Legal Hub — VersEngin Studio Labs
This consolidated Legal Hub is provided for transparency and ease of access. Depending on your location, certain
provisions may apply in addition to, or instead of, others (e.g., GDPR in the EEA/UK, CCPA/CPRA in California).
For the purposes of these documents, the “Services” include the VersEngin website at
versengin.com, the early-access account area and preferences page (/account), the Hana Verse
page and related media, the Support Hub, and survey or feedback flows used for product validation.
Where conflicts arise, the more protective rule for the individual will prevail under applicable law.
Terms of Use
This section explains the rules for using VersEngin, including the website, early-access accounts, surveys and experimental AI features like the Hana Verse persona.
- Use VersEngin lawfully and in line with these Terms.
- Keep your account details secure and up to date.
- AI and Hana Verse outputs are experimental and not professional advice.
1) Acceptance of Terms
These Terms of Use (“Terms”) govern your access to and use of the websites, applications, and services offered by VersEngin Studio Labs (“VersEngin,” “we,” “us,” “our”), including versengin.com and related pre-MVP features such as account sign-in (via Memberstack), surveys, and analytics-enabled pages (collectively, the “Services”). By accessing or using the Services, you agree to be bound by these Terms and our Privacy Policy and Cookies Policy.
2) Changes to These Terms
We may update these Terms to reflect operational, legal, or regulatory changes. We will revise the “Last Updated” date above and, where required by law, provide advance notice (e.g., banner notice or email) and/or request consent. Continued use of the Services after the effective date constitutes acceptance of the updated Terms.
3) Eligibility
You must be able to form a binding contract under the laws of your jurisdiction. Where parental consent is required by law, guardians must review and accept on behalf of minors. See Children’s Privacy for more information.
4) Accounts & Security
When creating an account (e.g., via Memberstack), you must provide accurate information and keep your credentials confidential. You are responsible for all activity under your account. Notify us immediately of any unauthorized use or security incident at dpo@versengin.com.
5) Permitted Use; Prohibited Conduct
You agree to use the Services only for lawful purposes and in compliance with these Terms. You will not: (a) attempt to access accounts or data without authorization; (b) reverse engineer, decompile, or otherwise attempt to derive source code except where permitted by law; (c) interfere with the proper functioning of the Services; (d) upload or transmit malicious code; (e) use the Services to violate others’ rights, including privacy and intellectual property; or (f) use automated means without our prior written consent except as permitted by robots.txt.
6) User Content
If the Services allow you to submit content (e.g., survey responses, feedback), you retain ownership of your content. You grant VersEngin a non-exclusive, worldwide, royalty-free license to host, store, process, and display the content for the limited purpose of operating, improving, and analyzing the Services, and as described in the Privacy Policy.
7) Intellectual Property
The Services (including text, designs, logos, graphics, and software) are protected by intellectual property laws. Except for rights expressly granted, no license or right is conveyed. “VersEngin,” “VersEngin Studio Labs,” “Hana Verse,” related logos, and trade dress are trademarks or trade names of VersEngin Studio Labs.
8) AI-Generated, Experimental & Persona-Based Features
Our pre-MVP environment may include experimental AI features, prompts, models, and AI-assisted experiences such as the Hana Verse digital persona. These elements are provided “as is” and may produce variable or unexpected outputs. Hana Verse is a fictional, AI-assisted character and is not a human advisor. You are responsible for independently assessing fitness for your purpose and should not rely on any output or persona content for legal, medical, financial, or safety-critical decisions without appropriate professional review.
9) Third-Party Services
The Services integrate certain third-party providers, including without limitation: Webflow (site hosting/CMS), Cloudflare (DNS, content delivery, security and edge compute via Workers/KV), Memberstack (authentication and account management), Cookiebot by Usercentrics (cookie consent and compliance logging), Google Analytics 4 (usage analytics), Google Forms (surveys), ConvertKit (email/newsletter delivery), and embedded media or social platforms where you choose to interact with them (for example, YouTube-nocookie video embeds or links to Hana Verse profiles on Instagram, TikTok, X, YouTube or Facebook). Your use of such third-party services is subject to their own terms and privacy policies. We are not responsible for the acts or omissions of third parties beyond our role as controller/processor as described in the Privacy Policy.
