VeritableRoll
Back to signup

Subscription terms and data processing

Version 2026-10-06.2 · 6 October 2026

Your completed signup form, selected plan and billing frequency, these terms and the processing/provider schedules below form your order. You accept them for the organisation you name. A free trial starts when your trial workspace is created and lasts 14 days. No card is requested, no Stripe customer or subscription is created for the trial, and no automatic charge follows it. A paid subscription starts only when an authorised administrator explicitly chooses a plan and completes payment. We retain the exact accepted document and its hash with your order; later page changes do not alter that agreement. These terms apply to organisations buying for business or professional purposes. The processing schedule takes precedence for personal data; a separately agreed written variation takes precedence for that variation.

You are appointed as the initial administrator, notice recipient, privacy contact and hold-review owner. You can arrange changes through your workspace or support. Your recorded source system remains authoritative until your administrators approve the migration. The standard order covers membership records, branches, CSV import, renewal assessment, independent review, issuance, exports and customer support. Member payment collections, campaigns, public applications, sensitive data and custom integrations need a separate agreed setup; the subscription does not activate them automatically.

1. Supplier and service

The supplier is ORRA DESIGNS LIMITED, registered in Scotland SC462855, trading as VeritableRoll, with registered office at Top Floor, No. 36 Lansdowne Crescent, Glasgow, G20 6NH, Scotland. VAT number GB467479437. Notices and support: hello@veritableroll.com.

VeritableRoll provides the hosted membership administration and renewal functions identified in the order. Access is granted for the subscription term to the customer's authorised staff and members within the purchased allowances. Customer records remain the customer's property. Orra retains ownership of its software, documentation and generic improvements; there is no right to sell, sublicense or copy the software.

A customer appoints at least one central administrator and a separate reviewer where its workflow requires an independent decision. The customer determines eligibility rules and makes renewal decisions. The software records and explains those decisions; it does not certify a person's professional competence or replace the customer's regulatory responsibilities.

The order states whether the source system remains authoritative or an agreed cutover has occurred. Import includes one standard CSV mapping and reconciliation session. Custom integrations, document migration, data cleansing and additional consultancy require a separately accepted scope and fee. Payment collection, recurring member billing, bulk email and public applications are included only if expressly ordered and accepted. Association membership fees go to that association's account; they are separate from the customer's subscription payable to Orra.

2. Free trial, prices and billing

The trial includes a private workspace under the selected member and branch allowances. The guided sample is a separate fictional workspace and never populates your register. Real imports follow the processing schedule below. At trial expiry, editing stops; your administrator can still view and export records for 30 days or choose a paid plan to resume. The same workspace and records carry forward on payment. After the return window, the controlled account-exit process applies. You can request earlier deletion through support. One free trial is available per administrator email; additional evaluations require agreement. A paid plan begins immediately on successful checkout, even if trial days remain.

PlanIncluded members / branchesMonthly, excluding VATAnnual, excluding VAT
Association2,000 / 5£99£990
Network5,000 / 15£149£1,490
Federation15,000 / 30£249£2,490

The order confirms the plan, allowances, currency and billing frequency. These are plan allowances, not a claim that 15,000 is the software's absolute limit. Larger workloads need a written capacity and price agreement. Orra will not automatically upgrade a plan or charge an overage without agreement. It will contact the customer when an allowance is reached; existing records and export remain available, while further additions may be paused until scope is agreed.

Subscription fees are payable in advance from the agreed service start date and renew monthly or annually on the corresponding anniversary. Applicable VAT is additional and shown on the invoice. Payment uses the named VeritableRoll Stripe account. Manual invoices, if agreed in the order, are due within 14 days. Payment-processing, email-provider and association collection fees are additional only where a separately agreed order identifies them; no undisclosed platform transaction charge applies.

Orra will give at least 30 days' written notice of a price increase, effective no earlier than the next renewal after that notice. Annual prices remain fixed for the paid term. Customers may cancel renewal before the increase takes effect. Disputed amounts raised promptly and in good faith will be investigated; undisputed amounts remain payable.

3. Term, cancellation and suspension

The customer may cancel automatic renewal at any time before its next billing date through the available billing controls or by emailing the monitored contact address. Access continues until the paid term ends. Ordinary cancellation does not refund an already started month or annual term. Orra may agree a refund in writing. Orra refunds unused prepaid service where it terminates for convenience, cannot resolve a material service breach within the period below, or an unresolved reasonable subprocessor objection ends the affected service.

Either party may terminate for a material breach not remedied within 30 days after written notice describing it, or immediately if the breach cannot reasonably be remedied. A serious security threat or unlawful use may require immediate, proportionate suspension. For non-payment Orra will give written notice and at least 14 days to resolve it before suspension. Suspension does not authorise deletion: return, export and agreed retention obligations continue. Orra will explain the reason and restoration steps unless legally prohibited.

