Skip to content
Legal

Privacy policy

Last updated Effective from

1About this policy

This policy explains how RampVera Limited (“RampVera”, “we”, “us”) handles personal data. It covers our website at rampvera.com and the RampVera platform.

It should be read alongside our Cookie Policy, which lists the specific cookies we set and what each one is for.

Who we are

RampVera Limited
278 Argyle, Custom House Harbour, IFSC, Dublin 1
Registered in Ireland, company number 821904
VAT number IE 4763636SH

Email: privacy@rampvera.com

2The two roles we play

Which half of this policy applies to you depends on why we hold your data.

When we are the controller. For people who visit our website, ask about the product, sign up for a trial, or administer or pay for an account, we decide why and how their data is processed. This policy describes that processing, and it is the document that governs it.

When we are a processor. RampVera is a tool organisations use to onboard their own sales staff. When a customer puts information about their employees into the platform (training progress, assessment results, notes from managers), that customer decides what goes in and why. They are the controller; we act on their instructions.

If you use RampVera because your employer provides it

Your employer’s privacy notice governs your data, not this policy. Questions about what is recorded about you, who can see it, and how long it is kept should go to your employer first. We will help them answer, but we are not permitted to make those decisions ourselves, or to give you access to your data or delete it without their instruction.

What we owe our customers in that processor role is set out in our Data Processing Agreement, which forms part of the customer contract.

3What we collect and why

Everything in this section describes our activity as a controller.

3.1  Website visitors and prospective customers

What Why Legal basis
Your name, work email, company, the approximate size of your sales team and whatever you write in the form on our Your Numbers page Responding to your enquiry and following up about the product Steps taken at your request before entering a contract (Article 6(1)(b)). For follow-up beyond your original enquiry, our legitimate interest in marketing our product to businesses that have shown interest (Article 6(1)(f))
Your IP address and request metadata, in our server logs Keeping the service available and defending it against abuse Our legitimate interest in operating a secure service (Article 6(1)(f))
Your answer to our cookie notice: a list of the categories you allowed, and nothing else So we do not ask again on every page, and so nothing optional is ever set for someone who declined Our legitimate interest in honouring the answer you gave (Article 6(1)(f))

We do not track you. There is no analytics tool on this site, no advertising or retargeting, and nothing that follows you to another website. We do not measure which pages you visit and we do not build a profile of your visit. Our Cookie Policy lists every cookie we set and how long each one lasts.

3.2  Account administrators and users

What Why Legal basis
Your name, work email, password and role within the account. Passwords are stored only as a cryptographic hash and are never held in a form anyone can read, including us Creating and securing your account, and applying the right permissions Performance of our contract (Article 6(1)(b))
Sign-in times, the IP address and browser you signed in from, and a record of significant actions taken in the account Detecting unauthorised access, investigating security incidents, and giving an account’s administrators an audit trail of what happened in it Our legitimate interest in securing the service and protecting our customers’ data (Article 6(1)(f))
Support messages and their contents Answering your question and improving our documentation Performance of our contract (Article 6(1)(b))
Server logs recording what failed, when, and which account and user were involved Finding and fixing faults Our legitimate interest in a reliable service (Article 6(1)(f))

3.3  Billing contacts

We invoice customers directly and do not take card payments, so we do not handle card details at any point. To issue an invoice we need a billing contact name, email, postal address and VAT number, and we keep the invoices and the accounting records behind them. The first is performance of our contract (Article 6(1)(b)); the second is a legal obligation under Irish tax and company law (Article 6(1)(c)).

Where a customer is in another EU member state, we confirm their VAT number against the European Commission’s VIES service to apply the correct VAT treatment. That involves sending the VAT number to the Commission’s system.

3.4  A note on our legitimate interests

Where we rely on legitimate interests above, we have considered whether our interest is outweighed by the interests and rights of the people affected. In each case the processing is limited to what the purpose needs, is what a person would reasonably expect from a business tool of this kind, and does not involve profiling or automated decisions about individuals. You can object to any of it at any time (see section 9).

4Our use of AI

RampVera does not currently use AI to process personal data.

