# VeraData Privacy Policy

**Effective date:** July 5, 2026  
**Last updated:** July 5, 2026  
**Operator:** Ivar Garcés (@teodorofodocrispin-cmyk) — Bogotá, Colombia

---

## 1. Who We Are

VeraData is a compliance data API operated by Ivar Garcés, an independent developer based in Bogotá, Colombia. Our API provides sanctions screening, KYB (Know Your Business) verification, and financial data for Latin American jurisdictions.

Contact: teodorofodocrispin@gmail.com  
API: https://api.veradata.dev

---

## 2. What Data We Process

### 2.1 Data You Send Us (Query Data)
When you call our API, you send us:
- **Entity names** — names of companies or individuals you are screening
- **Identifiers** — NIT, CNPJ, RFC, RUT, RUC numbers
- **Country codes** — the jurisdiction of the entity being screened
- **Wallet addresses** — your USDC wallet address used for x402 payment
- **IP address** — collected automatically and stored as a one-way SHA-256 hash (irreversible)

We do **not** store the raw entity names you query beyond what is needed to generate the audit hash. The audit hash is a cryptographic commitment that proves the query occurred without revealing its content.

### 2.2 Data in Our Sanctions and PEP Databases
We maintain:
- **Sanctions lists** — OFAC SDN, UN Consolidated, EU Consolidated, UK HM Treasury. These are official government publications in the public domain.
- **PEP dataset** — Politically Exposed Persons from Wikidata (CC0, public domain). These are public officials exercising public power — their inclusion in compliance databases is explicitly permitted under AML regulations in Colombia (Ley 1581/2012), Brazil (LGPD Art.7), EU (GDPR Art.6(1)(c) and AMLD5), and international FATF standards.

### 2.3 Audit Records
Every paid API call generates an immutable audit record containing:
- Endpoint called
- Country queried
- Payment network and wallet address (payer)
- IP hash (SHA-256, irreversible)
- Timestamp
- Audit hash (SHA-256 chain per EU AI Act Art.12)

These records are never deleted. They constitute the compliance audit trail required by EU AI Act Art.12/13 and FATF R16.

---

## 3. Legal Basis for Processing

| Data Type | Legal Basis |
|---|---|
| Query data (entity names) | Legitimate interest — AML/compliance verification (FATF R16, SARLAFT 2024) |
| PEP data | Public interest — processing of public figures' data for AML compliance is explicitly permitted under AMLD5, LGPD Art.7(II), Ley 1581 Art.10 |
| Sanctions data | Legal obligation — OFAC, UN, EU, UK sanctions lists are mandatory screening sources |
| Audit records | Legal obligation — EU AI Act Art.12, FATF R16 |
| IP hash | Legitimate interest — fraud prevention, trial quota enforcement |
| Wallet address | Contract performance — required for x402 payment processing |

---

## 4. Data Retention

| Data | Retention |
|---|---|
| Audit records (vera_audit) | Indefinite — required for compliance audit trail |
| PEP entries | Updated daily, replaced on sync |
| Sanctions entries | Updated on sync from official sources |
| Trial quotas (IP hash) | 24 hours rolling window |
| Stream tokens | 5 minutes (TTL enforced) |
| KYB monitor records | Until cancelled by payer |

---

## 5. Data Sharing

We do **not** sell your data. We do not share query data with third parties.

We use the following sub-processors:
- **Supabase** (supabase.com) — database storage, hosted on AWS us-east-1
- **Render** (render.com) — API hosting, hosted on AWS us-east-1
- **Coinbase Developer Platform** — x402 payment verification
- **Wikidata** (wikimedia.org) — PEP data source (public domain)
- **GDELT Project** (gdeltproject.org) — adverse media data (public domain)

---

## 6. Your Rights

If personal data about you appears in our PEP dataset (because you are or were a public official), you have the right to:
- **Know** what data we hold about you
- **Correct** inaccurate data
- **Request deletion** — subject to our legal obligations to maintain AML screening capability

Note: We cannot remove individuals from official government sanctions lists (OFAC, UN, EU, UK) as those are published by their respective governments, not by VeraData.

To exercise your rights: teodorofodocrispin@gmail.com

---

## 7. International Transfers

Data is stored in the United States (AWS us-east-1 via Supabase and Render). Transfers from the EU/EEA are covered by Standard Contractual Clauses in Supabase's and Render's DPAs. Transfers from Brazil are covered under LGPD Art.33(II).

---

## 8. Disclaimer

VeraData provides data for informational purposes only. Results do not constitute legal advice, compliance advice, or a definitive risk determination. Operators are responsible for their own compliance programs and decisions based on VeraData output.

---

## 9. Changes

We will update this policy as needed. Material changes will be announced via our llms.txt and GitHub repository.

---

*VeraData — LATAM Compliance Data for Autonomous AI Agents*  
*api.veradata.dev | github.com/teodorofodocrispin-cmyk/veradata-public*
