Terms, privacy and the small print — in plain view.
These documents govern your use of the Verto computer-assisted translation platform. They are written to comply with the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL) and, where applicable, the EU General Data Protection Regulation (GDPR).
Terms of Service
The legally binding agreement between you and the operator of Verto. Please read carefully before creating an account or using the Service.
1. Acceptance of Terms
By creating an account or otherwise accessing or using the Verto web application and related services (collectively, the "Service"), you ("User," "you," or "your") agree to be legally bound by these Terms of Service ("Terms"). If you are accepting on behalf of a company or other legal entity, you represent that you have the authority to bind that entity to these Terms. If you do not agree, do not use the Service.
These Terms constitute a binding legal agreement between you and the individual operator of Verto ("Verto," "we," "us," or "our"), a service operated by an individual sole trader based in Riyadh, Kingdom of Saudi Arabia. Verto is in the process of registering as a formal legal entity in the Kingdom of Saudi Arabia; until registration is complete, the Service is operated by an individual sole trader. These Terms are governed by the laws of the Kingdom of Saudi Arabia.
2. Description of Service
Verto is a professional-grade, browser-based computer-assisted translation (CAT) platform designed for Arabic-English translators, freelance linguists, and language service providers (LSPs). The Service is accessible via any modern web browser without installation. The Service includes:
- A web-based translation editor environment
- Cloud-based project management, file storage, and collaboration features
- Translation memory (TM) and glossary management
- Machine translation integration via third-party API connections
- Quality assurance (QA) tools
- Team collaboration features including task assignment, document splitting, shared TMs, and audit logging (Team plan only)
- An administrative web panel accessible to account administrators
The Service is provided on a subscription basis. Features available to a User depend on their active subscription plan as described in Section 4.
3. Account Registration and Security
3.1 Eligibility
You must be at least 18 years of age to create an account. By registering, you represent that you meet this requirement and that all information you provide is accurate, current, and complete.
3.2 Account Credentials
You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account. You must notify us immediately at support@goforverto.com if you become aware of any unauthorised access to your account. Verto will not be liable for any loss or damage arising from your failure to protect your credentials.
3.3 Team Accounts
On the Team plan, the account administrator ("Admin") has the authority to add or remove seat holders, assign roles, manage permissions, and access team-wide usage data. The Admin accepts responsibility for ensuring that all seat holders under their account comply with these Terms.
4. Subscription Plans and Billing
4.1 Plans
Verto offers the following subscription tiers, subject to change with notice as described in Section 14:
- Free Plan: 1 seat, 5 projects, personal TM and glossary up to 10,000 segments, built-in QA checks and confidence scoring. No charge.
- Professional Plan (USD 17/month): 1 seat, unlimited projects, unlimited personal TM and glossary, machine translation via personal API key, concordance search, advanced file formats (XLIFF, TMX, TBX), bilingual export, AI chat assistant in editor, basic reporting, email support.
- Team Plan (USD 75/month): Everything in Professional, plus up to 5 seats, shared TMs and glossaries with permission controls, reviewer workflow and assignments, file splitting across translators, comments on segments, translator velocity analytics, advanced reports, priority support.
- Custom Plan: Enterprise-level pricing and seat allocation negotiated directly with Verto. Terms are set out in a separate Order Form or Master Service Agreement. Includes everything in Team plus negotiated seat count, dedicated CSM, and custom contract and SLA.
4.2 Billing and Payment
Paid subscriptions are billed in advance on a monthly or annual basis through our payment processor, Lemon Squeezy. By subscribing, you authorise us to charge your payment method on each renewal date. All prices are in United States Dollars (USD) and are exclusive of applicable taxes, including Saudi Value Added Tax (VAT) at the prevailing rate.
4.3 Refunds
Subscriptions are non-refundable except where required by applicable law. If you cancel your subscription, you will retain access to paid features until the end of your current billing period. Verto may, at its sole discretion, issue a pro-rata refund in cases of service outages attributable to Verto that exceed 72 consecutive hours in a given billing month.
4.4 Failed Payments and Suspension
If a payment fails, we will notify you by email. You have 7 calendar days to update your payment method. If payment is not received within that period, your account will be downgraded to the Free plan. Your data will not be deleted, but features above the Free plan limits will become inaccessible until payment is resumed.
4.5 Plan Downgrade and Data Retention
If your account is downgraded (voluntarily or due to non-payment), projects and TM data exceeding Free plan limits will be placed in a read-only archived state. They will not be deleted for a period of 90 days, during which you may reactivate your subscription to restore full access. After 90 days of continuous Free plan status with data exceeding Free limits, we reserve the right to delete the excess archived data with 30 days' prior written notice.
5. Acceptable Use
You agree to use the Service only for lawful purposes and in accordance with these Terms. You must not:
- Use the Service to translate, process, or distribute content that is illegal, defamatory, obscene, or in violation of any third-party rights, including intellectual property rights
- Attempt to reverse engineer, decompile, disassemble, or otherwise extract the source code of the Service
- Use automated means (bots, scrapers, crawlers) to access or interact with the Service in ways not expressly permitted
- Circumvent, disable, or interfere with security-related features, including plan-based feature restrictions
- Share your account credentials with individuals who are not authorised seat holders under your plan
- Upload malicious code, viruses, or files designed to disrupt or damage the Service or its infrastructure
- Resell, sublicense, or otherwise commercialise access to the Service without prior written approval from Verto
Violation of this section may result in immediate suspension or termination of your account without refund.
6. Intellectual Property
6.1 Verto's Intellectual Property
The Service, including the web application, underlying software, user interface, design, algorithms, documentation, and all related materials, is the exclusive intellectual property of Verto and is protected by copyright, trademark, and other applicable laws. Nothing in these Terms grants you any ownership right in the Service.
6.2 Your Content
You retain full ownership of all content you upload to or create within the Service, including source documents, translated text, translation memories, glossary terms, and project files (collectively, "User Content"). By using the Service, you grant Verto a limited, non-exclusive, royalty-free licence to store, process, and transmit your User Content solely to the extent necessary to provide and maintain the Service. This licence terminates when you delete the content or close your account.
6.3 Translation Memories and Glossaries
Translation memories and glossaries you create within Verto are your intellectual property. Verto does not claim any ownership over the linguistic assets you build using the Service, nor will Verto use your TM or glossary content to train machine learning models without your explicit written consent.
6.4 Feedback
If you provide feedback, suggestions, or ideas regarding the Service, you grant Verto a perpetual, irrevocable, worldwide, royalty-free licence to use that feedback for any purpose without any obligation to compensate you.
7. Confidentiality of Translation Content
Verto understands that translation projects often involve commercially sensitive, legally privileged, or confidential source materials. We implement technical and organisational measures to restrict access to your User Content. Verto personnel will not access your documents or translation content except: (a) as necessary to provide technical support at your explicit request; (b) to investigate a security incident; or (c) as required by applicable law or a valid court order. Any such access is recorded in an immutable internal audit log, including the identity of the personnel who accessed the content, the timestamp, and the stated reason for access.
You are responsible for ensuring that you have the right to upload and process any content submitted to the Service, including obtaining any necessary confidentiality waivers from your clients where required.
8. Third-Party Integrations and File Storage Infrastructure
The Service integrates with third-party services including machine translation providers (accessed via your own API keys) and Cloudflare R2 for file storage. Application hosting, database infrastructure, and backend services are provided through a third-party cloud application hosting platform. Verto's application is hosted on that platform's infrastructure during its current development phase. Enterprise customers with specific hosting requirements should contact us to discuss available options. Your use of any third-party integration is subject to that provider's own terms and privacy policy. Verto is not responsible for the availability, accuracy, or security practices of third-party services.
8.1 Cloudflare R2 File Storage
All User Content files — including source documents, translated documents, bilingual exports, and project archives — are stored using Cloudflare R2, an enterprise-grade distributed object storage service operated by Cloudflare, Inc., holding ISO/IEC 27001, ISO/IEC 27701, SOC 2 Type II, and multiple other independently audited certifications. Full details are in the Compliance Certifications section of this page.
- Encryption at rest — All objects stored in R2, including their metadata, are automatically encrypted using AES-256 (Galois/Counter Mode). Encryption keys are managed by Cloudflare's internal key management systems.
- Encryption in transit — All data transfers between the Verto application and Cloudflare R2 are secured using TLS/SSL. Plaintext HTTP access to stored files is disabled.
- Durability — Cloudflare R2 is designed for 99.999999999% (eleven nines) annual data durability across Cloudflare's global network of over 330 data centres.
- Private access only — R2 buckets used by Verto are private. No file is publicly accessible — all access requires an authenticated, time-limited signed URL generated server-side by the Verto application.
