Last updated: 24 September 2026
This policy explains what personal data Fortis Ventures Ltd collects when you use Verbier, why we collect it, who we share it with, how long we keep it and what your rights are. It covers our website at https://verbier.dev (including the homepage demo, the dashboard, checkout and the documentation at /docs) and our API at https://api.verbier.dev.
1. Who we are and how to contact us
1.1 Fortis Ventures Ltd ("we", "us" or "Verbier") is a private limited company registered in England and Wales under company number 14849535. Our registered office is C/O Aardvark Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, BH21 7SB, United Kingdom. We trade as "Verbier".
1.2 For anything about this policy or your personal data, including exercising your rights or making a complaint, email hello@verbier.dev.
1.3 This policy is written to meet our obligations under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018. Where the EU GDPR also applies to our processing, for example for visitors in the European Economic Area ("EEA"), we handle your personal data in the same way.
1.4 In this policy, "Service" means the website, the homepage demo, accounts, the dashboard, checkout, the documentation and the API; "API" means our application programming interface at https://api.verbier.dev; "Customer Content" means the images, image URLs and other material sent to the API; and "Output" means the images and data the API returns. These terms have the meanings given in our Terms of Service at /terms.
2. Our two roles: controller and processor
2.1 We are the controller (we decide why and how the data is used) for personal data we process:
(a) to run your account, including sign-in and API keys;
(b) to bill you and take payments;
(c) to run and secure our website and API, including server logs, request logs and usage records;
(d) for the homepage demo (section 5); and
(e) when you correspond with us.
2.2 We are a processor for Customer Content that business customers send through the API on their own behalf. The customer decides which images to send and why. We process them only to produce the Output on the customer's instructions. For that processing the customer is the controller, and our Data Processing Addendum at /dpa governs how we handle it. If an image of you was sent to us by one of our customers, that customer's privacy notice applies, and you should contact them to exercise your rights. We do not keep images, so we are unlikely to be able to tell which customer sent a particular image. If you contact us, we will help where we can.
2.3 If you use the API for your own personal purposes rather than for a business, we handle the images you send in the same way. We use them only to return the Output to you, we do not keep them, and we do not use them to train models (section 6).
3. The personal data we collect and where it comes from
3.1 We collect the following categories of personal data:
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Your email address, your name if you give it, your password (collected and checked by our authentication provider, Clerk), email verification codes and the API keys you create | You, through the sign-up, sign-in and dashboard forms run by Clerk |
| Sign-in and device data | IP address, browser and device information, and session records | Your device, automatically, through Clerk. Clerk's service at clerk.verbier.dev runs on Cloudflare's network, which also processes this data to protect it (see our Cookie Policy at /cookies) |
| Billing data | Your plan, subscription status, billing periods and payment history, and the payment card details, billing country and postcode you enter at checkout. Card details go to Stripe; we never see your full card number. | You, Clerk Billing and Stripe |
| Usage data | For each API request: your account identifier, the route called, the number of images, the processing time and a label for the processing mode. For each billing period: the number of images delivered to your account | Our systems, when you use the API |
| Customer Content and Output | Images and image URLs sent to the API, and the resulting Output. We process these as a processor (section 2.2) | Our customers |
| Demo data | The photo you upload to the homepage demo, your IP address (or, for IPv6, your /64 network) and the number of tries you have made that day | You |
| Server logs | IP addresses and technical details of requests to verbier.dev and api.verbier.dev | Your device, automatically, through our hosting provider Vercel |
| Correspondence | Your email address and anything you write to us | You |
| Docs data | Your IP address and standard browser information (such as browser type and the address of the page that requested the file) | Sent by your browser directly to jsDelivr and Scalar when you open /docs (section 7.4). We do not receive it |
3.2 You do not have to give us personal data. However, we need your account data to open an account, and your billing data to provide a paid plan. Without them we cannot provide those parts of the Service.
3.3 We do not ask for special category data (such as health, ethnicity or religion), and we do not process images to identify anyone or to find out anything about them. See section 6.3.
