3 deals liveRTX 50 + Server ROK

Shop deals
Get a quote

Privacy notice

Privacy and cookies

What information VeriLicense collects, why we use it, how long we keep it, and how to contact us about your data.

Last reviewed · 29 August 2026

Who this applies to

This notice is for visitors to verilicense.co.uk and for people who contact us, request a quote, register as a broker or place an order. Most VeriLicense enquiries are business-to-business — for enterprise IT licences, server memory, networking and AI server builds — so the information involved is typically business contact details and other personal data used in a business, rather than consumer, context.

AN 1 IT LTD is the data controller. Company number 15734524, registered in England and Wales. Registered office: The Shard Floor 22 Office 12, London Bridge Street, London, Greater London, England, SE1 9SG.

Information we collect

When you contact us, submit a form or place an order, we may collect:

  • Contact and business details you submit through forms — name, business email address, company name, phone number, VAT number where supplied.
  • Quote requirements — product names, SKUs, quantities, server models and compatibility information you provide.
  • Broker programme details — purchasing volume bands, product interests, business type and qualifying answers from the broker registration form.
  • Order, invoice and fulfilment details where a purchase is made, and licence-key delivery records.
  • Basic website analytics and security logs used to operate the site (see Cookies and analytics below).

We do not ask for unnecessary personal information, and we never ask for payment-card details by email or over the phone.

Why we use your information

We use the information you provide to respond to enquiries, prepare quotes, discuss product availability, fulfil orders, support brokers, manage the customer relationship and maintain accurate accounting and business records. Our lawful bases under UK GDPR are legitimate interests (running the supplier relationship), contract (where you have asked us to quote or supply) and legal obligation (tax and accounting record-keeping).

Forms, email and where data is stored

When you submit the quote form, the broker registration form or add an item to the basket and proceed to checkout, the details are processed so we can respond. Form submissions are written to our database (Supabase, hosted in the EU) and a notification is sent to the VeriLicense sales inbox via our transactional email provider (Resend). Replies from our team go from a VeriLicense email address.

The website itself is hosted on Vercel. Database access is restricted to authenticated staff via our admin area; the database has row-level security enabled and no public read access to enquiries, quotes or broker records.

Who we share it with

Where it is genuinely necessary to handle your enquiry, quote or order, we may share relevant information with:

  • Trusted suppliers, distributors and manufacturers — to check availability, source product or arrange licensing.
  • Fulfilment and delivery providers — for physical hardware shipments and licence-key delivery.
  • Payment providers — when a paid order goes through (see Orders and payments below).
  • Service providers that run the website on our behalf — currently Vercel (hosting and analytics), Supabase (database), Resend (email), Crisp (user-initiated support chat), Google (Analytics and Ads conversion measurement) and OpenAI (Ads conversion measurement). Their processor or controller role depends on the service and data involved, as described in their applicable privacy and data-processing terms.

We only share what is necessary for the specific purpose. We do not sell your information, and we do not share it for third-party marketing.

Some providers may process information outside the UK. Where a destination is not covered by UK adequacy regulations, we use the provider's applicable UK International Data Transfer Agreement, UK Addendum to standard contractual clauses, or another lawful safeguard, together with proportionate security controls. Vendor details are available in the privacy notices for Vercel, Supabase, Resend, Crisp, Google and OpenAI.

Support chat

Live support is provided through Crisp and loads only when you choose a support topic. At that point we give Crisp the chosen topic, page title, site origin and page path, plus the message you send. We remove the entire page query and fragment from both the browser address and conversation context before Crisp loads. Crisp may also receive your IP address and technical/session information needed to operate the chat.

We use this information to answer the support request and manage the resulting customer or supplier conversation. Crisp's functional storage names begin crisp-client. Its primary chat-session storage (a cookie and browser-storage mirror) normally lasts up to six months and can be renewed on a return visit; connection state is session-based. If cookies are disabled, Crisp may leave a local-storage capability marker until you clear browser data. Crisp says a server session with no message is normally destroyed around 30 minutes after last access, while a session containing messages remains until it is deleted. We delete chat content when it is no longer needed to answer or manage the request. If it forms part of an order, payment or dispute record, it follows the six-year business-record period described below. See Crisp's cookie list and cookie-policy explanation.

Orders and payments

Card payments are processed by Stripe, our active payment processor. Card details are entered into a Stripe-hosted payment page, handled by Stripe, and never stored directly by VeriLicense. We receive a transaction reference, an indicator of card type, the billing details you supplied, and (if you entered them on the Stripe page) your company name and VAT number for the receipt. We do not receive your full card number.

Stripe processes UK and EU cardholder data under UK GDPR and the Data Protection Act 2018 as a separate data controller for the payment information you enter on its hosted page. Stripe's privacy policy explains how it handles that data: stripe.com/gb/privacy.

Order, invoice and fulfilment records are kept so we can complete the transaction, issue documentation, deliver licence keys, and meet accounting and tax obligations.

Cookies and analytics

We use a small number of cookies and similar storage. Some are essential; we also use analytics and advertising measurement.

