Privacy Policy
Version 1.0 · Last updated: August 10, 2026 · The English version governs.
This policy explains what Verit Global Labs Inc. (“Verit”, “we”) collects when you use the DiaCroma for Agents service and the diacroma.com website, and what we do with it. For business customers, the Data Processing Addendum governs personal data inside Customer content.
1 · What we collect
- Account data. An email address if you provide one at signup (signup works without one) or through a marketplace purchase. When you buy through Microsoft Marketplace and sign in on our activation page, we receive from Microsoft the purchase identifiers and, from your sign-in, your name, email and tenant identifiers.
- Service content. What you send the Service to do its job: agent names, missions, uploaded documents, tool names and schemas, proposed actions, and the resulting governance decisions and signed audit records.
- Usage and operational data. Governed-call counts and timestamps (also used for marketplace metering), technical logs, and service telemetry.
- Website. The site stores only your theme preference locally in your browser. We do not run advertising trackers. Fonts are served by Google Fonts, which receives your IP address when the page loads.
2 · What we use it for
To provide and operate the Service (including deriving proposed constraints from mission text using models hosted on Microsoft Azure), to administer your subscription through Microsoft’s marketplace, to secure the Service and keep its audit guarantees, and to support you. We do not sell personal data and we do not use your content to train machine-learning models.
3 · Who we share it with (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, storage, model inference (Azure AI Foundry) | United States (East US 2) |
| Microsoft Marketplace | Subscription lifecycle and billing | United States / global |
| Vercel | Website hosting (diacroma.com) | United States / global edge |
| Google Fonts | Web font delivery | Global |
We share data with these providers only as needed for the purposes above, and otherwise only if the law requires it.
4 · Retention
Account and service content are retained while your organization is active. Governance audit records are append-only by design and are retained for the life of the subscription plus up to twelve (12) months, then deleted. You can export your records via the API at any time. Deletion requests are honored except where retention is required by law or by the integrity of billing records.
5 · Security
TLS for data in transit; API keys stored only as hashes; secrets in a managed secret store; signed, append-only event chains for governance decisions; per-organization isolation; least-privilege access.
6 · Your rights
Depending on where you live (e.g., GDPR in Europe, CCPA in California), you may have rights to access, correct, export, restrict or delete personal data, and to object to processing. Write to diacroma@veritglobal.com and we will respond within the time the law requires. Where we transfer personal data out of the EEA/UK, we rely on the EU Standard Contractual Clauses (see the DPA).
7 · Changes and contact
We will post changes to this policy here and update the date above; material changes will be notified to subscribers by email. Contact: Verit Global Labs Inc. · diacroma@veritglobal.com.