A change of legal supplier is not automatic. Orra must notify the customer and arrange any required assignment, novation, processing-contract and billing changes before a new entity supplies or invoices the service. VAT treatment follows the actual supplier and applicable law at that time.

4. Customer responsibilities and acceptable use

The customer must have a lawful basis and necessary notices for its member data, limit uploads to the permitted fields, keep source records reasonably accurate, maintain its own source-system exports during parallel running, and appoint appropriate reviewers. It must protect credentials, promptly revoke departed staff and report suspected compromise. Shared staff accounts are not permitted.

Neither party may use the service to introduce malicious code, gain unauthorised access, defeat access controls or deliberately disrupt other customers. The customer must not import sensitive or excluded data without a separately agreed assessment. Orra may isolate an offending import while working with the customer to correct it, preserving necessary incident evidence under restricted access.

5. Support, maintenance and recovery

Included support is by email on UK business days, 09:00–17:00 Europe/London, with a target acknowledgement within one business day. Acknowledgement is not a resolution guarantee. Urgent security and service-loss reports receive priority. Orra will give reasonable advance notice of planned disruptive maintenance and updates during an active incident. No 24-hour staffed support, guaranteed uptime percentage or service-credit scheme is included.

The recovery schedule targets encrypted backups every six hours, transfer and independent deletion checkpoints every five minutes, and restoration within one business day after a disaster is assessed and required recovery material is available. These are operating targets, not guaranteed maximum data loss or restoration deadlines. The current operating schedule is included below. Recovery must replay the latest independently retained deletion journal before the recovered service accepts users.

The customer receives standard register and decision-history exports without an exit fee. Unless it requests earlier deletion, it has a 30-day period after termination to arrange verified return. Orra then deletes active member data under the agreed instructions. Isolated encrypted copies expire through the agreed backup/snapshot cycle, up to 35 days after the last affected archive was made; they remain beyond operational use and subject to deletion replay. Legal retention exceptions must be identified, restricted and explained. The operational schedule specifies the detailed exit procedure.

6. Confidentiality, data protection and security

Each party protects the other's confidential information, uses it only to deliver or receive the service, and limits disclosure to personnel and authorised providers who need it and are bound to confidentiality. The duty excludes information already lawfully public, independently developed or lawfully received without restriction. Legally required disclosure is limited to what is required, with notice where permitted. These duties survive termination.

The processing schedule provides the binding instructions and Article 28 terms for member data. Orra does not use those records for advertising or training AI models. Orra separately controls its own billing, business-contact and service-security records as described in the privacy notice. Security and subprocessor commitments are stated specifically; no insurance policy, certification, UK-only hosting or operational guarantee is implied by these terms.

7. Liability

neither party excludes or limits liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or anything that cannot lawfully be limited. Subject to that, each party's aggregate liability arising from the agreement in any 12-month period is limited to the greater of £1,000 and the subscription fees paid or payable for that period. For breach of confidentiality or data-protection obligations, the cap instead is the greater of £10,000 and twice those fees. Payment obligations are not capped by this clause. There is no exclusion of the processor's mandatory obligations or a data subject's statutory rights.

Neither party is liable for indirect or consequential loss. Reasonable direct costs of restoring or returning customer data following Orra's breach are treated as direct loss, subject to the applicable lawful cap. No insurance is represented as being in force.

8. General

Each party will give notices to the address named in the order and keep it monitored. Neither party is liable for delay caused by circumstances reasonably beyond its control, but must mitigate the effect and keep the other informed; this does not remove agreed data protection, return or payment duties. If the service remains unavailable for more than 30 days as a result, the customer may terminate and receive a refund for unused prepaid service.

Neither party may assign the agreement without the other's written agreement, not to be unreasonably withheld, except as expressly agreed in the order. A variation must be recorded in writing by authorised representatives; changing a public webpage does not retrospectively change a signed order. If a provision is unenforceable, the rest remains effective. Failure to exercise a right is not a waiver. The agreement does not confer third-party contractual rights, without affecting statutory data-subject rights. Scots law governs the agreement and the Scottish courts have jurisdiction, subject to any mandatory applicable law.

Processing instructions

Processing covers collection through an approved import or authenticated entry, organisation by branch, validation, assessment, human review, issuance, export, correction, agreed retention and erasure. It lasts for the service term plus the agreed return/deletion period. Data subjects are adult members, applicants where specifically enabled, and the customer's staff/officers.

Permitted fields: names; necessary contact addresses; stable source and member identifiers; membership grade, branch and dates; CPD totals/periods; professional certificate and insurance validity dates/references; fee amounts and payment status/references; staff attribution and concise operational reasons. Evidence documents remain in the customer's authorised source system; a reference is not permission to upload their contents.

