Data Processing Agreement
Last updated: 30 July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (the “Customer”, acting as controller) and Verbatim AI Ltd trading as Verbatim (“Verbatim”, acting as processor) for the Verbatim service (the “Agreement”). It applies where, and to the extent that, Verbatim processes personal data on the Customer’s behalf — for example the account data of a Team or Enterprise customer’s users. It takes effect on the Customer’s acceptance of the Agreement.
1. Definitions
“UK GDPR”, “controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, “Data Protection Law”). “Sub-processor” means any processor engaged by Verbatim.
2. Roles and scope
The Customer is the controller and Verbatim is the processor of the Customer Personal Data described in Schedule 1. Verbatim will process Customer Personal Data only to provide the service and only on the Customer’s documented instructions (including those in the Agreement and this DPA), unless required to do otherwise by law, in which case it will inform the Customer first where lawful to do so.
3. Verbatim’s obligations
- Confidentiality. Ensure personnel authorised to process the data are bound by confidentiality.
- Security. Implement appropriate technical and organisational measures to protect the data, taking account of the risk (Schedule 3).
- Sub-processors. The Customer authorises the sub-processors listed in Schedule 2. Verbatim will impose equivalent data-protection obligations on each, remains liable for their acts and omissions, and will give the Customer reasonable notice of any intended change, allowing the Customer to object on reasonable data-protection grounds.
- Assistance. Taking account of the nature of processing, assist the Customer by appropriate measures to respond to data-subject requests, and to meet the Customer’s obligations around security, breach notification, data protection impact assessments and prior consultation.
- Breach. Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information the Customer reasonably needs.
- Deletion or return. On termination, delete or return Customer Personal Data at the Customer’s choice, save where storage is required by law.
- Audit. Make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, on reasonable notice and subject to confidentiality, no more than once a year unless required by a supervisory authority.
4. International transfers
Verbatim will not transfer Customer Personal Data outside the UK/EEA except where an approved transfer mechanism (an adequacy decision, or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses) is in place, as reflected in Schedule 2.
5. Liability
Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement.
6. Term and governing law
This DPA lasts for as long as Verbatim processes Customer Personal Data under the Agreement. It is governed by the law of England and Wales.
Schedule 1 — Details of processing
- Subject matter: provision of the Verbatim service to the Customer.
- Duration: the term of the Agreement.
- Nature and purpose: hosting, storing and processing account and usage data to operate the service, including authentication, search, alerts and AI research features.
- Types of personal data: names, email addresses, hashed credentials, usage and preference data, and any personal data contained in searches or questions submitted by the Customer’s users.
- Categories of data subjects: the Customer’s authorised users (e.g. staff or team members).
Schedule 2 — Authorised sub-processors
| Sub-processor | Purpose | Location / transfer safeguard |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting and storage | Germany (EEA) — adequacy |
| Brevo (Sendinblue SAS) | Email delivery | France (EEA) — adequacy |
| Stripe Payments Europe, Ltd | Payment processing | Ireland (EEA) / USA — SCCs / UK Addendum |
| Anthropic, PBC | AI answers and summaries | USA — SCCs / UK Addendum |
| Voyage AI | Semantic search embeddings | USA — SCCs / UK Addendum |
Schedule 3 — Technical and organisational measures
- Encryption of data in transit (HTTPS/TLS).
- Passwords stored only as salted, iterated hashes; no plaintext credentials.
- Access to production systems and data restricted to authorised personnel on a need-to-know basis.
- Reputable infrastructure providers with physical and network security controls.
- Logging and rate-limiting to detect and limit abuse.
- Regular application updates and backups.
Contact
Data protection queries: privacy@getverbatim.co.