PRIVACY POLICY

Last Updated: 3 August 2026

1. Who We Are

Vercite AB, reg. no. 559550-9984, a company registered in Sweden ("Vercite", "we", "us", or "our"), operates the Vercite service.

Vercite provides software that helps organizations monitor and analyze how brands appear across AI-powered search and answer platforms.

This Privacy Policy applies to the websites, applications, and services we make available at vercite.io and aibrandtracking.com, and any related applications and services (collectively, the "Service").

Controller and contact. For the processing described in this Policy where we determine the purposes and means of processing, Vercite AB is the data controller. You can reach us regarding privacy matters at support@vercite.io or by post at Körsbärsstigen 32, 134 37 Gustavsberg, Sweden. We have not appointed a Data Protection Officer, as we are not required to do so; privacy enquiries are handled by our management team.

2. Scope and Audience

The Service is intended for organizations and business users, not for consumers. This Privacy Policy explains how we collect, use, store, process, and share information when you access or use the Service.

This Policy describes our processing as a controller. Where we process personal data on behalf of a customer (for example, personal data a customer chooses to include in monitoring configurations), we act as a processor, and that processing is governed by the Data Processing Agreement referenced in Section 8, with the customer as controller.

Children. The Service is not directed to children, and we do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, contact support@vercite.io and we will delete it.

3. Information We Collect

Account Information. When you create an account, we collect your name, email address, company name, authentication credentials (which we store in secure form), and subscription information. Providing this information is necessary to enter into and perform the contract with you; without it, we cannot provide an account.

Billing Information. Payments are processed by third-party payment providers such as Stripe. We do not store complete payment card details.

Brand Monitoring Configuration. To provide the Service, we collect and process the monitoring inputs you configure: brand names, competitor names, topics, queries and prompts, tracking configurations, and other monitoring settings. These inputs are intended to consist of brand, product, market, and topic terms. You should not include personal data, special categories of personal data, or confidential personal information of identifiable individuals in monitoring configurations (see Section 5).

AI Response Data. We collect and store responses generated by, and displayed on, supported AI and search platforms, which may include ChatGPT, Perplexity, Gemini, Microsoft Copilot, Google AI Overview, Google AI Mode, and Google Search, depending on your subscription plan and available integrations.

Technical and Usage Data. We may automatically collect IP address, browser type, device information, operating system, referring pages, usage activity, log data, and cookie and analytics data, subject to the consent requirements described in Section 13.

We process personal data for the following purposes, relying on the legal bases indicated under the EU/EEA General Data Protection Regulation ("GDPR"):

PurposeLegal basis
Creating and managing accounts; providing and operating the ServicePerformance of a contract (Art. 6(1)(b))
Processing subscriptions and paymentsPerformance of a contract; compliance with legal obligations (Art. 6(1)(b), (c))
Collecting and analyzing AI-generated responses and calculating visibility, ranking, citation, sentiment, and other metrics; generating reports and dashboardsPerformance of a contract; our legitimate interests in delivering and improving the Service (Art. 6(1)(b), (f))
Improving product functionality and conducting research and benchmarking (Section 6)Our legitimate interests in developing and improving the Service and producing market insights (Art. 6(1)(f))
Providing customer supportPerformance of a contract; legitimate interests (Art. 6(1)(b), (f))
Preventing abuse, fraud, and security incidentsLegitimate interests; legal obligations (Art. 6(1)(f), (c))
Sending service and, where permitted, marketing communicationsLegitimate interests or consent, as applicable (Art. 6(1)(f) or (a))
Setting non-essential cookies and analyticsConsent (Art. 6(1)(a)) and applicable ePrivacy rules (Section 13)
Complying with legal obligationsCompliance with legal obligations (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms.

5. AI Platforms and Data Processing

A core function of the Service is collecting responses from third-party AI and search platforms.

To provide the Service, we submit customer-configured queries, prompts, brand names, competitor names, and related monitoring information to those platforms. Submissions are made either directly through providers' official interfaces and APIs or through third-party data collection providers engaged by us. We may change these providers over time (see Section 7), and we maintain an appropriate transfer mechanism for any provider that processes personal data outside the EEA.

The Service is designed to reflect real-world user experiences on these platforms. As a result, submitted queries are processed by those platforms under their own terms, privacy policies, and data-handling practices. Depending on the platform, submitted information may be used by that platform for model improvement, training, quality assurance, or other purposes determined by that platform. We do not control how third-party platforms process information once submitted, and we encourage you to review the privacy policies of the relevant providers.

Where we use commercial AI provider interfaces to analyze responses for our own processing purposes, we use provider configurations and API tiers that, under the providers' terms, exclude submitted data from provider model training.

To limit the personal data exposed to third-party platforms:

  • The information we submit generally consists of queries and prompts, brand names, competitor names, and topics and tracking configurations.
  • We do not intentionally submit account credentials, payment information, or unrelated customer personal data to AI platforms.
  • You are responsible for ensuring that monitoring configurations do not contain personal data, special categories of personal data, or confidential information.

Individuals referenced in collected content. Responses collected from AI and search platforms may mention or describe individuals — for example, named executives, authors, or public figures. We collect this content as it appears on those platforms, for the purpose of monitoring how brands and topics are represented. Our legal basis is our legitimate interest, and that of our customers, in monitoring how brands, organizations, and topics are represented on public AI and search platforms (Art. 6(1)(f) GDPR). We do not use this content to build profiles of, evaluate, or make decisions about the individuals concerned, which is central to our assessment that these interests are not overridden by the rights and freedoms of the individuals mentioned. To the extent such content incidentally includes special categories of personal data, it relates to information manifestly made public through the platforms on which it appears (Art. 9(2)(e) GDPR), and we do not use it for any purpose directed at the individual.

