Our binding commitments on how we protect your packaging files, proprietary formulations, and brand information from the moment you submit to the moment we delete.
The short version: Every file you send us is treated as strictly confidential by default. No packaging artwork, formulation, or brand information is ever shared outside the compliance team assigned to your audit. Files are permanently deleted 30 days after report delivery. No exceptions.
No form-signing required. NDA protection applies automatically from the moment you submit.
Your files are accessible only to the compliance specialist assigned to your report — no one else.
Packaging artwork is permanently deleted 30 days after report delivery. No archive, no backup retention.
Your files and data are never sold, licensed, or shared with any third party for their own commercial purposes.
By submitting files or information to VeriScan™ for compliance review — whether through our online form, by email, or through any other channel — a mutual confidentiality agreement automatically comes into effect between you ("Disclosing Party") and Quantyva™ / VeriScan™ ("Receiving Party").
You do not need to sign a separate NDA before submitting files. This policy, together with our Terms of Service, constitutes our binding confidentiality commitment to you.
If your organisation requires a separate, signed NDA document for internal compliance or procurement purposes, please contact us at contact@veriscanaudit.com before submitting. We will execute a bilateral NDA upon request at no additional cost. See Section 10 for details.
The following categories of information are treated as confidential under this policy, regardless of how they are marked or whether they are explicitly identified as confidential at the time of submission:
Information is not confidential if it is: (a) already in the public domain at the time of disclosure; (b) independently developed by us without reference to your information; (c) received from a third party with no obligation of confidentiality; or (d) required to be disclosed by law or court order (see Section 4).
As the Receiving Party, VeriScan™ / Quantyva™ commits to:
Our confidentiality obligations are indefinite in respect of any trade secrets (formulations, proprietary processes) and survive for a minimum of 3 years from the date of disclosure for all other confidential information.
We may disclose confidential information in the following limited circumstances only:
In all other cases, we will obtain your written consent before disclosing any confidential information to any third party.
Every packaging file follows a defined, documented lifecycle from receipt to deletion:
Files are received via our encrypted intake form (Formspree, HTTPS). They are immediately transferred to encrypted cloud storage. The original email or form submission is not used as long-term storage.
A named compliance specialist is assigned. Only that specialist (plus QA reviewer) receives access credentials to your file folder. Access is revoked for all other personnel.
Files are reviewed in the secure cloud environment. No local copies are made to personal devices. Working notes and AI outputs are treated as confidential and stored in the same secure environment.
The compliance report is delivered to you by email. The report references your packaging but does not contain full reproductions of your artwork. Delivery is by secure link or password-protected PDF where sensitive content is involved.
Files are retained for 30 days after report delivery to enable follow-up questions, scope clarifications, or correction requests without requiring re-submission.
At day 30, all packaging artwork files are permanently and irreversibly deleted from all storage locations. A deletion log entry is created (containing only the deletion date and a non-identifiable file reference) for our records.
If you require earlier deletion — for example, immediately after report delivery — please request this by email and we will comply within 2 business days.
Access to client files is governed by the principle of minimum necessary access:
We apply the following technical controls to protect your files:
VeriScan™ uses AI-assisted analysis tools to support (not replace) human review of packaging text. This section explains exactly how AI tools interact with your data.
Only extracted text content (ingredient declarations, mandatory label text, nutritional data) is submitted to AI tools for analysis. Full artwork files, proprietary design elements, and company identity are not transmitted to AI services unless specifically required and agreed with you in advance.
We select AI tool providers that meet the following minimum criteria:
All AI outputs are reviewed by a qualified compliance specialist before inclusion in any report. No AI finding is reported to a client without human verification. Our AI tools are analysis aids — not autonomous decision-makers.
If you prefer that your packaging text is not processed by any AI tool, please state this in the "Additional Notes" field of the intake form. We will perform the audit using manual analysis only. Turnaround time may be extended; we will advise at the time of order.
In the event of a confirmed or suspected unauthorised access to, or disclosure of, your confidential information, we will:
We maintain a documented incident response procedure and test it periodically.
If your procurement or legal team requires a separately signed, bilateral NDA document — for example, to satisfy internal supplier vetting requirements — we are happy to execute one before any files are shared.
Our standard bilateral NDA covers the same scope as this policy in a format suitable for countersignature. It can be executed electronically (DocuSign or equivalent) and returned typically within 2 business days.
To request a standalone NDA, email contact@veriscanaudit.com with the subject line "NDA Request — [Company Name]". Please include your company's registered name and jurisdiction.
We can also review and execute an NDA provided by your legal team, subject to agreement on any material changes to the standard terms.
For any questions about this policy, to request early file deletion, to report a security concern, or to request a standalone NDA:
VeriScan™ — Quantyva™
Email: contact@veriscanaudit.com
Subject: "Data / NDA — [your company name]"
EU Registration: ROONRC.J2024000390307
We take security and confidentiality seriously and treat all such communications with priority.