GDPR Statement
Who we are
VervePartners Ltd.
Our website address is: www.vervevero.com
Our commitment to your privacy
Protecting personal data is a core priority at Verve. As an ISO 27001-certified organisation, we maintain robust information security practices and are committed to handling personal data lawfully, transparently, and securely.
Verve complies with all applicable data protection legislation, including the UK GDPR, EU GDPR, and the California Consumer Privacy Act (CCPA), where relevant.
How we ensure compliance
We maintain GDPR and CCPA compliance through a comprehensive governance framework that includes:
Regular audits of all data capture points, both internal and external.
Documented, auditable policies and procedures that are reviewed and updated on a regular basis.
A maintained inventory of personal data under our control, alongside ongoing reviews of technical and organisational safeguards to ensure adequacy.
Risk assessments with documented mitigation plans for any identified risks.
Continuous monitoring of regulatory guidance, including updates from the Information Commissioner’s Office (ICO) and other supervisory authorities.
Ongoing training and awareness, including attendance at relevant briefings, workshops, and industry events.
Specialist data protection support, with a retained consultancy (The Trustbridge) providing expertise and support to our Data Protection Officer (DPO).
Governance and oversight
Verve has an internal data protection working group comprising senior management, including the Head of IT, Privacy Officer, and Executive Director of Operations. This group oversees GDPR and CCPA implementation, ensures continued ISO 27001 compliance, and manages a monthly internal audit programme designed to test and validate regulatory and information security controls.
Our approach
We are committed to delivering an excellent customer experience while continuously adapting our operations to meet evolving legal and regulatory requirements. We work proactively to keep our clients, partners, and regulatory authorities informed of relevant changes.
Our Information Security Policy is available upon request.