Because this content is collected from public platform outputs rather than from the individuals themselves, providing individual notice would involve disproportionate effort within the meaning of Art. 14(5)(b) GDPR; this Policy serves as the public information measure. An individual who believes content held by us relates to them may contact support@vercite.io to request access or erasure, and we will assess the request against the applicable legal basis.

6. Research and Benchmarking

We use collected data to produce industry benchmarks, generate market insights, publish research reports, and analyze trends across industries. Any personal data is anonymized before it is used for these purposes, so that individuals can no longer be identified, directly or indirectly. Such anonymized data is no longer personal data and falls outside this Policy.

Published outputs do not identify any individual. Information about brands and organizations is generally not personal data, and these outputs may name brands, organizations, and other entities that are the subject of monitoring. Where a published output identifies a customer or a customer's brands, we do so on the basis of the permission granted in our Terms of Service — which a customer may withdraw at any time for future outputs — and without disclosing information that is confidential under those Terms.

If we conduct customer-specific research projects, those projects may be governed by separate agreements.

7. Information Sharing and Subprocessors

We share information with the following categories of service providers and recipients:

  • Data collection providers used to submit queries to, and collect responses from, supported AI and search platforms.
  • AI analysis providers used to analyze responses and calculate metrics.
  • Infrastructure providers providing hosting, database, storage, and cloud services.
  • Payment providers used to process subscription payments and billing.
  • Email providers used to send transactional and service communications.
  • Identity providers where you choose to sign in using a third-party account.
  • Support and communication tools used to handle support enquiries.
  • Analytics providers used to understand platform usage and improve performance.

We maintain a list of the subprocessors we engage, identifying each subprocessor and the processing it performs. Customers may obtain the current list on request, subject to confidentiality obligations. Where the identity of a particular provider is commercially sensitive, we describe its role, the processing it performs, and its processing location, and disclose its identity on request. These confidentiality arrangements apply to the list provided to customers; where an individual exercises the right of access under Art. 15 GDPR, we identify the actual recipients of that individual's personal data as that Article requires.

Changes to subprocessors. Where we act as a processor on a customer's behalf, we engage subprocessors under general written authorization. Before adding or replacing a subprocessor, we will inform affected customers of the intended change and provide an opportunity to object on reasonable data-protection grounds, as set out in our Data Processing Agreement. If an objection cannot be resolved, the customer may terminate the affected part of the Service.

Other disclosures. We may disclose information where required by law, legal process, or regulatory request, or to establish, exercise, or defend legal claims. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

8. Data Processing Agreement

Where our provision of the Service involves processing personal data on a customer's behalf in circumstances not outlined in Section 3, that processing is governed by our Data Processing Agreement ("DPA"), which forms part of the agreement between the customer and us and addresses the matters required by Art. 28 GDPR, including subject matter and duration, security measures, subprocessor controls, assistance with data-subject requests, breach notification, and deletion or return of data. The DPA is available on request.

9. International Data Transfers

Customer account data and collected monitoring data are hosted and stored within the European Economic Area.

Some of our service providers process personal data outside the EEA. This applies to providers supporting payments, transactional email, sign-in via third-party identity providers, website analytics, AI analysis, and data collection from AI and search platforms.

Where a recipient is located in a country the European Commission has recognised as providing an adequate level of protection, we transfer on the basis of that decision. For recipients in the United States, this includes certification under the EU–U.S. Data Privacy Framework (and the UK and Swiss extensions, where relevant). Otherwise, we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses, supported by a transfer impact assessment where required.

Non-essential analytics are used only with your consent (see Section 13). You may request information about the mechanism applicable to a specific provider, and a copy of the relevant safeguards (which may be redacted to protect commercially sensitive terms).

10. Data Retention

We retain personal data for as long as necessary to provide the Service, maintain historical reporting and trend analysis, fulfill contractual obligations, comply with legal requirements, and resolve disputes or enforce agreements. Retention periods are determined by the purpose for which data is processed and applicable legal requirements.

Security and authentication logs (such as sign-in records containing IP addresses) are retained for no longer than twelve (12) months from collection, unless a longer period is required for an ongoing security investigation or to establish, exercise, or defend legal claims.

Anonymized information, from which individuals can no longer be identified, may be retained indefinitely.

11. Your Rights

Depending on applicable law, including the GDPR, you have the right to: access your personal data; correct inaccurate data; request deletion; restrict or object to processing — including an unconditional right to object to processing for direct marketing purposes; receive a copy of your data in a portable format; and withdraw consent where processing is based on consent, without affecting prior processing.

You also have the right to lodge a complaint with a data protection supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY").

We do not make decisions producing legal or similarly significant effects concerning individuals based solely on automated processing within the meaning of Art. 22 GDPR.

To exercise your rights, contact support@vercite.io. Where we process personal data on behalf of a customer (as a processor), we will refer your request to that customer as controller and assist them as required.

12. Security

We implement reasonable technical, organizational, and administrative measures designed to protect information from unauthorized access, disclosure, alteration, or destruction. No method of transmission or storage can be guaranteed to be completely secure.

13. Cookies and Analytics

We use cookies and similar technologies to operate the Service and, with your consent, to understand usage, improve functionality, and measure performance.

Strictly necessary cookies, required to provide the Service and maintain security, do not require consent. Non-essential cookies and analytics technologies are set only with your prior consent, obtained through our cookie banner, and you may withdraw consent at any time. Further detail is available in our Cookie Policy.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The current version is available through the Service and shows the effective date above. Where required by law, we will provide additional notice of material changes.

15. Contact Information

Vercite AB Reg. No. 559550-9984 Körsbärsstigen 32, 134 37 Gustavsberg, Sweden Email: support@vercite.io