Last updated: 3 July 2026
Data Processing Agreement
Verisum Ltd
This Data Processing Agreement ("DPA") forms part of, and is subject to, the Master Subscription Agreement or other written or electronic agreement between the parties for the provision of the Verisum services (the "Principal Agreement"). In the event of conflict between this DPA and the Principal Agreement in respect of the Processing of Personal Data, this DPA prevails.
Between:
- Verisum Ltd, a company incorporated in England and Wales (company number 16946194) whose registered office is at Fyning Hill Cottage, Rogate, Petersfield, England, GU31 5EB ("Verisum", the "Processor"); and
- The Customer identified in the Principal Agreement (the "Customer", the "Controller"),
each a "party" and together the "parties".
Effective date: the date of the Customer's acceptance of the Principal Agreement (the "Effective Date").
Background
(A) The Customer uses Verisum's AI-governance platform (the "Services") under the Principal Agreement.
(B) In providing the Services, Verisum Processes Personal Data on behalf of the Customer.
(C) This DPA sets out the terms on which Verisum Processes that Personal Data, in accordance with Article 28 of the UK GDPR and the EU GDPR.
1. Definitions
1.1 Capitalised terms not defined here have the meaning given in the Principal Agreement or in Data Protection Law.
1.2 In this DPA:
- "Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including (i) the UK GDPR and the Data Protection Act 2018 ("UK GDPR"); (ii) Regulation (EU) 2016/679 ("EU GDPR") where applicable; and (iii) the Privacy and Electronic Communications Regulations 2003, each as amended or replaced.
- "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Special Category Data" have the meanings given in the UK GDPR.
- "Customer Personal Data" means Personal Data that Verisum Processes on behalf of the Customer in connection with the Services, as further described in Annex 1.
- "Sub-processor" means any third party engaged by Verisum to Process Customer Personal Data.
- "UK IDTA" means the International Data Transfer Agreement issued by the UK Information Commissioner, and/or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
- "EU SCCs" means the standard contractual clauses approved by European Commission Decision 2021/914.
2. Roles and scope of Processing
2.1 The parties acknowledge that, for the purposes of Data Protection Law, the Customer is the Controller and Verisum is the Processor in respect of Customer Personal Data.
2.2 Annex 1 sets out the subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects.
2.3 Verisum shall Process Customer Personal Data only: (a) on the Customer's documented instructions (including as set out in this DPA and the Principal Agreement, and as necessary to provide the Services), unless required to do otherwise by law (in which case Verisum shall, where legally permitted, inform the Customer of that legal requirement before Processing); and (b) for the purposes described in Annex 1 and not for any other purpose.
2.4 Verisum shall inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law. Verisum is not obliged to conduct a legal review of the adequacy of the Customer's instructions.
2.5 The Customer warrants that it has a valid lawful basis for the Processing and has provided all necessary notices and obtained all necessary consents for Verisum to Process Customer Personal Data as contemplated by the Principal Agreement.
3. Verisum's obligations
Verisum shall:
3.1 implement and maintain the technical and organisational measures set out in Annex 2 to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing;
3.2 ensure that persons authorised to Process Customer Personal Data are bound by an appropriate obligation of confidentiality and have received appropriate data-protection training;
3.3 taking into account the nature of the Processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to Data Subject requests under Chapter III of the UK GDPR (see clause 6);
3.4 assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of Processing and the information available to Verisum;
3.5 make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits in accordance with clause 8; and
3.6 at the Customer's choice, delete or return all Customer Personal Data in accordance with clause 9.
4. Confidentiality
Verisum shall treat all Customer Personal Data as confidential and shall not disclose it except as permitted by this DPA or the Principal Agreement, as required to provide the Services, or as required by law.
5. Security
5.1 Verisum shall implement the technical and organisational measures described in Annex 2.
5.2 The Customer acknowledges that security measures are subject to technical progress and development and that Verisum may update or modify them from time to time, provided such updates do not materially reduce the overall security of the Services.
6. Data Subject rights
6.1 Verisum shall, to the extent legally permitted, promptly notify the Customer if it receives a request from a Data Subject to exercise rights under Data Protection Law in respect of Customer Personal Data (an "DSR"), and shall not respond to that DSR itself except on the Customer's documented instructions or as required by law.
6.2 Taking into account the nature of the Processing, Verisum shall provide reasonable assistance (including via Services functionality such as data export and deletion tools) to enable the Customer to respond to DSRs.
