Verbatim

Data Processing Agreement

Last updated: 30 July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (the “Customer”, acting as controller) and Verbatim AI Ltd trading as Verbatim (“Verbatim”, acting as processor) for the Verbatim service (the “Agreement”). It applies where, and to the extent that, Verbatim processes personal data on the Customer’s behalf — for example the account data of a Team or Enterprise customer’s users. It takes effect on the Customer’s acceptance of the Agreement.

Most individual users do not need this document — for your own personal data, Verbatim is the controller and our Privacy Policy applies. This DPA is for business customers who need controller-to-processor terms. Business customers can request a countersigned copy at hello@getverbatim.co.

1. Definitions

“UK GDPR”, “controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, “Data Protection Law”). “Sub-processor” means any processor engaged by Verbatim.

2. Roles and scope

The Customer is the controller and Verbatim is the processor of the Customer Personal Data described in Schedule 1. Verbatim will process Customer Personal Data only to provide the service and only on the Customer’s documented instructions (including those in the Agreement and this DPA), unless required to do otherwise by law, in which case it will inform the Customer first where lawful to do so.

3. Verbatim’s obligations

4. International transfers

Verbatim will not transfer Customer Personal Data outside the UK/EEA except where an approved transfer mechanism (an adequacy decision, or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses) is in place, as reflected in Schedule 2.

5. Liability

Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement.

6. Term and governing law

This DPA lasts for as long as Verbatim processes Customer Personal Data under the Agreement. It is governed by the law of England and Wales.

Schedule 1 — Details of processing

Schedule 2 — Authorised sub-processors

Sub-processorPurposeLocation / transfer safeguard
Hetzner Online GmbHCloud hosting and storageGermany (EEA) — adequacy
Brevo (Sendinblue SAS)Email deliveryFrance (EEA) — adequacy
Stripe Payments Europe, LtdPayment processingIreland (EEA) / USA — SCCs / UK Addendum
Anthropic, PBCAI answers and summariesUSA — SCCs / UK Addendum
Voyage AISemantic search embeddingsUSA — SCCs / UK Addendum

Schedule 3 — Technical and organisational measures

Contact

Data protection queries: privacy@getverbatim.co.

Verbatim · Terms · Privacy · Cookies · DPA · hello@getverbatim.co
Contains Parliamentary information licensed under the Open Parliament Licence v3.0. Not affiliated with, or endorsed by, the UK Parliament.