Morph

Privacy Policy

Last updated: 1 July 2026

1. Who We Are

This Privacy Policy explains how Vereon (“Vereon”, “we”, “us”, “our”) collects and uses personal data when you use Morph, our data-pipeline platform, together with any related websites, applications and services (the “Service”).

For the personal data described in this policy, Vereon is the controller. If you have any questions about this policy or how we handle your personal data, please contact us at info@vereon.tech.

2. Scope of This Policy

This policy covers the personal data we process as a controller — for example, information about your account and your use of the Service.

It does not cover the data that flows through the Service on your behalf (“Your Data”). When Morph processes Your Data, we act as a processor on your documented instructions and as needed to provide the Service, and that processing is governed by our Terms & Conditions and, where required, a separate data processing agreement. If you access the Service through an organisation’s account (for example, your employer), that organisation is responsible for its own handling of your personal data.

3. Personal Data We Collect

We collect the following categories of personal data:

  • Account data — such as your name, email address, profile image, and the organisation you belong to. Sign-in credentials are handled by our authentication provider.
  • Billing data — your plan and subscription and transaction details. Payments are handled by our payment provider; we do not store full payment-card numbers.
  • Usage and device data — such as log data, IP address, browser and device information, and how you interact with the Service.
  • Communications — the content of messages you send us, for example support requests.

4. How We Use Personal Data and Our Lawful Bases

We use personal data for the following purposes, relying on the lawful bases under the UK GDPR shown in brackets:

  • to provide, operate and secure the Service and manage your account (performance of our contract with you);
  • to take payment for paid plans and to detect and prevent fraud (performance of a contract; our legitimate interests in securing payment and preventing fraud);
  • to improve, troubleshoot and analyse use of the Service (our legitimate interests in maintaining, securing and improving the Service);
  • to communicate with you about the Service, including service and security notices (performance of a contract; our legitimate interests in keeping you informed about the Service);
  • to send you marketing communications where you have chosen to receive them (your consent, which you may withdraw at any time); and
  • to comply with our legal and regulatory obligations (compliance with a legal obligation).

5. Your Data & Our Processor Role

Consistent with our bridge model, Your Data is processed in transit to apply the transformations you configure and is not retained on our servers beyond the transient processing needed to deliver it to your chosen destination. Where Your Data includes personal data, you are the controller and we act as a processor, processing it only on your documented instructions and as needed to provide the Service. Please see our Terms & Conditions for more detail.

6. Cookies & Analytics

We use cookies and similar technologies that are necessary to run the Service and keep it secure. With your consent where required, we also use product-analytics and error-monitoring tools to understand how the Service is used and to diagnose problems. You can control non-essential cookies through your browser settings or any cookie controls we provide.

7. Who We Share Personal Data With

We share personal data only as needed to run the Service:

  • Service providers who process personal data on our behalf, including cloud hosting and authentication (Amazon Web Services), payment processing (Stripe), product analytics (Mixpanel) and error monitoring (Sentry);
  • Third-party services you choose to connect through Morph (for example, Xero, Google Drive or an SFTP destination), whose own privacy policies then apply to their processing; and
  • Public authorities, advisers or other parties where we are required to share data by law, or to establish, exercise or defend legal claims.

We do not sell your personal data.

8. International Transfers

We primarily host the Service in the UK or European Economic Area. Some of our service providers may process personal data in countries outside the UK. Where they do, we put in place an appropriate safeguard recognised under the UK GDPR — such as the UK International Data Transfer Agreement or Addendum, or reliance on UK adequacy regulations — so that your personal data remains protected.

9. How Long We Keep Personal Data

We keep account data for as long as your account is active and for a reasonable period afterwards. We keep billing records for as long as required by law (for example, for tax purposes). We keep usage and log data for a limited period needed to operate and secure the Service, after which it is deleted or anonymised. Consistent with our bridge model, Your Data is not retained after it has been delivered.

10. Security

We use appropriate technical and organisational measures to protect personal data, including encryption of data in transit, encryption of credentials you provide for connected services, and access controls. No method of transmission or storage is completely secure, but we work to protect your personal data and to notify you and the relevant authority of any breach where the law requires.

11. Automated Decision-Making

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

12. Your Rights

Under the UK GDPR you have the following rights in relation to your personal data:

  • to access a copy of your personal data;
  • to have inaccurate personal data corrected;
  • to have your personal data erased in certain circumstances;
  • to restrict or object to our processing in certain circumstances;
  • to data portability; and
  • to withdraw any consent you have given, at any time.

To exercise any of these rights, please contact us at info@vereon.tech. We will respond within one month, as required by the UK GDPR. Exercising these rights is free of charge in most cases.

13. Complaints

If you have a concern about how we handle your personal data, please contact us first at info@vereon.tech so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at ico.org.uk.

14. Children

The Service is intended for business users and is not directed at children under 18. We do not knowingly collect personal data from children.

15. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will take reasonable steps to notify you, for example by email or through the Service. Please check the “Last updated” date above to see when this policy was last revised.

16. Contact

If you have any questions about this policy or wish to exercise your rights, please contact us at info@vereon.tech.

← Back to sign in