7. Personal Data Breach
7.1 Verisum shall notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 The notification shall, to the extent known, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
7.3 Verisum shall take reasonable steps to mitigate and remediate the breach and shall cooperate with the Customer and provide reasonable information to enable the Customer to meet its own breach-notification obligations.
7.4 Verisum's notification of, or response to, a Personal Data Breach shall not be construed as an acknowledgement of fault or liability.
8. Audit
8.1 Verisum shall make available to the Customer, on reasonable prior written request and no more than once per 12-month period (unless required by a supervisory authority or following a Personal Data Breach), such information as is reasonably necessary to demonstrate compliance with this DPA.
8.2 The Customer may, on 30 days' notice, audit Verisum's compliance, provided such audits are conducted during business hours, do not unreasonably interfere with Verisum's operations, are subject to confidentiality, and (where Verisum makes available third-party audit reports or certifications) the Customer first accepts those reports in satisfaction of the audit right to the extent they address the relevant matters.
9. Deletion or return
9.1 On termination or expiry of the Principal Agreement, Verisum shall, at the Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless retention is required by law.
9.2 Verisum may retain Customer Personal Data in routine backups for a limited period consistent with its backup cycle, during which such data remains subject to this DPA and is not actively Processed.
9.3 On-chain records. Where the Customer uses Verisum's cryptographic anchoring features (Verisum Verify), the Customer acknowledges that only cryptographic hashes — which do not themselves contain or reveal Personal Data — are anchored to a distributed ledger, and that such hashes are by design immutable and cannot be deleted. The Customer shall not submit Personal Data for on-chain anchoring in a form from which Personal Data could be derived.
10. International transfers
10.1 Verisum shall not transfer Customer Personal Data outside the UK or the EEA except in compliance with Data Protection Law.
10.2 Where such a transfer occurs (including via a Sub-processor listed in Annex 3), the parties shall put in place an appropriate transfer mechanism, being the UK IDTA and/or EU SCCs (with the UK Addendum where relevant), or shall rely on an adequacy decision or other lawful transfer mechanism. The relevant clauses are incorporated by reference and completed as set out in Annex 3.
11. Sub-processing
11.1 The Customer grants Verisum general authorisation to engage Sub-processors, subject to this clause 11. The Sub-processors approved as at the Effective Date are listed in Annex 3.
11.2 Verisum shall impose on each Sub-processor data-protection obligations that are substantially the same as those in this DPA, and shall remain liable to the Customer for the performance of each Sub-processor's obligations.
11.3 Verisum shall give the Customer at least 30 days' notice of any intended addition or replacement of a Sub-processor. The Customer may object on reasonable data-protection grounds within that period; the parties shall then work in good faith to resolve the objection, failing which the Customer may terminate the affected Services.
12. Liability
The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Principal Agreement.
13. Term and termination
This DPA takes effect on the Effective Date and continues until all Customer Personal Data has been deleted or returned in accordance with clause 9. Termination of this DPA does not affect the Principal Agreement.
14. General
14.1 Governing law. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, save that nothing limits any mandatory rights of Data Subjects or supervisory authorities.
14.2 Order of precedence. In the event of conflict between the transfer mechanisms referenced in clause 10 and the remainder of this DPA, the transfer mechanisms prevail to the extent of the conflict.
14.3 Severance. If any provision is held invalid, the remainder continues in force.
Annex 1 — Details of Processing
| Item | Detail | |---|---| | Subject matter | Provision of the Verisum AI-governance platform (Services) to the Customer. | | Duration | For the term of the Principal Agreement, plus any retention period under clause 9. | | Nature and purpose | Hosting, storage, and processing of Customer-supplied governance data to deliver the Services, including organisational and system assessments, AI policy generation, staff declarations, vendor and incident registers, monitoring/drift analysis, reporting, and (where enabled) cryptographic attestation and anchoring. | | Types of Personal Data | Business contact details of the Customer's users and personnel (name, work email, job title, organisation); account authentication data; staff-declaration data (name, work email, declaration responses); user-generated content within governance records; usage/log data. Verisum is not designed for, and the Customer must not submit, Special Category Data (as defined in UK GDPR Article 9). | | Categories of Data Subjects | The Customer's employees, contractors, and authorised users; personnel named in the Customer's governance records; the Customer's own vendor/supplier contacts where entered by the Customer. | | Frequency | Continuous, for the duration of the Services. |
Annex 2 — Technical and Organisational Measures (TOMs)
Verisum implements the following technical and organisational measures to protect Customer Personal Data. This annex reflects controls in place at the time of publication; Verisum reviews and updates these measures on a continuous basis.
