Legal
One page, one commitment.
Last updated · 12 July 2026
The position
Verdscore treats every legal document as a public commitment. No dark patterns, no buried clauses, no policy-by-obscurity. Each policy below lives on its own page, dated, and versioned in git.
Every policy, one place
Pick the one you need. Each page is self-contained.
Privacy Policy
What we process, why, who we share it with, and how you exercise your GDPR rights.
Terms of Service
Plain-language rules of engagement — subscription, cancellation, liability, jurisdiction.
Cookies
One strictly-necessary session cookie; analytics only if you say yes.
DPA
Processor terms for B2B customers, incorporating SCCs 2021/914.
Subprocessors
Every third party that touches your data, what they see, and where they sit.
Security
Encryption, authentication, hosting, incident response — the security posture behind the product.
Impressum
Company identification and responsible-party disclosure (TMG § 5, GDPR Art. 13).
System status
Live health check for the web app, API, database, and email delivery.
How we version this
Every substantive change to any policy on this page updates the “last updated” date on that page, is committed to git with a plain-language summary, and — for anything that affects our processor commitments — triggers a notice to signed customers at least 30 days ahead of the change taking effect. See the DPA for the objection mechanism.
Who to talk to
One inbox for every legal question — from a GDPR data-subject request to a signed DPA to a security questionnaire. Email [email protected] or use the contact form. Typical turnaround: 2 business days.
Questions about this document? Send me a message — I read every one.