- US CLOUD Act — As Cloudflare, Inc. is incorporated in the United States, data stored on R2 may be subject to the US CLOUD Act, which permits US law enforcement to compel disclosure of data held by US companies regardless of where the data is physically stored. Verto will notify affected users of any such request to the maximum extent permitted by applicable law.
9. Disclaimer of Warranties
Translation output produced using the Service is not warranted for accuracy, fitness for any purpose, or regulatory compliance. Professional review of all translated content remains the responsibility of the User.
10. Limitation of Liability
11. Indemnification
You agree to indemnify, defend, and hold harmless Verto and its affiliates, officers, agents, and employees from and against any claims, liabilities, damages, losses, and expenses arising out of: (a) your access to or use of the Service; (b) your User Content; (c) your violation of these Terms; or (d) your infringement of any third-party rights.
12. Termination
You may terminate your account at any time by contacting support@goforverto.com or through account settings. Termination takes effect at the end of your current billing cycle for paid plans. Verto may suspend or terminate your account immediately if you materially breach these Terms, we are required to do so by law, or your continued use poses a risk to other users. Upon termination, you may request an export of your User Content within 30 days.
13. Governing Law and Dispute Resolution
These Terms are governed by the laws of the Kingdom of Saudi Arabia. Disputes shall first be subject to 30 days of good-faith negotiation. If unresolved, disputes shall be submitted to the competent courts of Riyadh, Saudi Arabia. For EU users, nothing in this clause limits your rights to bring claims before the courts of your country of residence.
14. Modifications
Verto may modify these Terms at any time. For material changes, we will provide at least 30 days' advance notice by email. Continued use after the effective date constitutes acceptance.
15. Contact
For questions about these Terms: support@goforverto.com — Riyadh, Kingdom of Saudi Arabia.
Privacy Policy
How we collect, use, store, share, and protect your personal data — written in compliance with the Saudi PDPL and, where applicable, the EU GDPR.
1. Data Controller
The data controller responsible for your personal data is the individual operator of Verto, based in Riyadh, Kingdom of Saudi Arabia.
2. Data We Collect
2.1 Account Data
Name, email address, country, preferred language, and hashed password. Billing data (card details) is handled directly by Lemon Squeezy and is not stored on Verto's servers.
2.2 Usage Data
We automatically collect data about how you interact with the Service, including: features accessed, projects created, translation events, TM match rates applied, file formats used, error events, session duration, browser type, and operating system. This data does not include the content of your translation segments unless you explicitly share a project with our support team.
2.3 User Content
User Content (source documents, translated text, translation memories, glossary terms) is stored on Verto's infrastructure — Cloudflare R2 for files and our cloud application hosting provider's database infrastructure for structured data. We process this content solely to deliver the Service to you. We treat all User Content as confidential in accordance with Section 7 of the Terms of Service.
2.4 Communications Data
If you contact us for support, we retain the content of your communications and the email address you used. This data is used only to respond to your enquiry and to improve our support processes.
2.5 Technical Data
We collect IP address, browser type (for web panel access), and device identifiers for security, fraud prevention, and service reliability purposes.
3. How We Use Your Data
We use personal data for the following purposes:
- To provide, operate, and improve the Service
- To manage your account and subscription
- To communicate with you about your account, billing, and service updates
- To enforce these Terms of Service and our acceptable use policies
- To detect, investigate, and prevent security incidents and fraudulent activity
- To comply with applicable legal obligations, including responses to lawful requests from Saudi Arabian authorities
- To conduct product analytics (using anonymised or aggregated data) to understand feature usage and improve the Service
We do not use your User Content (translation documents, TMs, glossaries) for any purpose beyond delivering the Service, and we do not use it to train AI or machine learning models without your explicit written consent.
4. Legal Basis for Processing
Under the Saudi PDPL and, where applicable, the GDPR, we process your personal data on the following legal bases:
- Contract: Processing necessary to perform the Service you have subscribed to.
- Legal Obligation: Processing required to comply with applicable laws.
- Legitimate Interests: Processing for security, fraud prevention, and product improvement, where such interests do not override your rights.
- Consent: Where we ask for your consent (for example, to use content for AI training), you may withdraw it at any time without affecting the lawfulness of prior processing.
5. Data Sharing
We do not sell your personal data. We share data only with:
- Cloudflare R2 — File storage. Cloudflare processes data as a sub-processor under contractual data processing obligations and does not access the content of stored objects except as required to operate the infrastructure.
- Cloud application hosting provider — Application hosting and database infrastructure. This provider processes data as a sub-processor under contractual obligations.
