1. Introduction & Scope
VeraPiù ("we", "us", or "our") provides high-performance custom digital systems, modular educational technology platforms, and SaaS portals for schools, technical institutes, academies, and enterprise organizations.
This Privacy Policy applies to all personal data collected through our public website (verapiu.com), our educational portals (Student, Teacher, Family, and Admin portals), and our bespoke application deployments, unless covered under a distinct enterprise Data Processing Agreement (DPA).
When institutions deploy VeraPiù to manage school rosters, grades, and attendance, the institution serves as the Data Controller, and VeraPiù acts strictly as the Data Processor in accordance with Article 28 of the EU General Data Protection Regulation (GDPR).
2. Information We Collect
Depending on how you interact with VeraPiù, we collect the following categories of data:
Account & Identification Data
Full names, institutional email addresses, phone numbers, role assignments (e.g. Student, Teacher, Parent/Guardian, Administrator), and hashed authentication credentials.
Academic & Operational Data (Institutional Portal)
Gradebook entries, attendance and absence records, class assignments, course schedules, academic communications, and behavioral notations uploaded by designated institutional staff.
Technical & Telemetry Information
IP addresses, device identifiers, browser types, operating systems, session timestamps, and crash logs collected strictly for security auditing, fraud prevention, and performance monitoring.
3. Purposes of Processing
We process collected data exclusively for explicit, legitimate purposes:
- Delivering modular educational portals and ensuring role-isolated access for authorized stakeholders.
- Enabling real-time attendance alerts, automated notifications, and gradebook management.
- Maintaining enterprise-grade infrastructure security, detecting unauthorized access, and upholding audit trails.
- Providing dedicated institutional support, SLA guarantees, and platform maintenance.
We NEVER sell personal data, monetize student or institutional records, or use educational data for behavioral advertising.
4. Legal Bases for Processing (GDPR Article 6)
Under European data protection laws, our processing of personal data is justified under the following legal grounds:
Contractual Necessity (Art. 6(1)(b))
Processing essential to provide our software services under our institutional agreement.
Legitimate Interests (Art. 6(1)(f))
Securing our network, preventing fraudulent activity, and diagnosing system outages.
Consent (Art. 6(1)(a))
Where you voluntarily subscribe to our communications or opt into non-essential telemetry.
Legal Obligation (Art. 6(1)(c))
Complying with statutory accounting, regulatory audit, and law enforcement directives.
5. Sub-processors & Cloud Infrastructure
We maintain strict oversight of our technology partners and cloud vendors. All infrastructure providers are bound by Data Processing Agreements and EU Standard Contractual Clauses (SCCs):
| Provider | Service | Data Location |
|---|---|---|
| Cloudflare, Inc. | DDoS Mitigation, CDN & Edge Security | Global / EU Edge |
| Supabase, Inc. | Managed PostgreSQL & Real-time Database | Frankfurt, Germany (EU-Central) |
| Vercel, Inc. | Serverless Edge & Next.js Application Hosting | Frankfurt, Germany (EU-Central) |
| Stripe Payments Europe | Payment Gateway & Billing Invoicing | Dublin, Ireland (EU) |
6. Data Retention & Erasure
Personal data is retained only for the duration necessary to satisfy institutional agreements, legal retention mandates, or legitimate operational requirements:
- Institutional Records: Maintained for the active term of the institution's agreement plus 90 days following contract termination to enable secure migration.
- Audit & Security Logs: Retained for a rolling period of 12 months for forensic and compliance auditing.
- Billing Records: Retained for 10 years in compliance with EU statutory fiscal and tax regulations.
7. Your Rights Under GDPR
Under Chapter III of the GDPR, data subjects have significant legal rights regarding their personal information:
8. Technical & Organizational Security
We maintain defense-in-depth security measures to protect data from accidental loss, unauthorized access, alteration, or disclosure:
9. Contact & Data Protection Officer (DPO)
If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or require an institutional Data Processing Agreement, contact our Data Protection Office:
VeraPiù Data Protection Office
Email: dpo@verapiu.com
Legal Inquiries: legal@verapiu.com
You also retain the right to lodge a complaint with your local EU supervisory authority (e.g., Garante per la protezione dei dati personali in Italy or your relevant national authority).
VeraPiù Legal & Data Protection Office
For formal data subject requests, law enforcement inquiries, or customized Data Processing Addendums (DPA) for your school or enterprise: