What we hold, and why.
Written to be read. If any part of this is unclear, that is a fault in the writing and we would like to hear about it.
Who is responsible for what
Verdant plays two different roles, and the distinction matters for your rights.
For your practice's clients. When a practice stores client records in Verdant, the practice is the data controller and Verdant is the processor. We handle those records only on the practice's instructions. If you are a client of a practice and want to see, correct or delete your records, contact the practice directly — they can action it themselves, without us.
For practitioners and prospects. When you sign up, book a demo or email us, Verdant is the controller for that data — your name, practice, email, and the correspondence itself.
What we collect
From people who contact us or hold an account:
- Name, practice name, email address and anything you write to us.
- Billing details, held by our payment processor rather than by us. We store the last four digits and the expiry, nothing more.
- Product usage — which features an account uses and when — so we can tell what is working. This is tied to an account, not to an individual practitioner's browsing.
- Technical logs: IP address, browser and timestamps, retained for 30 days for security and debugging.
From clients of a practice, on that practice's instructions: whatever the practice records. That typically includes contact details, appointment history, clinical notes, consent forms and payment records.
We do not buy data about you from anyone, and we do not enrich your record from third-party sources.
Why we hold it, and on what basis
- To provide the service — performance of our contract with you.
- To keep it secure — legitimate interest in protecting records we are trusted with.
- To bill you — contract, and legal obligation for tax records.
- To answer you — legitimate interest in replying to someone who wrote to us.
- To improve the product — legitimate interest, using aggregate usage rather than the contents of clinical records. We do not read your clients' notes.
We do not rely on consent for any of the above, which means there is no consent for us to withdraw — but you can object to processing based on legitimate interest at any time.
Who else sees it
Only the subprocessors listed on our security page, each for a single named purpose, each under a contract that binds them to the same standards. We publish that list in full and give 30 days' notice before adding to it.
We do not sell personal data, we do not share it with advertisers, and we do not use clinical records to train machine learning models — ours or anyone else's.
We will disclose data if legally compelled. Where we are permitted to tell you first, we will.
How long we keep it
Account and client data stays for as long as the account is open. When an account is closed we retain it for 90 days so a change of mind is recoverable, then delete it irrecoverably from live systems. Encrypted backups age out within a further 35 days.
Some records outlive the account by law — invoices and tax records for seven years, and the security audit log for two. Where a practice has its own statutory retention period for clinical records, that period governs and we hold the data until the practice exports or instructs deletion.
Your rights
Under the GDPR and equivalent laws you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it to another provider in a portable format. You can also object to processing we base on legitimate interest.
Most of this you can do yourself: export lives in the product and works on every plan, with no fee. For anything else, email privacy@verdant.example.com. We respond within 30 days and usually within three business days.
If you are unhappy with how we handled a request you can complain to your local supervisory authority. We would rather you told us first, but it is your right either way.
Where the data lives
Verdant runs in the EU (Stockholm) and the US (Northern Virginia). Practices on the Group plan can pin all storage and processing to the EU region.
Where data moves between regions, transfers are covered by the standard contractual clauses, and by the UK addendum for practices in the United Kingdom.
Cookies
The marketing site sets no cookies at all. There is no analytics script, no advertising pixel and no consent banner, because there is nothing to consent to.
The application sets one cookie to keep you signed in, and one to remember your practice if you belong to more than one. Both are strictly necessary and neither is used for tracking.
Changes and contact
If we change this notice materially we will email account holders at least 30 days before it takes effect, and keep the previous version available for comparison.
Questions, requests or complaints: privacy@verdant.example.com, or Verdant Software Ltd, Malmö, Sweden.