  • Essential — small bits of storage we need to make the site work, for example to keep your basket between pages or to keep you signed in to the broker area after you log in.
  • Analytics (optional).If you select Analytics, we use Google Analytics 4, Vercel Analytics and Vercel Speed Insights to understand page use and performance. Their tags do not load until you make that choice. You can also use Google's GA opt-out add-on at tools.google.com/dlpage/gaoptout.
  • Advertising measurement (optional).If you select Advertising measurement, Google Ads and OpenAI Ads tags measure which accepted ad clicks lead to a quote request or order. We keep ad personalisation and remarketing consent denied in this release. Google and OpenAI may use measurement cookies and similar browser storage after this choice. See Google's cookie information and OpenAI's privacy policy. Google's advertising controls are at myadcenter.google.com.
  • Consent choice. The essential vl_cookie_consent cookie records the purposes you selected, the notice version and the time of your choice for up to 180 days. It does not contain your name, email or ad click.
  • Security — the hosting platform keeps short-lived security logs (including IP addresses and request paths) used to operate the site and rate-limit abuse. This does not depend on optional analytics consent.

The current cookie and browser-storage inventory is below. Vendor durations are their default maximums; browser privacy controls may shorten them.

  • Essential basket and sign-in storage. The first-party local-storage key verilicense-cart-v1keeps your basket until you clear the basket or remove browser data. Supabase authentication cookies beginning sb-keep an authenticated broker session available until you sign out, the session expires, or you remove browser data. During a successful checkout, a session-storage key beginning vl-order-confirmation-start- times a short order confirmation retry window; it remains only until the browser tab or session closes.
  • User-initiated support chat.Crisp's functional storage names begin crisp-client. Its primary chat-session storage (a cookie and browser-storage mirror) normally lasts up to six months and can be renewed on a return visit; connection state is session-based. If cookies are disabled, Crisp may leave a local-storage capability marker until browser data is cleared. Crisp does not load until you choose a support topic. See the Support chat section and Crisp links above.
  • Google Analytics 4. First-party cookies _ga and _ga_<id>distinguish a browser and keep session state for up to two years, with their expiry refreshed on use. See Google's GA4 cookie reference.
  • Google Ads. First-party cookies beginning _gcl_ and, where applicable, _gac_keep ad-click and campaign measurement information for up to 90 days. Google Conversion Linker may also use the persistent local-storage key _gcl_ls; we remove it when you reject or withdraw Advertising measurement. See Google's cookie durations and Conversion Linker reference.
  • OpenAI Ads. The first-party __oppref click-reference cookie lasts up to 30 days; the __obref browser-reference cookie up to 365 days; and the __oaiq_consent preference cookie up to 30 days. The matching local-storage preference oaiq_consent has no built-in expiry. They are only available after Advertising measurement is accepted. On withdrawal we remove OpenAI click/browser references and ensure neither preference store can retain a prior truechoice. See OpenAI's conversion-measurement explanation and current public Pixel runtime.
  • Site conversion de-duplication. After a consented analytics or advertising event is handed to its browser tag, first-party session-storage keys beginning vl-ads-, vl-ga4-, vl-quote-success- or vl-openai-ads-prevent that same event being sent twice. They last only until the browser tab or session closes.
  • Vercel.Web Analytics does not set cookies; its privacy-preserving visitor hash resets daily. Speed Insights uses no persistent visitor storage and reports anonymous, per-page Web Vitals. See Vercel's Web Analytics privacy information and Speed Insights privacy information.

When you accept Advertising measurement and then submit a form or place an order, we send Google a securely hashed (SHA-256) version of your email address so it can match the conversion to an ad click. Google receives the hash, not your readable email. This never happens without your consent.

We use Google Ads and OpenAI Ads conversion tracking as described above. For OpenAI Ads purchase measurement, we send the order value, currency, order reference and purchased product details; the event sets opt_out to opt out of future user-level personalisation and does not include raw customer contact details. The OpenAI pixel may set a first-party referrer cookie and, if Automatic Advanced Matching is enabled in the advertising account, may hash supported customer information in the browser. None of this tag processing starts unless you select Advertising measurement. We do not currently use Facebook, LinkedIn or TikTok pixels on this site.

Our lawful basis for analytics and advertising cookies is your consent. You can accept or reject each purpose separately and withdraw either choice at any time using “Cookie settings” in the footer. Withdrawal updates the vendor consent state, prevents further optional capture and removes the optional vendor cookies that this site can access. Essential storage relies on our legitimate interest in running the site.

How long we keep information

We keep enquiry, quote and order records for as long as needed to manage the relationship, answer follow-up questions and meet accounting requirements (typically six years from the end of the relevant tax year for financial records). Broker accounts are kept while the broker relationship is active and for a reasonable period afterwards. We do not copy advertising click IDs or campaign parameters into enquiry, order or payment records. Optional analytics and advertising providers retain their own measurement data under the settings and policies linked above.

Your rights

Under UK GDPR you have the right to ask what we hold about you, to ask us to correct it, to ask us to delete it where we no longer need it, to object to processing based on legitimate interests, and to ask for a copy of your data in a portable format. We will respond within one month.

If you are unhappy with how we have handled your information, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk. We would always prefer the chance to put things right first — please contact us before you do.

Contact us about privacy

For anything in this notice — a question, a correction, a request to stop being contacted about a specific enquiry, or a formal data-rights request — email sales@verilicense.co.uk with enough detail for us to identify the enquiry or account. We read this inbox during UK business hours and will reply within one working day.

Changes to this notice

We update this notice when the site or how we handle data meaningfully changes — for example, if we add a new analytics or marketing provider, or change payment processor. The “Last reviewed” date at the top of the page records the most recent change.