Privacy Policy

Last updated: August 29, 2026

This Privacy Policy explains how VERLYN S.R.L., a company registered in Romania (Unique Registration Code / CUI: 55429086; European Unique Identifier / EUID: ROONRC.J2026049878000; registered with the Trade Registry Office attached to the Bucharest Tribunal, registration number J2026049878000), with registered office at Bulevardul Dinicu Golescu, Nr. 7, Etaj Parter, Ap. SP. COM. 3, Sector 1, Bucharest, Romania ("Verlyn," "we," "us," or "our"), collects, uses, and protects information in connection with the Verlyn platform (the "Service").

Verlyn provides AI-assisted content creation, personalization, and (where authorized) publishing tools for B2B sales and marketing teams on LinkedIn, along with lead list curation features. This policy is written to reflect what Verlyn actually does, not generic boilerplate — please read it in full if you're evaluating whether the Service is right for your organization.

1. Who this policy covers

Verlyn is a business-to-business (B2B) product. Our direct customers are companies ("Organizations"), and individual users ("Users" or "Reps") access the Service as members of an Organization, typically through a company email address. This policy covers:

  • Users — employees of a customer Organization who log into and use Verlyn directly.
  • Leads — individuals whose business contact information (such as name, job title, company, email address, or phone number) is surfaced within Verlyn as part of lead list curation, sourced from third-party data providers. Leads have not directly interacted with Verlyn and have not provided their data to us directly — see Section 5.
  • Visitors to our marketing website who have not created an account.

2. Information we collect

  • Account and profile information. Name, work email, role, and organization affiliation when a User is invited to or signs up for Verlyn.
  • Voice and style data. To personalize AI-generated content, we may process writing samples a User provides or authorizes us to access (for example, prior LinkedIn posts), and we derive a stored "style profile" used to generate future drafts in that person's voice.
  • Grounding content. Information Users or their Organization's marketers submit to make AI-generated content specific and accurate — for example, manually entered notes about recent work, or bulk-uploaded spreadsheets/CSV files containing similar notes per Rep. This may include references to deals, customers, or business activity that the Organization chooses to share with us.
  • Lead and contact data. Business contact information (name, title, company, email, phone number) for individuals identified as potential leads, sourced through Apollo.io ("Apollo"), a licensed business contact data provider, and surfaced within Verlyn for an Organization's own sales use. We do not collect this data by directly scraping LinkedIn or any social platform; it is licensed through Apollo. See Section 5 for more on this.
  • LinkedIn account data (where connected). If a User authorizes Verlyn to connect to their LinkedIn account, we access only the data covered by the specific permissions ("scopes") the User approves during that authorization — for example, the ability to publish a post on their behalf. We do not access a User's private messages, connections list, or browsing activity on LinkedIn, and we do not have the technical ability to identify who has liked or commented on a LinkedIn post through this connection — that information is not made available to third-party applications like ours by LinkedIn. Where our product surfaces a possible match between a lead and someone who engaged with a post, this is based on information the User themselves enters after reviewing their own LinkedIn notifications, not on data we pull automatically.
  • Content and usage data. Drafts generated by our AI, edits Users make to those drafts, approval/compliance-review records, and engagement metrics for content published through the Service (where available via LinkedIn's official reporting tools).
  • Technical data. Standard web/app usage data such as IP address, browser type, device information, and log data, collected automatically when you use the Service.

3. How we use information

We use the information above to:

  • Generate, personalize, and route AI-drafted content for review and approval within an Organization's workflow.
  • Operate compliance and review features, including checks against brand-approved content and applicable platform rules.
  • Allow marketers within an Organization to curate lead lists for their own Reps' use.
  • Where an Organization has enabled it, sync Rep-logged interaction notes to that Organization's own HubSpot account, so their CRM reflects activity that happened in Verlyn.
  • Publish content to LinkedIn on a User's behalf, but only after that User has both authorized the connection and separately approved the specific piece of content.
  • Improve the quality of AI-generated drafts over time based on how Users edit generated content and how published content performs.
  • Provide customer support, maintain security, and comply with legal obligations.
  • Communicate with Users and Organization administrators about the Service.

