VeriScan™ by Quantyva™
Services How It Works Pricing Contact
Submit for Review
Legal

NDA & Data Handling

Our binding commitments on how we protect your packaging files, proprietary formulations, and brand information from the moment you submit to the moment we delete.

Last updated: 28 May 2026 Effective: 28 May 2026 NDA applies automatically to all orders
Contents
1. Automatic NDA Coverage 2. What Is Confidential 3. Our Obligations 4. Permitted Disclosure 5. File Lifecycle 6. Access Controls 7. Technical Security 8. AI Tools & Third Parties 9. Breach Protocol 10. Standalone NDA 11. Contact

The short version: Every file you send us is treated as strictly confidential by default. No packaging artwork, formulation, or brand information is ever shared outside the compliance team assigned to your audit. Files are permanently deleted 30 days after report delivery. No exceptions.

🔒

Files treated as confidential by default

No form-signing required. NDA protection applies automatically from the moment you submit.

👤

Need-to-know access only

Your files are accessible only to the compliance specialist assigned to your report — no one else.

🗑️

Files deleted within 30 days

Packaging artwork is permanently deleted 30 days after report delivery. No archive, no backup retention.

🚫

Never sold or shared for third-party use

Your files and data are never sold, licensed, or shared with any third party for their own commercial purposes.

1. Automatic NDA Coverage

By submitting files or information to VeriScan™ for compliance review — whether through our online form, by email, or through any other channel — a mutual confidentiality agreement automatically comes into effect between you ("Disclosing Party") and Quantyva™ / VeriScan™ ("Receiving Party").

You do not need to sign a separate NDA before submitting files. This policy, together with our Terms of Service, constitutes our binding confidentiality commitment to you.

If your organisation requires a separate, signed NDA document for internal compliance or procurement purposes, please contact us at contact@veriscanaudit.com before submitting. We will execute a bilateral NDA upon request at no additional cost. See Section 10 for details.

2. What Is Considered Confidential

The following categories of information are treated as confidential under this policy, regardless of how they are marked or whether they are explicitly identified as confidential at the time of submission:

  • Packaging artwork and files: All PDF, AI, PNG, JPEG, or other format files depicting packaging design, artwork, or layout
  • Ingredient lists and formulations: Recipes, ingredient declarations, additive names, and nutritional compositions visible in or extracted from packaging
  • Brand and product strategy: Unreleased product names, launch timelines, market entry plans, or competitive positioning information shared in connection with an audit
  • Commercial information: Pricing, supplier relationships, volume data, or customer information disclosed in the course of the engagement
  • Regulatory history: Prior audit findings, enforcement notices, or regulatory correspondence shared with us for context
  • Contact details: The identity of the brand, company, or individuals engaging our services

Information is not confidential if it is: (a) already in the public domain at the time of disclosure; (b) independently developed by us without reference to your information; (c) received from a third party with no obligation of confidentiality; or (d) required to be disclosed by law or court order (see Section 4).

3. Our Confidentiality Obligations

As the Receiving Party, VeriScan™ / Quantyva™ commits to:

  • Using confidential information solely for the purpose of performing the contracted compliance audit and for no other commercial, research, or operational purpose
  • Not copying, reproducing, or duplicating your files beyond what is strictly necessary to perform the analysis
  • Not disclosing any confidential information to any person, company, or AI service not explicitly covered in this policy
  • Applying the same standard of care to your confidential information as we apply to our own confidential information — and in no case less than a reasonable standard of care
  • Informing you promptly in the event of any suspected or confirmed unauthorised access to your files
  • Ensuring all personnel and contractors with access to your files are bound by equivalent confidentiality obligations

Our confidentiality obligations are indefinite in respect of any trade secrets (formulations, proprietary processes) and survive for a minimum of 3 years from the date of disclosure for all other confidential information.

4. Permitted Disclosure

We may disclose confidential information in the following limited circumstances only:

  • Within the compliance team: To the compliance analyst, QA reviewer, and report writer assigned to your specific audit — on a strict need-to-know basis
  • AI processing tools: Packaging text content may be submitted to AI tools for analysis assistance. See Section 8 for the specific controls that apply.
  • Legal obligation: If compelled by law, court order, or a competent regulatory authority. We will notify you as soon as legally permissible before making such disclosure and will cooperate with any efforts to limit the scope of disclosure.

In all other cases, we will obtain your written consent before disclosing any confidential information to any third party.

5. File Lifecycle

Every packaging file follows a defined, documented lifecycle from receipt to deletion:

1

Receipt

Files are received via our encrypted intake form (Formspree, HTTPS). They are immediately transferred to encrypted cloud storage. The original email or form submission is not used as long-term storage.

2

Assignment

A named compliance specialist is assigned. Only that specialist (plus QA reviewer) receives access credentials to your file folder. Access is revoked for all other personnel.

3

Analysis & Review

Files are reviewed in the secure cloud environment. No local copies are made to personal devices. Working notes and AI outputs are treated as confidential and stored in the same secure environment.

