Article 5. Cookies and Similar Technologies
The Site uses a deliberately small set of cookies and browser-storage items. Our Cookie Policy sets out, cookie by cookie, exactly what we use, why, and for how long; this Article summarizes the position. Google Analytics only loads, and only sets a cookie, after you click "Accept" on the cookie banner presented on your first visit; declining, or taking no action, means it never loads. A separate browser-storage flag remembers your choice so you are not re-prompted on every visit; it is not a cookie and stores nothing beyond "accepted" or "declined." Vercel Analytics and Speed Insights use no cookies at all. See our Cookie Policy for the complete, current list.
Article 6. Disclosure of Personal Data to Third Parties
6.1 We Do Not Sell Personal Data
Veren Digital does not sell Personal Data, and has not sold Personal Data in the preceding twelve months. We do not share Personal Data with third parties for their own independent marketing purposes. We disclose Personal Data only to the categories of recipients described below, each of which Processes it solely to help us operate the Site or deliver the Services.
6.2 Categories of Recipients
- Resend — sends the transactional emails generated by our contact form and by lead-magnet delivery, on our behalf.
- Google Analytics (GA4) — Processes the consent-gated analytics events described in Article 3.2.
- Vercel — hosts the Site and provides Vercel Analytics and Speed Insights.
- Calendly — powers our call-booking page; once you book a call, Calendly holds your booking details directly under its own privacy policy.
We may also disclose Personal Data where required to comply with a legal obligation, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case we will require the receiving party to honor the commitments made in this Policy.
Article 7. International Data Transfers
Veren Digital is based in Nigeria, and the Site is used by visitors around the world, including in the European Union, the United Kingdom, and the United States. As a result, your Personal Data may be transferred to, stored in, and Processed in a country other than the one in which you are located, including Nigeria and the countries where our Sub-processors operate. Where such a transfer is subject to the GDPR or UK-GDPR, we and our Sub-processors rely on recognized transfer mechanisms, including the European Commission's and UK Information Commissioner's Office's standard contractual clauses or an equivalent adequacy or safeguard mechanism offered by the relevant Sub-processor.
Article 8. Data Retention
We retain contact-form submissions and consent records for as long as reasonably necessary to respond to you, to maintain a relationship you have initiated with us, and to demonstrate — for our own compliance and, if ever needed, yours — that consent was properly given and when. Retaining a consent record after the underlying communication has concluded is itself a compliance safeguard, not indefinite data hoarding. Analytics data collected through GA4 is retained according to Google Analytics' own default retention window, which we have not extended. Where you ask us to delete your Personal Data sooner and no legal obligation requires us to keep it, we will do so; see Article 10.4 for how to make that request.
Article 9. Data Security
We apply technical and organizational measures reasonably designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction, appropriate to the nature of the data involved. These measures include restricting access to Personal Data to personnel and Sub-processors who need it to perform their function, relying on reputable infrastructure and service providers (see Article 6.2) who maintain their own security programs, and transmitting data submitted through the Site over encrypted connections. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; if we become aware of a breach affecting your Personal Data that creates a real risk to you, we will notify you and the relevant supervisory authority as required by Applicable Data Protection Laws.
Article 10. Your Rights
Depending on where you are located, you have certain rights over the Personal Data we hold about you. We honor these rights regardless of your location as a matter of practice, but the specific entitlements below are grouped by the framework that grants them.
10.1 Nigeria — Nigeria Data Protection Act / NDPR
If you are in Nigeria, the Nigeria Data Protection Act 2023 and the NDPR entitle you to access the Personal Data we hold about you, request that we correct inaccurate data, request that we delete your data, object to how we are Processing it, and lodge a complaint with the Nigeria Data Protection Commission.
10.2 European Union and United Kingdom — GDPR and UK-GDPR
If you are in the European Union or the United Kingdom, the GDPR or UK-GDPR entitle you to access your Personal Data, request rectification of inaccurate data, request erasure, request that we restrict Processing, receive a copy of your Personal Data in a structured, portable format, object to Processing carried out on the basis of legitimate interest, and withdraw Consent at any time without affecting the lawfulness of Processing carried out before you withdrew it. Withdrawing Consent is as simple as giving it: reply STOP to any message, use the cookie-preferences control on our Cookie Policy page, or email us at the address in Article 16. You also have the right to lodge a complaint with your local data protection supervisory authority; this does not affect your right to seek a remedy through a court.
10.3 United States — California CCPA/CPRA
If you are a California resident, the CCPA and CPRA entitle you to know what categories and specific pieces of personal information we have collected about you, request deletion of that information, request correction of inaccurate information, and opt out of the sale or sharing of personal information. As stated in Article 6.1, we do not sell or share personal information, so there is no sale or sharing to opt out of. We will not discriminate against you — by denying service, charging a different price, or providing a different level of service — for exercising any right described in this Article.
10.4 Exercising Your Rights
To exercise any right described in this Article, email privacy@legal.verendigital.com with your request and enough information for us to locate the Personal Data at issue (typically the email address or phone number you used with us). We may ask you to verify your identity before acting on a request, using information proportionate to the sensitivity of the request. We aim to respond within one month of a verified request; where a request is complex or we have received a high volume of requests, we may extend that period by up to two further months, and we will tell you if we do, and why. There is no charge for making a request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act.
Article 11. Automated Decision-Making
We do not use your Personal Data to make decisions about you through solely automated means that produce legal or similarly significant effects. Where our Services involve AI systems acting on a client's own end-customer data — for example, PCAA identifying and prioritizing leads to re-engage — those systems operate on our client's instructions under the client's own responsibility as Controller, as described in our Data Processing page, and are not decisions this Policy governs with respect to Site visitors.
Article 12. Children's Privacy
The Site is directed at business audiences and is not intended for, or directed at, children. We do not knowingly collect Personal Data from anyone under the age of 18. If you believe a child has provided us with Personal Data, contact us at privacy@legal.verendigital.com and we will delete it promptly.
Article 13. Third-Party Links
The Site may link to or embed third-party services, currently limited to Calendly. We do not control these third parties and are not responsible for their content, availability, or privacy practices. Visiting a linked or embedded third-party service is governed by that service's own privacy policy, not this one.
Article 14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or in Applicable Data Protection Laws. The "Last Updated" date at the top of this page always reflects the most recent version. Where a change is material, we will provide additional notice reasonably calculated to reach affected users, such as a notice on the Site. Your continued use of the Site after an update takes effect constitutes acceptance of the revised Policy.
Article 15. Governing Law
This Policy is governed by the laws of Nigeria, without prejudice to any mandatory data-protection rights available to you under the law of the country in which you are located.
Article 16. Contact Us
Questions about this Policy, or requests concerning your Personal Data, can be sent to privacy@legal.verendigital.com, or by post to Veren Digital Solutions Limited, 20 Kingdom Abadi Close, Old Etegwe Road, Yenagoa, Bayelsa State, Nigeria.