4. Legal basis for processing (for individuals in the EU/EEA/UK)

Where GDPR or equivalent law applies, we rely on the following legal bases:

  • Contract — processing User account data is necessary to provide the Service the Organization has subscribed to.
  • Legitimate interest — processing lead/contact data for B2B sales outreach purposes, balanced against the individual's rights. Organizations using Verlyn are responsible for ensuring their own outreach activity complies with applicable law (including ePrivacy/marketing consent rules where relevant).
  • Consent — where a User explicitly authorizes a LinkedIn connection or provides voice/style samples.

5. Where lead and contact data comes from

We want to be direct about this rather than vague: Verlyn does not scrape LinkedIn or any other platform to build lead lists. Contact data surfaced in the Service is sourced from Apollo.io, a licensed business data provider, under our agreement with them. Apollo is responsible for the original collection and lawful basis of that data; our role is to make it usable within an Organization's Verlyn workspace. If you are a Lead and want more detail on how your business contact information was originally sourced, we can direct you to Apollo's own privacy disclosures.

6. Sub-processors and third parties

We use the following service providers to operate Verlyn:

  • Hosting and database infrastructure: Supabase, hosted in the EU (Frankfurt, Germany — eu-central-1 region).
  • AI/LLM processing: content generation is processed through Anthropic's Claude API, which involves sending draft content and grounding notes to Anthropic for processing.
  • Lead/contact data provider: Apollo.io.
  • CRM sync (where an Organization enables it): HubSpot — Rep-logged interaction notes are pushed to the Organization's own HubSpot account. This is push-only; Verlyn does not read data back from HubSpot.
  • Payment processing: [PLACEHOLDER — once selected]
  • LinkedIn: for authorized publishing and, if applicable, analytics, subject to LinkedIn's own privacy policy and terms.

7. International data transfers

Verlyn's primary database infrastructure is hosted within the European Union (Frankfurt, Germany), so personal data processed through the Service is generally not transferred outside the EU/EEA by virtue of hosting. Some sub-processors (see Section 6) may process data outside the EU/EEA in connection with providing their services to us — where this occurs, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or the sub-processor's own equivalent certified mechanism, as required by applicable law. [PLACEHOLDER — confirm the specific transfer mechanism/safeguard actually in place for each non-EU sub-processor once data processing agreements are finalized; this still needs legal review to confirm accuracy for each named vendor.]

8. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to our processing of your personal data, and to receive a copy of your data in a portable format. To exercise these rights, contact us at contact@verlyn.ai. If you are a Lead whose contact information appears in an Organization's account and you wish to have it removed, we will honor that request and will also flag it to the originating data provider where applicable.

Romanian and EU residents also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) or their local data protection authority.

9. Data retention

[PLACEHOLDER — define retention periods, e.g. "Account and content data is retained for the duration of an active subscription plus [X] days after cancellation. Lead data is retained per the terms of our data provider agreement." Requires a business decision before publication.]

10. Security

We use reasonable administrative, technical, and physical safeguards designed to protect information processed through the Service, including access controls scoped per Organization so that one company's data is not visible to another. No system is completely secure, and we cannot guarantee absolute security.

11. Cookies

Our website and application may use cookies or similar technologies for authentication, security, and basic analytics. [PLACEHOLDER — expand once analytics/cookie tooling is finalized, and add a cookie consent mechanism if required for EU visitors.]

12. Children's privacy

The Service is intended for business use by adults and is not directed at individuals under 18. We do not knowingly collect data from children.

13. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to Organization administrators, and the "Last updated" date above will be revised.

14. Contact us

Questions about this policy or our data practices can be sent to contact@verlyn.ai, or by mail to Verlyn S.R.L., Bulevardul Dinicu Golescu, Nr. 7, Etaj Parter, Ap. SP. COM. 3, Sector 1, Bucharest, Romania.

This document is a draft prepared for early-stage development purposes and contains placeholders for information not yet finalized (legal entity, hosting region, sub-processor names, retention periods). It should be reviewed by qualified legal counsel, particularly for GDPR compliance, before publication or use with real customer or lead data.