4. What we use personal data for, and our lawful bases
4.1 The table below sets out each purpose and the lawful basis we rely on under Article 6(1) of the UK GDPR. "Contract" means the processing is necessary to perform our contract with you (our Terms of Service), or to take steps you ask for before entering into it. "Legal obligation" means the processing is necessary to comply with the law. "Legitimate interests" means the processing is necessary for the interest named, and that interest is not overridden by your rights and interests.
| Purpose | Personal data | Lawful basis |
|---|---|---|
| Creating and running your account: sign-up, email verification, sign-in, sessions and managing API keys | Account data; sign-in and device data | Contract |
| Providing the API to you: checking your API key and processing your requests | Account data; usage data | Contract |
| Counting the images delivered, applying plan limits and working out what you owe | Usage data; billing data | Contract |
| Taking payments, renewing and cancelling plans, and giving refunds, including refunds under the 14-day cancellation right for consumers | Billing data; account data | Contract. Legal obligation where the law requires a refund (Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013; Consumer Rights Act 2015) |
| Keeping accounting and tax records | Billing data | Legal obligation (Companies Act 2006 and UK tax law) |
| Sending service emails: verification codes, receipts, notice of price changes and changes to our terms, and security notices | Account data | Contract. Legal obligation where the law requires us to tell you something |
| Keeping the Service secure and preventing abuse: protecting sign-in from bots, rate limiting, detecting shared API keys and multiple free accounts, and enforcing our Terms and Acceptable Use Policy (/acceptable-use) | Sign-in and device data; server logs; usage data; account data | Legitimate interests: keeping the Service, our customers' accounts and our systems secure, and preventing fraud and abuse of the free plan |
| Running and fixing the Service: diagnosing errors, monitoring performance and checking that billing is accurate | Usage data; server logs | Legitimate interests: providing a reliable service and billing correctly |
| Running the homepage demo, including the moderation check and the daily limit | Demo data | Legitimate interests (see section 5.6) |
| Providing the interactive API reference on /docs | Docs data | Legitimate interests: providing usable API documentation through a standard documentation viewer |
| Answering questions, complaints and requests to exercise your rights | Correspondence; any data relevant to the request | Legitimate interests: responding to people who contact us. Legal obligation for data protection rights requests and complaints |
| Establishing, exercising or defending legal claims, and complying with lawful requests from courts, regulators or law enforcement | Any data relevant to the claim or request | Legitimate interests: protecting our legal position. Legal obligation where the law requires disclosure |
4.2 Where we rely on legitimate interests, we have weighed our interests against your rights and interests. You can ask us for details of that assessment, and you can object (section 11).
4.3 We do not rely on consent for any of the processing described in this policy.
4.4 We do not send marketing emails.
5. The homepage demo ("Try it now")
5.1 What it is. Anyone can try the Service on our homepage without an account by uploading a JPEG, PNG or WebP photo of up to 3 MB. Each IP address can make 5 tries per day, counted in UTC (midnight to midnight). For IPv6 addresses we count the /64 network, because a single connection is often given a whole /64 block of addresses. There is also a limit of 300 tries per day across all visitors.
5.2 What happens to your photo.
(a) Daily limit. Our website's server sends your photo and your IP address to our API. The API records your IP address (or /64 network) against a counter for the day, and your try counts even if the photo is then refused.
(b) Moderation. A copy of your photo is sent to OpenAI's moderation API, which checks it for sexual, violent or self-harm content. If the photo is flagged, it is refused and not processed further. If the moderation service cannot be reached, the demo refuses the photo.
(c) Cut-out. If the photo is not flagged, we remove the background, add a Verbier watermark and return the result to your browser.
(d) Not kept. We process the photo and the result and return the result to you. We do not keep either of them. Section 5.3 explains what our providers keep.
5.3 What our providers keep.
(a) OpenAI processes the photo for us as our processor. OpenAI's published API data controls say that data sent to its moderation endpoint is not used to train its models, and that by default it may be kept in abuse-monitoring logs for up to 30 days.
(b) Modal runs our API. Modal's platform stores the data passed into and out of our processing functions in encrypted form and deletes it within 7 days at most.
