Who we are
VeranticSystems ("we", "us") is a GoHighLevel implementation partner. We set up and maintain CRM accounts, automations, funnels and integrations for business clients. This policy explains what personal data we collect through this website and in the course of our work, why we collect it, how long we keep it and the rights you have over it.
For data collected through this website and our own business operations, we are the data controller. For data held inside a client's GoHighLevel account or connected systems that we access to do our work, the client is the controller and we act as a processor on their written instructions (see Client account data).
VeranticSystems is a remote-first team operating from the United Kingdom; our registered address appears on every proposal and invoice and is available on request. Contact: hello@veranticsystems.com.
What we collect
We collect only what we need to respond to you and deliver our services.
- Contact and enquiry data. Name, work email, phone number, company name, the services you are interested in, budget and timeline, and anything you write in a message or booking note.
- Booking data. The date, time and time zone of a call you book, and the details you enter on the booking form.
- Applicant data. If you apply for a role: your CV, portfolio links, and the answers you give during the process.
- Newsletter data. Your email address and the date and source of your subscription.
- Technical data. IP address, browser type, device, pages viewed and referring site, collected through server logs and any analytics we run (see Cookies and analytics).
- Correspondence. Emails, messages and call notes exchanged with you while we work together.
We do not knowingly collect special-category data (such as health information) through this website. Where our client work involves systems that hold such data, it is handled under the client's instructions and our data processing terms, and we design automations so that sensitive detail is kept out of them wherever possible.
How we use it
- To reply to enquiries, run the free audit call and prepare proposals.
- To deliver, support and improve the services you have engaged us for.
- To send the newsletter you subscribed to, which you can leave with one click at any time.
- To consider job applications and communicate about them.
- To keep records for accounting, tax and legal compliance.
- To protect the website and our systems against misuse.
We do not sell personal data, and we do not share it with third parties for their own marketing.
Legal bases (UK and EU GDPR)
Where the UK GDPR or EU GDPR applies, we rely on the following bases:
- Contract: to respond to your request, deliver services you have engaged, and manage the relationship.
- Legitimate interests: to run and secure this website, to follow up on a genuine business enquiry, and to keep reasonable business records. We balance these against your rights and expectations.
- Consent: for the newsletter and for any non-essential cookies. You may withdraw consent at any time.
- Legal obligation: for accounting, tax and responding to lawful requests.
Cookies and analytics
This website uses a small amount of browser storage to remember your theme choice (light or dark). That storage never leaves your device and contains no personal data.
If we enable analytics, we use privacy-respecting, aggregate measurement and will list the provider here. If any cookie requires consent, a banner will ask for it before it is set. Our booking window may embed a third-party scheduling tool; that tool's own cookie and privacy notice applies inside the embedded frame.
Who we share data with
We use a small number of service providers to run our business. Each processes data only on our instructions and under contract:
- Form delivery and scheduling services (Web3Forms and Cal.com) that pass your enquiry or booking to our inbox and calendar.
- Email and productivity providers for correspondence and document storage.
- Web hosting and content delivery for this website.
- Payment processors for invoicing, who handle card data under their own PCI-compliant terms; we never see full card numbers.
- Video-call providers for audit and project calls.
We may also disclose data where required by law, to protect our rights, or as part of a business sale or restructuring, in which case this policy continues to apply.
Client account data
To do our work we are given access to clients' GoHighLevel accounts and connected systems. Those systems contain personal data about the client's own leads, customers or patients. In that role:
- The client is the controller and decides why and how the data is used. We act only on documented instructions.
- Access is limited to the people on the project, through named user accounts, and is removed when the engagement ends.
- We do not copy client contact data out of the client's systems except where a migration or reconciliation task requires a temporary working copy, which is deleted once the task is verified.
- Test leads used to verify automations use our own phone numbers and inboxes, never a real customer's.
- We sign data processing terms with clients on request, and our Terms of Service include the standard processor obligations.
How long we keep it
- Enquiries that do not become clients: up to 24 months from last contact, then deleted.
- Client records and correspondence: for the length of the engagement and 6 years after, for accounting and legal purposes.
- Applicant data: 6 months after a decision, unless you ask us to keep it for future roles.
- Newsletter: until you unsubscribe or we retire the list.
- Server logs: up to 90 days.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where consent is the basis. You also have the right to complain to a supervisory authority; in the UK that is the Information Commissioner's Office.
To exercise any right, email hello@veranticsystems.com. We will respond within one month and may need to verify your identity first. If your request concerns data held in a client's account, we will pass it to the client, who is responsible for responding.
International transfers
We are a distributed team and our providers operate globally, so data may be processed outside the country where you live, including outside the UK and EEA. Where that happens we rely on adequacy decisions or standard contractual clauses, together with the providers' own security commitments.
Security
We use named accounts with multi-factor authentication for every system we access, least-privilege permissions, encrypted devices, and a written offboarding process that removes access when a project or role ends. No system is perfectly secure; if we ever discover a breach affecting your data we will notify you and the relevant authority as the law requires.
Children
This website and our services are aimed at businesses. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We will update this page when our practices change and update the effective date at the top. Significant changes will be highlighted here for at least 30 days.
Questions about this document can be sent to hello@veranticsystems.com. We reply within one working day.