10) Disclaimer; Limitation of Liability
To the extent permitted by law, the Services are provided “as is” and “as available,” without warranties of any kind. VersEngin disclaims all implied warranties (e.g., merchantability, fitness, non-infringement). To the maximum extent permitted by law, VersEngin and its directors, officers, employees, and agents shall not be liable for indirect, incidental, special, consequential, or punitive damages, or any loss of profits, data, goodwill, or business interruption. In jurisdictions that do not allow limitations of liability, our liability will be limited to the greatest extent permitted by law.
11) Indemnification
You agree to indemnify and hold VersEngin harmless from claims arising from your misuse of the Services or violation of these Terms, except to the extent caused by our breach of applicable law.
12) Governing Law & Dispute Resolution
These Terms are governed by the laws of Spain and applicable EU law, without regard to conflict-of-law principles. Courts located in Barcelona, Spain shall have exclusive jurisdiction, except where consumer protection rules mandate otherwise. Before formal proceedings, the parties will attempt to resolve disputes amicably within thirty (30) days after written notice.
13) Entire Agreement; Severability
These Terms, together with the policies linked herein, constitute the entire agreement between you and VersEngin. If any provision is held invalid, the remaining provisions remain in full force and effect.
14) Force Majeure; Accessibility
We are not responsible for failure or delay caused by circumstances beyond our reasonable control (e.g., Internet outages, natural disasters, regulatory actions). These Terms and related policies are available in accessible electronic formats; to request an alternative format, contact us at dpo@versengin.com.
Privacy Policy GDPR / CCPA
This section explains what personal data we collect, why we use it, which providers help us process it, and the choices and rights you have under GDPR, UK GDPR and CCPA/CPRA.
- We collect account, usage, survey and communication data to operate and improve VersEngin.
- We use a small set of providers (Webflow, Cloudflare, Memberstack, Cookiebot, GA4, Google Forms, ConvertKit).
- You can control cookies, newsletters and exercise your legal privacy rights at any time.
1) Who We Are & DPO
VersEngin Studio Labs (“VersEngin,” “we,” “us”) is the controller of your personal data for the Services described here, unless stated otherwise. We have appointed a Data Protection Officer (DPO) reachable at dpo@versengin.com. Registered location: Barcelona, Spain.
2) What We Collect
- Account & Identification: name, email, password hash, Memberstack ID.
- Survey Data: responses to product-validation surveys (opinions, preferences, optional demographics where allowed).
- Usage & Device Data: pages viewed, events (e.g., sign-in, survey start/submit), timestamps, approximate location (derived from IP), device/browser metadata; collected via first-party scripts and Google Analytics 4 (only where consent is provided where required).
- Communications: messages or emails you send us; newsletter preferences (via ConvertKit or equivalent).
- Consent & Preferences: cookie and tracking permissions recorded via our consent management platform (Cookiebot), newsletter and communication preferences (e.g., ConvertKit tags, opt-in/opt-out), and language or locale choices stored in your account or browser.
- Cookies & Similar Tech: see Cookies Policy.
3) Why We Process Your Data (Legal Bases)
- Provide the Services (create accounts, authenticate, run surveys) — Contractual necessity (GDPR Art. 6(1)(b)).
- Security & abuse prevention (fraud prevention, service integrity) — Legitimate interests (Art. 6(1)(f)) with balancing tests applied.
- Analytics cookies & measurement (e.g., GA4) — Consent (Art. 6(1)(a)) where required; you can withdraw at any time.