5.4 Your IP address. We store your IP address (or /64 network) with that day's try counter in a key-value store run by Modal in the United States. We use it only to apply the daily limit. It is not linked to an account or used for anything else, and it is deleted automatically about 7 days after the counter was last updated. Our application logs record the number of tries but not your IP address. Our hosting provider Vercel's server logs do record IP addresses (section 3).
5.5 Where the data goes. The demo uses Vercel (hosting), Modal (processing and the counter) and OpenAI (moderation), all in the United States. See sections 7 and 8.
5.6 Lawful basis. We rely on legitimate interests. Our interests are:
(a) letting people try the Service without creating an account;
(b) preventing abuse and keeping our costs under control through the daily limits; and
(c) not processing or returning sexual, violent or self-harm imagery.
We consider that these interests are not overridden by yours. You choose whether to upload a photo, we use the minimum data for the shortest time, and we use it for nothing else. You have the right to object (section 11).
5.7 Automated decision. The moderation check is automated: no person looks at your photo, and the result alone decides whether the demo processes it. This is not a "significant decision" within the meaning of Article 22A of the UK GDPR, because it has no legal effect on you and no similarly significant effect. It only decides whether our free demo processes one photo. The restrictions and safeguards in Articles 22B and 22C of the UK GDPR therefore do not apply. For visitors in the EEA, Article 22 of the EU GDPR does not apply either. We do not use the result for anything else, and we do not profile you. If you think a photo was refused in error, or you want to know more about how the check works, email hello@verbier.dev. We do not keep demo photos, so we can only look at a refused photo if you send it to us.
6. Images sent through the API
6.1 When a business customer sends Customer Content to the API, we act as its processor under our Data Processing Addendum at /dpa (section 2.2).
6.2 Whoever sends images through the API, we handle them as follows:
(a) images are processed in memory by our machine-learning models on GPU servers run by Modal in the United States, and the Output is returned in the API response;
(b) we do not store images or Output in any database, file store or log of our own. Modal's platform holds them only as described in section 5.3(b);
(c) we do not use Customer Content or Output to train or improve any model;
(d) if you give us an image URL (or a URL for a background image), our servers fetch the image from that address. We use the URL only to fetch the image and do not log it;
(e) for each request we log only your account identifier, the route called, the number of images, the processing time and a label for the processing mode. We do not log image content, URLs or Output; and
(f) requests and responses pass through Vercel's network in transit, because api.verbier.dev is routed through Vercel to Modal. Vercel does not cache API responses for us.
6.3 Images may show people, including their faces. We do not process images to identify anyone, so our processing does not involve biometric data within the meaning of Article 9 of the UK GDPR. We do not analyse images to infer anything about the people in them. Business customers are responsible for assessing their own use of the Output.
7. Who we share personal data with
7.1 Our service providers. These providers act as our processors, on our instructions and under written contracts:
| Provider | What they do for us | Personal data | Location |
|---|---|---|---|
| Clerk, Inc. | Accounts, sign-in, sessions, API keys and billing records (Clerk Billing) | Account data; sign-in and device data; billing data except card details | United States |
| Vercel Inc. | Hosts our website and routes API traffic to Modal (images pass through in transit); keeps server logs | Server logs; Customer Content, Output and demo photos in transit | United States, and other countries where Vercel operates its network |
| Modal Labs, Inc. | Runs our API and machine-learning models; stores usage counts, demo IP counters and request logs | Usage data; demo data; Customer Content and Output while they are processed | United States |
| OpenAI OpCo, LLC | Checks homepage demo photos for sexual, violent or self-harm content. Nothing else | Demo photos | United States |
| Stripe (see 7.2) | Card payments for paid plans | Billing data, including card details | Ireland, United Kingdom and United States |
7.2 Stripe. Our Stripe account is with Stripe Payments Europe, Limited (Ireland). Stripe Payments UK, Ltd. provides regulated payment services in the UK, and data is transferred to Stripe, LLC in the United States. Stripe acts as our processor for some processing. It is an independent controller for its own purposes, including preventing fraud and meeting its legal obligations such as anti-money-laundering checks. Stripe's privacy policy (stripe.com/privacy) applies to that processing.