- Lemon Squeezy — Subscription payment processing. They receive billing information directly from you and are subject to their own privacy policy.
- Error monitoring — We use error monitoring tooling to log technical errors. Reports are anonymised and do not include translation content.
- Legal and regulatory — We may disclose personal data if required by law, court order, or a valid request from a competent Saudi Arabian authority.
6. International Data Transfers and Data Location
Verto's infrastructure involves services operated by US-incorporated entities. Full details on data location and applicable cross-border transfer frameworks are provided in the Data Location & Transfers section of this page. In summary:
6.1 Cloudflare R2 Storage
Files you upload to Verto are stored on Cloudflare R2, distributed across Cloudflare's global network. We cannot guarantee your files will reside exclusively in any single country or region.
6.2 Cloud Hosting Provider Infrastructure
Structured data — including account information, project metadata, and TM segment data — is stored within our cloud application hosting provider's database environment, which may be hosted in data centres outside the Kingdom of Saudi Arabia.
6.3 Safeguards
All data in transit is protected by TLS/SSL encryption. All data at rest is encrypted using AES-256. Where personal data is transferred outside Saudi Arabia, we rely on contractual safeguards consistent with the PDPL's cross-border transfer requirements.
7. Data Retention
We retain your personal data for as long as your account is active or as necessary to provide the Service. Specifically:
- Account data is retained for the duration of your account plus 12 months following closure, to allow for dispute resolution and legal compliance.
- Usage event logs are retained for 24 months on a rolling basis.
- User Content (documents, TMs, glossaries) is retained in accordance with the plan downgrade and termination provisions in the Terms of Service.
- Support communications are retained for 36 months.
- Audit logs are retained for 5 years for compliance and security purposes.
Upon expiry of the relevant retention period, data is securely deleted or irreversibly anonymised.
8. Security
Verto implements layered technical and organisational security measures across its application and infrastructure stack:
8.1 Application-level security
All browser-to-application communication is encrypted using TLS 1.2 or higher. Sessions are authenticated and expire on inactivity. Role-based permissions govern what each user and administrator can access within a project or account. All administrative actions are recorded in an immutable audit log. User passwords are stored as salted hashes — never in plaintext. Machine translation API keys are stored encrypted. Verto support personnel can only access User Content when explicitly invited by the account owner for support purposes.
8.2 File storage security (Cloudflare R2)
Files stored on Cloudflare R2 are automatically encrypted at rest using AES-256 (GCM). All file transfers are encrypted in transit using TLS/SSL. R2 buckets used by Verto are private — no file is publicly accessible without an authenticated, time-limited signed URL generated by the Verto application. Cloudflare holds ISO/IEC 27001:2013, ISO/IEC 27018:2019, ISO/IEC 27701:2019, SOC 2 Type II, SOC 3, PCI DSS Level 1, C5 (BSI), EU Cloud Code of Conduct, Global CBPR, and Global PRP certifications. Full details are in the Compliance Certifications section and at the Cloudflare Trust Hub.
8.3 Incident response
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant regulatory authorities as required by applicable law, including the PDPL and, where applicable, the GDPR — without undue delay and, where feasible, within 72 hours of becoming aware of the breach. No method of electronic storage is completely secure; we cannot guarantee absolute security.
9. Your Rights
Subject to applicable law, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data, subject to legal retention obligations.
- Restriction: Request that we limit the processing of your data in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdrawal of Consent: Where processing is based on consent, withdraw it at any time.
We may need to verify your identity before processing your request. You also have the right to lodge a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) or, for EU residents, with your local supervisory authority.
10. Cookies and Tracking
The Verto web panel uses essential cookies necessary for authentication and session management. We do not use advertising cookies or third-party tracking cookies. We use a first-party analytics approach that does not share data with advertising networks. You may configure your browser to reject cookies, but doing so may affect the functionality of the web panel.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email with at least 30 days' notice before the revised policy takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
Compliance Certifications
Verto's security posture is built on two tiers: the independently audited certifications held by our infrastructure provider Cloudflare, and the application-level practices Verto implements and maintains directly.
Tier 1 — Cloudflare R2 Infrastructure Certifications
The following certifications and compliance frameworks have been independently audited and verified for Cloudflare's infrastructure, which includes Cloudflare R2. These certifications are current as of the effective date of these Terms and are subject to annual re-audit by Cloudflare. The most current status is published on the Cloudflare Trust Hub.
Information Security Management
The internationally recognised standard for an ISMS. Independently certified by a third-party auditor, with three-yearly audits and annual surveillance reviews.