- Legal obligations (e.g., record-keeping, regulatory compliance) — Legal obligation (Art. 6(1)(c)).
4) How We Use Data
We use data to operate the site, authenticate users, deliver surveys, analyze engagement (where consent is required and provided), detect abuse, communicate with you (e.g., product updates, newsletters with your opt-in), and improve features. We do not engage in profiling or automated decisions that produce legal or similarly significant effects on individuals.
5) Sharing & Disclosure
We share personal data with trusted providers under data-processing agreements, or as independent controllers where applicable:
- Hosting & CMS: Webflow (site hosting, forms/CMS as configured).
- Edge & Security: Cloudflare (DNS, content delivery, security services and edge compute via Workers/KV).
- Auth & Membership: Memberstack (account management, authentication, gating early-access features).
- Analytics: Google Analytics 4 (aggregate usage metrics; configured to respect consent choices and regional requirements, including Consent Mode where applicable).
- Consent Management: Cookiebot by Usercentrics (cookie banner, consent logging and cookie declaration).
- Forms/Email: Google Forms (surveys) and ConvertKit (newsletters and selected service emails).
- Embedded Media & Social: third-party platforms where you choose to interact with our content, for example YouTube-nocookie embeds for Hana Verse videos or outbound links to social profiles (Instagram, TikTok, X, YouTube, Facebook).
- Professional Services: legal, accounting, and audit advisors.
We may disclose data if required by law, to protect rights and safety, or in connection with corporate transactions, subject to appropriate safeguards.
6) International Transfers
Your data may be transferred outside the EEA/UK. Where this occurs, we rely on adequacy decisions or appropriate safeguards (e.g., EU Standard Contractual Clauses, UK IDTA). Where transfers are to certified U.S. recipients, we may rely on the EU-U.S. Data Privacy Framework when applicable, plus supplementary measures as needed.
7) Retention
We keep personal data only as long as needed for the purposes above: account data for the life of the account; survey data for validation windows (typically up to 24 months unless aggregated/anonymized sooner); analytics data per provider defaults/configuration; and longer where required by law or to establish/defend legal claims. We periodically review and delete or anonymize data no longer required.
8) Children’s Privacy
The Services are not directed to children under 13. If you are under the age of digital consent in your country (e.g., 13 in the U.S., 14 in Spain, up to 16 in some EU member states), you must obtain parental consent as required by law. If we learn we have collected personal data from a child without required consent, we will take reasonable steps to delete it.
9) Your Choices
- Consents: Accept/decline non-essential cookies and withdraw consent at any time.
- Comms: Unsubscribe from non-essential emails via links in messages.
- Do Not Track / Global Privacy Control: Where legally required and technically feasible, we honor supported browser signals for opt-out of sale/sharing/targeted ads.
10) Your Rights
See Data Protection & User Rights for region-specific details. We respond to verified requests within one month under GDPR/UK GDPR (extendable by two months where complex) and within 45 days under CCPA/CPRA (extendable where reasonably necessary with notice).
11) We Do Not Sell or Share Personal Information
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising without your consent where required. You may adjust advertising/analytics choices via the cookie consent controls (see Cookies Policy).
12) Changes to This Privacy Policy
We may update this Privacy Policy. We will update the “Last Updated” date and, where required, notify you and/or seek consent for material changes.
Data Protection & User Rights
This section explains your privacy rights under GDPR/UK GDPR and CCPA/CPRA, and how to exercise them with VersEngin.
- You can request access, correction, deletion or a copy of your data.
- You can object to certain uses (e.g. analytics/marketing) and withdraw consent.
- You can contact your data protection authority, but we encourage you to contact us first.
1) GDPR / UK GDPR (EEA/UK)
Subject to conditions and exemptions, you have the right to access; rectification; erasure; restriction; data portability; and to object to processing based on legitimate interests or direct marketing. Where processing is based on consent, you may withdraw it at any time without affecting lawfulness prior to withdrawal. We aim to respond within one month, extendable by two months where necessary with notice.
