Last updated: 1 July 2026
This Privacy Policy explains how Vereon (“Vereon”, “we”, “us”, “our”) collects and uses personal data when you use Morph, our data-pipeline platform, together with any related websites, applications and services (the “Service”).
For the personal data described in this policy, Vereon is the controller. If you have any questions about this policy or how we handle your personal data, please contact us at info@vereon.tech.
This policy covers the personal data we process as a controller — for example, information about your account and your use of the Service.
It does not cover the data that flows through the Service on your behalf (“Your Data”). When Morph processes Your Data, we act as a processor on your documented instructions and as needed to provide the Service, and that processing is governed by our Terms & Conditions and, where required, a separate data processing agreement. If you access the Service through an organisation’s account (for example, your employer), that organisation is responsible for its own handling of your personal data.
We collect the following categories of personal data:
We use personal data for the following purposes, relying on the lawful bases under the UK GDPR shown in brackets:
Consistent with our bridge model, Your Data is processed in transit to apply the transformations you configure and is not retained on our servers beyond the transient processing needed to deliver it to your chosen destination. Where Your Data includes personal data, you are the controller and we act as a processor, processing it only on your documented instructions and as needed to provide the Service. Please see our Terms & Conditions for more detail.
We use cookies and similar technologies that are necessary to run the Service and keep it secure. With your consent where required, we also use product-analytics and error-monitoring tools to understand how the Service is used and to diagnose problems. You can control non-essential cookies through your browser settings or any cookie controls we provide.
We share personal data only as needed to run the Service:
We do not sell your personal data.
We primarily host the Service in the UK or European Economic Area. Some of our service providers may process personal data in countries outside the UK. Where they do, we put in place an appropriate safeguard recognised under the UK GDPR — such as the UK International Data Transfer Agreement or Addendum, or reliance on UK adequacy regulations — so that your personal data remains protected.
We keep account data for as long as your account is active and for a reasonable period afterwards. We keep billing records for as long as required by law (for example, for tax purposes). We keep usage and log data for a limited period needed to operate and secure the Service, after which it is deleted or anonymised. Consistent with our bridge model, Your Data is not retained after it has been delivered.
We use appropriate technical and organisational measures to protect personal data, including encryption of data in transit, encryption of credentials you provide for connected services, and access controls. No method of transmission or storage is completely secure, but we work to protect your personal data and to notify you and the relevant authority of any breach where the law requires.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
Under the UK GDPR you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us at info@vereon.tech. We will respond within one month, as required by the UK GDPR. Exercising these rights is free of charge in most cases.
If you have a concern about how we handle your personal data, please contact us first at info@vereon.tech so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at ico.org.uk.
The Service is intended for business users and is not directed at children under 18. We do not knowingly collect personal data from children.
We may update this policy from time to time. If we make material changes, we will take reasonable steps to notify you, for example by email or through the Service. Please check the “Last updated” date above to see when this policy was last revised.
If you have any questions about this policy or wish to exercise your rights, please contact us at info@vereon.tech.