Legal

Data Handling

A practical summary of what VeriVest holds, where it lives, who can reach it and how long it is kept.

Data categories

  • Identity data and identification documents
  • Entity and structure data, including beneficial ownership
  • Financial schedules provided for eligibility assessment
  • Source of funds and source of wealth declarations
  • Verification and screening results
  • Signed declarations, certificates and fund documents
  • Audit and access logs

Tenant isolation

Every record belongs to a single client organisation. Isolation is enforced at the database level through row level security, not only in application code, so data cannot be read across organisations.

Access

  • Access is role based and least privilege by default
  • Applicants see only their own application
  • Accountants see only the client and request they were invited to
  • Reviewers see records within their organisation
  • Auditors may be granted read only access
  • Administrative access is separated, restricted and logged

Document storage

Documents are stored in private, encrypted storage. Access is authenticated and time limited on every request, and every upload and download is recorded in the audit log.

Retention and deletion

Retention periods are configurable per client organisation so they can be set to match record keeping obligations. When a retention period ends, records are deleted or de identified in line with the configured policy.

Where a legal or regulatory obligation requires records to be preserved, that obligation takes precedence over a shorter configured period.

Backups and recovery

Database and document backups are taken on a regular schedule, encrypted, and covered by documented restoration procedures.

This page is maintained by Retrader Pty Ltd for the VeriVest platform. It is general information, is not legal advice, and will be updated before commercial launch.