7.3 Cloudflare. Clerk's service at clerk.verbier.dev runs on Cloudflare's network. Cloudflare sets security cookies there and processes your IP address as Clerk's provider. See our Cookie Policy at /cookies.
7.4 Third parties on our documentation page. Our API reference at /docs uses a viewer script served by jsDelivr (operated by Volentio JSD Limited, a company registered in England and Wales) from cdn.jsdelivr.net. The viewer loads fonts from fonts.scalar.com, run by Scalar (API Documentation Inc.). When you open /docs, your browser connects to these providers directly and sends them your IP address and standard browser information. They are not our processors. They use this data under their own privacy policies, and jsDelivr's says it uses such data for analytics and security. We do not send them any other information.
7.5 Others. We may also share personal data:
(a) with our professional advisers, such as accountants, lawyers and insurers, who are bound by confidentiality;
(b) with courts, regulators, law enforcement or other public authorities where the law requires it or where it is needed to establish, exercise or defend legal claims; and
(c) with a buyer of, or successor to, our business or its assets, who will be bound by this policy for the data they receive. We will tell you before this happens.
7.6 We do not sell or rent personal data (see section 13).
8. International transfers
8.1 Several of our providers are in the United States, so your personal data is transferred outside the UK. Where it goes to the United States, we rely on the following safeguards:
| Recipient | Safeguard |
|---|---|
| Clerk, Inc. | The UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge"), under which the UK recognises certified US organisations as providing adequate protection. Clerk is certified. Clerk's data processing addendum also incorporates the ICO's International Data Transfer Addendum to the EU standard contractual clauses (the "UK Addendum"), for use if the Data Privacy Framework cannot be relied on |
| Stripe, LLC | The UK Extension to the EU-US Data Privacy Framework (Stripe, LLC is certified), with the UK Addendum as a fallback under Stripe's Data Transfers Addendum |
| Vercel Inc. | The UK Extension to the EU-US Data Privacy Framework (Vercel is certified). Vercel's data processing addendum also incorporates the UK Addendum |
| Modal Labs, Inc. | The UK Addendum, incorporated in Modal's data processing addendum |
| OpenAI OpCo, LLC | The EU standard contractual clauses as amended by the UK Addendum, incorporated in OpenAI's data processing addendum |
8.2 Stripe Payments Europe, Limited is in Ireland. UK law recognises the EEA as providing adequate protection, so no further safeguard is needed for that transfer.
8.3 On /docs, your browser sends data directly to jsDelivr and Scalar (section 7.4); we do not transfer it to them.
8.4 You can ask us for more information about these safeguards, or a copy of the relevant terms, by emailing hello@verbier.dev.
9. How long we keep personal data
9.1 We keep personal data only for as long as we need it for the purposes in section 4:
| Data | How long we keep it |
|---|---|
| Account data, sign-in records and API keys | While your account is open. When you close your account (by emailing us, as our Terms of Service explain), we delete it within 30 days, apart from the billing records below |
| Billing and payment records | 6 years from the end of the financial year in which the transaction took place, to meet our accounting and tax obligations. |
| Usage counts per billing period | About 7 weeks from the start of the billing period, then deleted automatically |
| API request logs | Up to 30 days |
| Website and API server logs (Vercel) | Up to 30 days |
| Customer Content and Output | Not kept by us after the API response is returned. Modal's platform deletes them within 7 days at most (section 5.3(b)) |
| Demo photos and results | Not kept by us after the result is returned. For what OpenAI and Modal keep, see section 5.3 |
| Demo IP address counters | Deleted automatically about 7 days after they were last updated |
| Correspondence | 2 years after our last exchange |
| Records of rights requests and complaints | 3 years after the request or complaint is closed |
| Cookies and local storage | See our Cookie Policy at /cookies |
9.2 We may keep personal data for longer where we need it to establish, exercise or defend a legal claim, or where the law requires us to.