Encryption
- Data encrypted in transit using TLS 1.2 or above (HTTPS enforced across all customer-facing endpoints; HSTS enabled).
- Data encrypted at rest via the managed database provider (Supabase / PostgreSQL), which encrypts all customer data at rest using AES-256.
- Cryptographic hashes (SHA-256) used for API-key storage and for tamper-evident audit trails on governance attestations.
Access control
- Row-Level Security (RLS) enforced at the database layer to segregate data by organisation, backstopping application-level org isolation.
- Role-based access control within the application; least-privilege principle for administrative access.
- Authentication via email magic-link and email/password with cookie-based sessions managed by Supabase Auth.
- Two-factor authentication (TOTP) available and opt-in per user for customer accounts. Session management includes an "active sessions" view with the ability to revoke individual sessions.
- API keys for machine-to-machine access are SHA-256 hashed at rest and support rotation.
- Rate limiting enforced on authentication endpoints, API-key-authenticated endpoints, and LLM-backed endpoints.
Infrastructure & network security
- Application and database hosted with reputable providers (see Annex 3); provider-managed network controls, firewalls, and DDoS protection.
- Secrets and credentials stored outside source control via environment configuration; a startup guard prevents accidental client-side exposure of the database service-role key.
- Content Security Policy (CSP), Strict-Transport-Security, X-Frame-Options: DENY, and X-Content-Type-Options: nosniff enforced on all responses.
- Regular dependency vulnerability scanning; secret-scanning (gitleaks) enforced on every code change via pre-push hooks and CI.
Personal Data handling in evidence records
- Free-text fields on attestation, provenance, and incident-lock records are scrubbed for common Personal Data patterns (emails, phone numbers, national identifiers, credit card numbers, titled names) before persistence and before inclusion in cryptographic hash preimages.
Resilience & backup
- Automated daily backups via the managed database provider, with 7-day point-in-time recovery on the current tier. Backup retention is subject to the hosting provider's terms and Verisum's plan level.
- Application deployed via managed hosting with automated rollback on failed deploys.
Logging & monitoring
- Application and access logging retained by the hosting provider (runtime logs surfaced via the hosting dashboard).
- Application-side audit log records governance-relevant events (attestations, exchanges, incident locks, IBG decisions, authentication events including login, logout, and MFA changes).
- Uptime monitoring via the hosting provider's dashboard. Formal alerting (paging/on-call rotation) is a roadmap item.
Organisational measures
- Personnel bound by written confidentiality obligations.
- Secure software-development practices: mandatory pre-deploy checks (TypeScript compile, lint, tests, secret scan, production build) enforced via a git pre-push hook and required as a status check on the main branch on GitHub.
- Documented incident-response process; incidents are recorded in an immutable, DB-trigger-enforced audit log.
- Access to production systems and secrets is restricted to authorised personnel.
Sub-processor management
- Written terms with Sub-processors imposing obligations equivalent to those in this DPA (clause 11).
- Sub-processor register (Annex 3) maintained and reviewed as new integrations are added.
Annex 3 — Approved Sub-processors
| Sub-processor | Purpose | Processing location(s) | |---|---|---| | Supabase | Database, authentication, and backend hosting (PostgreSQL) | EU (Germany) | | Hostinger | Web/application hosting and CDN edge delivery | UK / EU; CDN edge globally | | Stripe | Payment processing and subscription billing (Stripe acts as a separate Controller for payment data) | UK / EU / US | | Resend | Transactional email delivery | EU | | Anthropic | AI model processing for AI policy generation and Copilot features. Verisum operates under Anthropic's standard API terms, which include a no-training commitment on API content. Customer content sent to the model is limited to the specific prompt fields exposed in the Verisum Copilot flows. | US | | Make.com | Workflow automation for scheduled reporting jobs (aggregate metrics only). No Personal Data flows through Make.com. | EU |
International transfer mechanism: For any Sub-processor Processing Customer Personal Data outside the UK/EEA, the parties rely on the UK International Data Transfer Agreement (IDTA) and the EU Standard Contractual Clauses with the UK Addendum, as applicable to the transfer.