2) CCPA/CPRA (California)
California residents have the right to know categories and specific pieces of personal information collected; delete personal information; correct inaccurate information; opt out of “sale” or “sharing” (as defined under CPRA) and limit use/disclosure of sensitive personal information; and not be discriminated against for exercising these rights. VersEngin does not sell personal information. We may “share” for cross-context behavioral advertising only with your consent where required; you may opt out at any time via cookie controls or by contacting us.
3) How to Exercise Your Rights
Submit a request by emailing dpo@versengin.com with the subject line “Privacy Request” and indicate your region (e.g., EEA, UK, California). We may need to verify your identity. Authorized agents may submit requests with appropriate authorization. We respond within one month (GDPR/UK GDPR) or 45 days (CCPA/CPRA), extendable where reasonably necessary with notice. You can also adjust certain settings directly in your account (for example language and newsletter preferences), which does not replace but complements your formal rights.
4) Complaints
EEA/UK users may lodge a complaint with their supervisory authority (e.g., AEPD in Spain, ICO in the UK). See the EU authority list: edpb.europa.eu/about-edpb/board/members_en. We encourage you to contact us first so we can address your concerns.
Summary of Categories (CCPA/CPRA) — click to expand
- Identifiers: name, email, IP — collected.
- Customer records: account ID, membership status — collected.
- Internet/Network activity: usage analytics, events — collected.
- Geolocation (approx.): derived from IP — collected.
- Inferences: limited product interest groupings — possibly derived.
- Sensitive data: none required for basic access; if collected (e.g., authentication tokens), usage is limited and protected.
Contact & Legal Notice
This section tells you who is behind VersEngin, how to contact us about privacy or legal matters, and provides the service provider identification required for websites operating from Spain.
- VersEngin is operated from Barcelona, Spain.
- You can reach our privacy contact at dpo@versengin.com.
- Hana Verse is a fictional digital persona, not a separate legal entity.
1) Identity & Contact
Service provider (Spain): VersEngin Studio Labs
Tax ID: Y1002511R
Address:08019 Barcelona, Spain
Email (DPO/Privacy): dpo@versengin.com
The “Hana Verse” persona is a fictional digital character used as a brand and creative interface for VersEngin; it is
not a separate legal entity.
2) Notices; Service of Process
Formal notices should be sent to the email above and will be deemed given upon confirmed receipt. For service of process, please contact us by email to arrange a proper address and method consistent with applicable law.
3) Accessibility
We aim to provide accessible content. To request an alternative format of any policy or to report an accessibility issue, contact dpo@versengin.com.
4) Changes to This Legal Hub
We may update this page to reflect changes in our Services, providers, or legal requirements. Material changes will be communicated as required by law.
This document is provided to meet common global requirements for online services (including GDPR and CCPA/CPRA). It does not constitute legal advice. For product- or jurisdiction-specific questions, please consult qualified counsel.
Policy Updates & Change Log
This section tracks when we last updated these policies and highlights significant changes.
- The Legal Hub is reviewed at least once every 12 months.
- Material changes are communicated via on-site notice or email where applicable.
We review and update this Legal Hub at least once every 12 months or as required by law. Significant changes will be announced via on-site notice or email where applicable.
- 17 Dec 2025 — v1.3 compliance update: added Spanish Legal Notice (service provider identification), clarified GDPR legal bases for consent-based analytics, aligned Cookies “Regional Notes” with prior consent, and expanded “similar technologies” disclosure (sessionStorage/local storage).
- 7 Dec 2025 — v1.2 update to reflect Hana Verse persona, explicit consent management via Cookiebot, Cloudflare edge/Workers usage, and current analytics/early-access stack.
- 31 Oct 2025 — Initial consolidated Legal Hub v1.
- Planned: Annual refresh v1.4 (Dec 2026) or earlier if services change.