Verusuite Privacy Statement

Effective date: June 1st 2026 Provider: North Wave ("Verusuite", "we", "us"), Švitrigailos g. 11k-109, Vilnius.

1. Who this statement is for

This statement explains how Verusuite handles personal data in connection with the Verusuite email and collaboration platform (the "Service"). It is addressed to the organisations that sign up for a workspace ("Tenants") and the administrators who manage them. Where a Tenant provisions mailboxes for its own people, those individuals should read this statement together with their organisation's own privacy notice.

2. Our two roles (controller and processor)

Verusuite acts in two distinct capacities, and your rights and our obligations differ between them:

  • As a data controller for the data we collect to create, bill, secure, and support a workspace: signup and account details, authentication and security data, billing data, and partner-programme data (sections 3.1 to 3.4).
  • As a data processor for the content inside a workspace - email messages, attachments, contacts, and calendars (section 3.5). Here the Tenant is the controller: it decides what is stored and why, and we process that content only on the Tenant's documented instructions to deliver the Service.

For content we process on a Tenant's behalf, individual users should direct privacy requests to their Tenant administrator; we will assist the Tenant in responding.

3. What we collect

3.1 Account and signup data (controller)

Workspace name and identifier, primary domain, and for the founding administrator: given and family name, a personal/login email address, a recovery email address, optional phone number, and a password (stored only as an argon2id hash, never in clear text). We also derive a billing country from the network location at signup.

3.2 Authentication and security data (controller)

One-time passcodes (OTPs) and their expiry, session and refresh tokens, login and device metadata (IP address, user agent, timestamps), anti-abuse signals including a Cloudflare Turnstile challenge token and rate-limit counters keyed to email/IP, and checks against disposable-email lists. We use these to authenticate users and to protect the Service from abuse.

3.3 Billing data (controller)

Plan, licensed seat count, billing country and currency, coupon usage, and the identifiers of your payment records held by our payment processor (Stripe customer and subscription IDs, subscription status, renewal date). Card numbers and payment credentials are entered directly into Stripe and are never stored on our systems; we receive only tokens and status.

3.4 Partner-programme data (controller, where applicable)

For organisations that join the partner/referral programme: company details, contact email and phone, KYC documents (for example business registration, identity, and tax documents), payout method, and bank/payout details. Payout bank details are held encrypted (envelope encryption) and are accessible only for processing payouts. We also keep commission and referral records.

3.5 Customer Content (processor, on behalf of the Tenant)

Email messages and their headers, attachments, mailbox and folder structure, contacts (CardDAV), and calendar events (CalDAV) that users send, receive, or store. We process this only to operate the mailbox service for the Tenant.

3.6 Operational and diagnostic data

To run the Service reliably we generate: mail delivery and queue records (recipient address, delivery state, SMTP result codes, retry/bounce information), administrative audit logs of security-relevant actions, and the verdicts of automated spam and malware scanning (rspamd and ClamAV) applied to inbound and outbound mail. DKIM signing keys and DNS verification records are maintained per domain.

4. Why we use it, and our legal bases

Purpose Data Legal basis (GDPR Art. 6 / Egypt PDPL)
Create and operate the workspace, deliver mail 3.1, 3.5, 3.6 Performance of a contract
Authenticate users and secure the Service (anti-abuse, spam/malware scanning, rate limiting) 3.2, 3.6 Legitimate interests; legal obligation (security)
Billing, invoicing, tax 3.3 Performance of a contract; legal obligation
Operate the partner programme and pay commissions 3.4 Performance of a contract; legal obligation
Service and security communications (for example the signup verification code) 3.1, 3.2 Performance of a contract
Comply with law and respond to lawful requests as relevant Legal obligation

Under the Egypt Personal Data Protection Law (Law No. 151 of 2020), processing relies on the corresponding lawful grounds (consent, contractual necessity, legal obligation, and legitimate interest as permitted).

5. Who we share it with (sub-processors)

We do not sell personal data. We share data only with service providers who process it on our behalf under contract:

Sub-processor Purpose Data involved
Stripe Payment processing and subscription billing Billing data, card data (entered directly into Stripe)
Cloudflare Bot/abuse protection (Turnstile), DNS provisioning, network geolocation (country) IP address, challenge tokens, domain/DNS records
Digital Ocean Encrypted storage of messages and attachments Customer Content

We may also disclose data where required by law, to protect our rights or users' safety, or in connection with a corporate transaction (with notice where required).

6. International transfers

The Service is operated from EU, Emirates, and your data may be processed in countries other than your own, including outside the European Economic Area and Egypt. Where we transfer personal data internationally we rely on appropriate safeguards: for GDPR, the European Commission's Standard Contractual Clauses (and adequacy decisions where they apply); for the Egypt PDPL, the cross-border transfer conditions permitted under the law. A copy of the relevant safeguards is available on request at [email protected].

7. How long we keep it

Data Retention
Account and billing data For the life of the workspace plus 12 months, then deleted or anonymised; tax records kept for 24 months.
Customer Content (mail, contacts, calendars) Until deleted by the user/Tenant or the workspace is closed, after which it is deleted within 30 days
Abandoned signups (unverified) Reaped automatically after 48 hours
Audit and security logs 24 months
Mail delivery/queue records 30 days

8. How we protect it

Encryption in transit (TLS, with STARTTLS required for mail submission) and at rest (server-side encrypted object storage); passwords stored only as argon2id hashes; outbound mail DKIM-signed; partner bank details held under envelope encryption; automated malware (ClamAV) and spam (rspamd) scanning; role-based access controls and tenant isolation; and audit logging of administrative actions. No system is perfectly secure, but we maintain measures appropriate to the risk as required by GDPR Art. 32 and the Egypt PDPL.

9. Your rights

Subject to the conditions and exemptions in the GDPR and the Egypt PDPL, you may request to: access your personal data; correct inaccurate data; delete data; restrict or object to certain processing; receive your data in a portable format; and withdraw consent where processing is based on consent. For Customer Content where we act as processor, please make these requests to your Tenant administrator (the controller); we will support them in responding.

To exercise rights regarding data for which we are the controller, contact [email protected]. You also have the right to lodge a complaint with your supervisory authority - in the EU, your national data protection authority; in Egypt, the Personal Data Protection Centre.

10. Children

The Service is intended for business use and is not directed to children under [16/AGE]. We do not knowingly collect personal data from children.

11. Cookies and similar technologies

The web application uses strictly necessary session and authentication tokens to keep you signed in, and the Cloudflare Turnstile challenge to distinguish humans from bots at signup. We do not use advertising or cross-site tracking cookies.

12. Changes to this statement

We may update this statement; material changes will be notified to workspace administrators and reflected by a new effective date above.

13. Contact

[North Wave MB] Privacy enquiries: [email protected] Egypt representative : Arwa Software LTD.