10. Security
10.1 We protect personal data with measures that fit the risks, including:
(a) encrypting all traffic to our website and API with TLS (HTTPS);
(b) processing images in memory and not storing them in our own systems (section 6.2);
(c) authenticating API requests with secret API keys, which you can revoke at any time in the dashboard. You must keep your keys secret, as our Terms of Service explain;
(d) requiring passwords of at least 15 characters and verifying email addresses with a code;
(e) leaving payment card details to Stripe, so that we never see full card numbers;
(f) restricting access to our systems and to our providers' administration consoles to authorised people who need it, protected by strong authentication; and
(g) choosing providers with independently audited security. Vercel and Modal have each completed SOC 2 Type 2 audits.
10.2 If a personal data breach occurs, we will report it to the ICO within 72 hours of becoming aware of it where the law requires. If the breach is likely to result in a high risk to you, we will also tell you without undue delay.
10.3 No method of transmitting or storing data is completely secure, but we work to keep your personal data safe.
11. Your rights
11.1 Under data protection law you have the right to:
(a) access: get a copy of your personal data and information about how we use it;
(b) rectification: have inaccurate personal data corrected and incomplete data completed;
(c) erasure: have your personal data deleted in certain circumstances, for example where we no longer need it;
(d) restriction: ask us to limit how we use your personal data in certain circumstances, for example while we check its accuracy;
(e) objection: object to processing we carry out on the basis of legitimate interests. We will then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims;
(f) portability: receive the personal data you gave us in a structured, commonly used, machine-readable format, and have it sent to another organisation, where we process it by automated means on the basis of contract or consent;
(g) withdraw consent: where we rely on consent, withdraw it at any time without affecting the processing before you withdrew it. At present we do not rely on consent (section 4.3); and
(h) information about automated decisions, as described in section 5.7.
11.2 To exercise any of these rights, email hello@verbier.dev. We will respond within one month. If your request is complex, or you have made several requests, we may extend this by up to two further months, and we will tell you why within the first month. If we need more information to confirm your identity or to understand your request, the time limit runs from when we receive it. We do not normally charge. We may charge a reasonable fee, or refuse, where a request is manifestly unfounded or excessive.
11.3 Some rights have exceptions, and we will explain if one applies. For images sent through the API by a business customer, please contact that customer (section 2.2).
11.4 Complaints to us. If you think we have not handled your personal data in line with data protection law, you can complain to us at hello@verbier.dev. We will acknowledge your complaint within 30 days of receiving it. We will look into it, keep you informed of progress and tell you the outcome without undue delay.
11.5 Complaints to the ICO. You can also complain to the Information Commissioner's Office:
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Helpline: 0303 123 1113
- Website: https://ico.org.uk (complaints: https://ico.org.uk/make-a-complaint)
If you live in the EEA, you can also complain to the data protection authority in your country.
12. Children
12.1 The Service is for adults. You must be 18 or over to create an account. The homepage demo is not intended for anyone under 18.
12.2 We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email hello@verbier.dev and we will delete it.
13. No selling, advertising or tracking
13.1 We do not sell or rent personal data to anyone.
13.2 We do not use analytics, advertising or tracking tools, and we do not show advertising. We do not build profiles of visitors or follow them across other websites. Our website's fonts are served from our own servers, so viewing our pages does not send requests to font providers. The documentation page is the exception (section 7.4).
13.3 The only cookies and similar technologies we use are strictly necessary. See our Cookie Policy at /cookies.
14. Changes to this policy
14.1 We may update this policy, for example when we change the Service, our providers or the law changes. We will publish the new version at /privacy with a new "Last updated" date.
14.2 If a change is significant, we will also email account holders before it takes effect.
15. Contact
15.1 Fortis Ventures Ltd, C/O Aardvark Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, BH21 7SB, United Kingdom.
15.2 Email: hello@verbier.dev
15.3 Related documents: Terms of Service (/terms), Cookie Policy (/cookies), Acceptable Use Policy (/acceptable-use) and Data Processing Addendum (/dpa).