Exclude children, health information, criminal/DBS information (including revealing status flags), allegations, disciplinary narratives, special-category membership inferences, unrestricted attachments and unrelated free text until specifically assessed and agreed. A body whose membership itself reveals sensitive information needs separate screening. Free text must contain only the permitted operational facts. The customer assesses whether a DPIA is needed; Orra supplies system information and helps resolve identified risks. The renewal engine supports named human reviewers and is not sold as an autonomous decision-maker about professional practice rights.

Processor commitments

Orra will process only documented customer instructions, including transfers, unless UK law requires otherwise; it will notify the customer of that requirement where legally permitted and immediately flag instructions it believes unlawful. Authorised personnel must be bound to confidentiality. Orra will maintain risk-appropriate Article 32 security, assist with rights requests, security, breach notifications, DPIAs and regulator consultation, and notify the customer of personal-data breaches without undue delay. Initial notification need not await a complete investigation.

Only authorised subprocessors may be used, under equivalent protection duties; Orra remains responsible for their performance. The attached schedule identifies them. Proposed changes require at least 30 days' notice and an opportunity to object before processing moves. An unresolved reasonable objection leads to an alternative or termination of the affected service with data returned.

Orra will provide compliance information and contribute to customer or appointed-auditor audits/inspections. At termination, the customer chooses return or deletion; remaining copies are deleted unless legally required to retain them, with the legal reason and protection recorded. These commitments follow the ICO's processor-contract requirements.

## Retention, recovery and exit schedule

The assessment-history and archived-member periods you enter at signup are your recorded instructions. The verified central administrator must confirm those periods in the workspace before automatic erasure is authorised. Holds require an identified reason and owner and at least quarterly review. Do not store data longer than your lawful purpose requires; correction, export and controlled erasure are available through the workspace and support.

Original CSV files are parsed into bounded staging. Row payloads are cleared when processed, excluded or cancelled; unfinished imports expire under the configured deadline. Sessions expire after eight hours. Application diagnostics exclude request bodies and member fields and use size-based log rotation, rather than a promised day-based retention period.

Encrypted backups run every six hours, with off-host transfer and independent deletion checkpoints scheduled every five minutes. Recovery is targeted within one business day after the incident has been assessed and recovery materials are available. These are operating targets, not guarantees. Off-host archives are retained for 28 days, with up to seven daily snapshots. Restores must replay the independent deletion journal before access is enabled.

On termination, access and writes are frozen. You may request an export followed by deletion, or deletion without return. The standard return window is 30 days; earlier deletion may be instructed. We verify the recipient, export the organisation records and retire its managed identities through the controlled exit process. Isolated backups remain beyond operational use until expiry, up to 35 days after the last affected archive, and remain subject to deletion replay. Any legal retention exception is identified and restricted. Billing and contractual records are held separately for the applicable accounting and legal purposes; they are not member-register records. Contact us for your recorded order or to exercise data rights.

Providers, locations and authorised access

You authorise the following processing for this standard service. Changes to membership-data subprocessors require the notice and objection process above.

ComponentPurpose and location
Hetzner Online GmbHMembership application, PostgreSQL and self-hosted Keycloak identity in Nuremberg, Germany. Encrypted off-host Storage Box backups and an independent monitor in Falkenstein, Germany. Account processing agreement accepted for Orra on 6 October 2026.
Resend / Plus Five Five, Inc.Account setup and operational email, with minimal contact details. EU sending region; stored data in the United States. Disclosed email/log retention is 30 days plus seven-day provider backups; contract-termination deletion may take up to 90 days under the provider agreement. The executed agreement includes UK transfer clauses. Member lists and assessment evidence are not sent.
StripeSubscription checkout, invoices and customer billing portal. Orra is the seller. Payment details are handled by Stripe under its applicable privacy and processing terms; the membership database does not store card details.
CloudflareAuthoritative DNS. The membership application uses DNS-only records. General enquiries to hello@ are forwarded through Cloudflare to the operator’s Gmail; this uses global provider infrastructure. Do not email member records or sensitive documents.
Orra operator access and recovery deviceAuthorised administration and encrypted recovery testing from the UK and Spain. Access is restricted to operating and supporting the service. Recovery keys and test copies are held on the operator-controlled Mac.

Customer support tickets are stored with the application. Keep them to the issue, relevant record references and permitted operational facts; do not attach or paste sensitive member data. The general-enquiry mailbox is for business questions only. No AI provider receives customer member records through the production service.

Signup information and privacy

Orra uses your organisation, administrator and billing information to establish and operate the business account. The signup session uses a necessary, secure, HttpOnly cookie lasting seven days, so returning from Stripe resumes the same order. It is not used for advertising. Signup documents and instructions are retained with the commercial agreement. Failed or abandoned signups are reviewed and stripped of their contact and instruction fields after 30 days where no subscription exists; Stripe may retain its own checkout/customer records under its terms. We do not automatically subscribe you to marketing. General privacy questions and rights requests go to hello@veritableroll.com; you may complain to the Information Commissioner’s Office.