Parts of the product are designed around AI assistance (proposing which indicators a track should measure, for example), and you will see that described on our website. Those features do not yet send anything to a model. No prompt, no employee record and no account data leaves the application for AI processing today.

When that changes, this section will be rewritten before the feature ships, not after, and the following will hold:

  • Where it runs. AI processing will use Amazon Bedrock in the European Union. Requests will be processed within the EU and will not be routed to model providers outside it.
  • What we log. Records of AI requests will hold metadata only: when a request happened, which account made it, which model was used and how long it took. We will not retain the content of prompts or responses in those logs.
  • Human oversight. AI output will not be used to assess any customer’s employee without a person deciding. If that ever changes, this policy is updated first.
  • Telling you when it is AI. Where you are interacting with an AI feature rather than a person, we will make that clear in the interface.

5Who else processes data for us

We use a small number of service providers. Each is bound by contract to process data only on our instructions and to keep it secure.

Provider What they do Where
Amazon Web Services EMEA SARLLuxembourg Hosting, database, file storage and transactional email Dublin, Ireland eu-west-1
Google Ireland Limited Our own business email, calendar and documents, so any correspondence you send us is processed there EU and US

We do not sell personal data, and we do not share it with advertising networks.

We will disclose data to a public authority only where we are legally required to. Where we are permitted to tell the affected customer, we will.

6Where your data is held

We host RampVera in Dublin, Ireland. Customer content (everything your organisation puts into the platform) stays within the European Union, including in backups. Our supporting services are configured to keep data within the European Union.

One exception, and it is only about correspondence. Google Ireland Limited provides our business email, calendar and documents, so anything you send us by email (an enquiry, a support request) is processed on Google’s systems, and Google may process it outside the European Economic Area, including in the United States. Those transfers are covered by the Standard Contractual Clauses in Google’s data processing terms and by the EU–US Data Privacy Framework, under which Google LLC is certified.

This applies to correspondence with us only. Content your organisation puts into the RampVera platform is held in the European Union and is not processed through these services.

7How long we keep things

What How long Why that long
Account data While the account is open, then 30 days A short window to reverse an accidental closure, after which it is deleted
Customer content in the platform On our customer’s instruction, then deleted or returned as their contract requires It is theirs, not ours
Invoices and accounting records 6 years from the end of the relevant tax year Required by Irish tax law
Server and access logs 180 days Long enough to investigate a security incident and to spot a recurring fault
Enquiries from prospective customers 24 months from your last contact with us After that we assume you are not interested
Your answer to the cookie notice 6 months Then we ask again
Backups Up to 90 days, then overwritten Backups roll on a fixed cycle

About backups. When we delete something it goes from the live service straight away, but a copy may remain in a backup until that backup is overwritten on the schedule above. Backups are not used for anything except restoring the service after a failure.

8How we protect data

We encrypt data in transit and at rest. Access to production systems is limited to staff who need it, protected by multi-factor authentication, and logged. We keep our dependencies patched and review changes to the code before they ship.

If a breach affects your personal data and is likely to pose a high risk to you, we will tell you. Where we act as a processor, we notify the customer without undue delay so they can meet their own obligations.

9Your rights

Under the GDPR you can ask us to:

  • give you a copy of the personal data we hold about you
  • correct it if it is wrong
  • delete it
  • restrict what we do with it, or object to processing we base on legitimate interests
  • provide it in a portable format, or send it to another provider
  • withdraw consent you have given, at any time; this does not affect what we did before you withdrew it

Write to privacy@rampvera.com. We will respond within one month. There is no charge, and we will not treat you differently for asking.

If you use RampVera through your employer, send your request to them rather than to us. As explained in section 2, we cannot act on it directly. If you contact us anyway, we will pass it on and tell you we have done so.

You can also complain to a data protection authority. Ours is the Irish Data Protection Commission (dataprotection.ie), and you may equally complain to the authority where you live or work.

10Changes

We will update this policy as our service changes. When a change materially affects how we handle your data, we will tell affected customers directly rather than relying on you noticing the date at the top of this page.

11Contact

Questions about this policy, or about how we handle your data: privacy@rampvera.com.

RampVera Limited
278 Argyle, Custom House Harbour, IFSC, Dublin 1