PII Protection in Public Cloud
Extends ISO 27001 with specific controls for processing personal data in cloud environments. Independently audited by Schellman.
Privacy Information Management
GDPR-aligned PIMS certification. Cloudflare is certified as both a PII Processor and a PII Controller — one of the first in the cloud infrastructure industry to hold this dual certification.
Security · Confidentiality · Availability
Independent third-party auditor opinion in accordance with AICPA standards. Renewed annually and available on request.
Public summary of SOC 2
Publicly available summary of Cloudflare's SOC 2 audit, providing an independent auditor's opinion on its security, confidentiality and availability controls.
Payment Card Industry — top tier
Highest service-provider level. While Verto does not process payment card data through R2, this reflects the maturity of Cloudflare's overall security and access controls.
Cloud Computing Compliance Criteria Catalog
Introduced by Germany's Federal Office for Information Security. Makes R2 infrastructure suitable for customers with German and EU regulatory obligations.
GDPR-recognised processor framework
Cloudflare is a verified member, providing assurance that it operates as a GDPR-compliant processor of personal data across EEA countries.
Cross-Border Privacy Rules
Cloudflare was among the inaugural organisations certified under the Global CBPR system in June 2025 — 50 requirements across nine guiding principles, established by a forum of nine governments.
Global Privacy Recognition for Processors
Achieved simultaneously with CBPR in June 2025. Provides assurance to data controllers that Cloudflare meets internationally recognised standards for handling personal data as a processor.
Tier 2 — Verto Application-Level Security Practices
In addition to the infrastructure certifications above, Verto implements and maintains the following security practices at the application layer:
- All sessions require authentication. Sessions expire after 60 minutes of inactivity.
- All file access requires a time-limited signed URL generated server-side. Files are never directly linked or publicly accessible.
- Plan-based feature restrictions (projects, seats, TM limits, API access) are enforced at the server layer, not only at the UI level.
- All administrative actions — login, permission changes, file access, plan changes, and team modifications — are written to an immutable, timestamped audit log that records the identity of the acting user and the stated reason where applicable.
- User passwords are stored as salted cryptographic hashes. Plaintext passwords are never stored or transmitted.
- Translation memory and glossary content is never used to train AI or machine learning models without explicit written consent.
- Machine translation API keys entered by users are stored encrypted in the database. They are only decrypted server-side at the point of use.
- Verto support and development personnel can only access User Content (documents, translations) when explicitly invited into a project by the account owner for support purposes. Such access is logged in the audit trail.
Data Location & Transfers
This section explains where your data physically resides, which legal jurisdictions apply to it, and what safeguards are in place for cross-border transfers.
Files — Cloudflare R2
Files you upload to Verto — including source documents, translated documents, TM exports, and project archives — are stored on Cloudflare R2, which is distributed across Cloudflare's global network of over 330 data centres. Verto uses location hints to bias storage towards regions geographically closer to our primary user base in the MENA region. However, Cloudflare determines the precise physical location of stored data within its distributed infrastructure, and we cannot guarantee that your files will reside exclusively in any single country or region.
Structured Data — Cloud Hosting Provider
Structured data — including account information, project metadata, usage events, translation memory segment data, and audit logs — is stored within our cloud application hosting provider's database infrastructure, which may be hosted in data centres outside the Kingdom of Saudi Arabia. Our cloud application hosting provider is a US-incorporated company, and the same CLOUD Act considerations described above apply to data held by that provider.
Cross-Border Transfer Safeguards
Regardless of the physical location of data, all data in transit between Verto and its infrastructure providers is protected by TLS/SSL encryption. All data at rest is encrypted using AES-256. Verto relies on contractual data processing obligations with Cloudflare and its cloud application hosting provider to ensure appropriate technical and organisational security measures are maintained.
Saudi PDPL Compliance
Where personal data is transferred outside the Kingdom of Saudi Arabia, Verto relies on contractual safeguards consistent with the requirements of Saudi Arabia's Personal Data Protection Law (PDPL), Articles 29–30, which govern the transfer of personal data outside the Kingdom. We require that recipient sub-processors commit to equivalent levels of data protection.
EU GDPR
For users in the European Economic Area, cross-border data transfers to Cloudflare and our cloud application hosting provider are governed by Standard Contractual Clauses (SCCs) adopted under Article 46(2)(c) of the GDPR, where applicable. EU users retain the right to lodge a complaint with their national data protection supervisory authority if they believe their data has been processed in breach of the GDPR.