4

Report Delivery

The compliance report is delivered to you by email. The report references your packaging but does not contain full reproductions of your artwork. Delivery is by secure link or password-protected PDF where sensitive content is involved.

5

Support Period (30 days)

Files are retained for 30 days after report delivery to enable follow-up questions, scope clarifications, or correction requests without requiring re-submission.

6

Permanent Deletion

At day 30, all packaging artwork files are permanently and irreversibly deleted from all storage locations. A deletion log entry is created (containing only the deletion date and a non-identifiable file reference) for our records.

If you require earlier deletion — for example, immediately after report delivery — please request this by email and we will comply within 2 business days.

6. Access Controls

Access to client files is governed by the principle of minimum necessary access:

  • Each client project has a dedicated, isolated folder in our secure cloud environment
  • Access is granted only to the named compliance analyst and QA reviewer for that project
  • Access is revoked immediately upon completion of the project and deletion of files
  • No administrative or technical staff have routine access to client file contents
  • Access logs are maintained and reviewed periodically
  • Two-factor authentication (2FA) is required for all accounts with access to client storage

7. Technical Security Measures

We apply the following technical controls to protect your files:

  • Encryption in transit: All file uploads and downloads are encrypted using TLS 1.2 or higher
  • Encryption at rest: Files stored in cloud storage are encrypted at rest using AES-256 or equivalent
  • No local storage on personal devices: Analysts work in the cloud environment; downloading files to personal or unmanaged devices is prohibited
  • No file sharing by unencrypted email: Files are never forwarded as unencrypted email attachments; secure links or password-protected transfers are used
  • Secure deletion: File deletion uses methods that prevent recovery (overwrite or cryptographic erasure depending on the storage provider)
  • Incident monitoring: We monitor for unauthorised access attempts and review access logs regularly

8. AI Tools & Third-Party Processors

VeriScan™ uses AI-assisted analysis tools to support (not replace) human review of packaging text. This section explains exactly how AI tools interact with your data.

8.1 What is submitted to AI tools

Only extracted text content (ingredient declarations, mandatory label text, nutritional data) is submitted to AI tools for analysis. Full artwork files, proprietary design elements, and company identity are not transmitted to AI services unless specifically required and agreed with you in advance.

8.2 Provider selection criteria

We select AI tool providers that meet the following minimum criteria:

  • A binding Data Processing Agreement (DPA) compliant with GDPR Art. 28 is in place
  • The provider does not train its models on customer-submitted data by default
  • Data is processed within the EEA or under appropriate transfer safeguards (Standard Contractual Clauses)
  • The provider maintains SOC 2 Type II or equivalent security certification

8.3 Human oversight

All AI outputs are reviewed by a qualified compliance specialist before inclusion in any report. No AI finding is reported to a client without human verification. Our AI tools are analysis aids — not autonomous decision-makers.

8.4 Opt-out

If you prefer that your packaging text is not processed by any AI tool, please state this in the "Additional Notes" field of the intake form. We will perform the audit using manual analysis only. Turnaround time may be extended; we will advise at the time of order.

9. Data Breach Protocol

In the event of a confirmed or suspected unauthorised access to, or disclosure of, your confidential information, we will:

  • Notify you by email within 48 hours of becoming aware of the incident (and within 72 hours notify the relevant supervisory authority where required by GDPR)
  • Provide a description of the nature of the incident, the categories of information affected, and the likely consequences
  • Describe the measures we have taken or propose to take to address the incident
  • Cooperate fully with any investigation you initiate
  • Take all reasonable steps to contain the breach and prevent further unauthorised access or disclosure

We maintain a documented incident response procedure and test it periodically.

10. Standalone NDA on Request

If your procurement or legal team requires a separately signed, bilateral NDA document — for example, to satisfy internal supplier vetting requirements — we are happy to execute one before any files are shared.

Our standard bilateral NDA covers the same scope as this policy in a format suitable for countersignature. It can be executed electronically (DocuSign or equivalent) and returned typically within 2 business days.

To request a standalone NDA, email contact@veriscanaudit.com with the subject line "NDA Request — [Company Name]". Please include your company's registered name and jurisdiction.

We can also review and execute an NDA provided by your legal team, subject to agreement on any material changes to the standard terms.

11. Contact

For any questions about this policy, to request early file deletion, to report a security concern, or to request a standalone NDA:

VeriScan™ — Quantyva™
Email: contact@veriscanaudit.com
Subject: "Data / NDA — [your company name]"
EU Registration: ROONRC.J2024000390307

We take security and confidentiality seriously and treat all such communications with priority.

VeriScan™ by Quantyva™

Premium packaging compliance review for food brands entering Italian, Spanish, and French markets.

Services

Essentials Audit Multilingual Audit Pro & Full EU Audit

Company

How It Works Submit for Review

Legal

Privacy Policy Terms of Service NDA & Data Handling
© 2026 Quantyva™ (BrandX Invest) — ROONRC.J2024000390307. All rights reserved.
Privacy Policy Terms of Service Contact