Data Processing Addendum

This Data Processing Addendum forms part of the Terms of Service between you (the Customer) and VERA (the Processor) and applies where VERA processes Personal Data on your behalf. It takes effect automatically when you accept the Terms of Service; you do not need to sign a separate copy, though we will sign one on request. Where this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA controls.

Version
1.0
Effective
July 28, 2026
Last updated
July 28, 2026
Revisions
1
On this page (12 sections)
  1. 1. 1. Definitions
  2. 2. 2. Roles and scope
  3. 3. 3. Processing on documented instructions
  4. 4. 4. Confidentiality
  5. 5. 5. Security measures
  6. 6. 6. Subprocessors
  7. 7. 7. International transfers
  8. 8. 8. Assistance to the Customer
  9. 9. 9. Personal Data Breach
  10. 10. 10. Return and deletion
  11. 11. 11. Audit rights
  12. 12. 12. Liability and term

1. 1. Definitions

"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (2016/679) ("EU GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the CCPA as amended.

"Personal Data" means personal data, personal information, or the equivalent under Data Protection Law, that VERA processes on the Customer's behalf under the Terms of Service. "Controller", "Processor", "Data Subject", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the EU GDPR.

"Subprocessor" means a third party engaged by VERA to process Personal Data. "Standard Contractual Clauses" or "SCCs" means the clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

2. 2. Roles and scope

The Customer is the Controller and VERA is the Processor in respect of Personal Data the Customer submits to the Service about its own customers, leads, contacts, employees, and contractors.

VERA is an independent Controller in respect of the Customer's own account data, billing data, support correspondence, and product usage data. That processing is governed by the Privacy Policy, not by this DPA.

The subject matter of the processing is the provision of the Service. The duration is the term of the Terms of Service plus any period before deletion under section 10. The nature and purpose is hosting, storing, organizing, generating content from, transmitting, and displaying Personal Data so the Customer can operate its business.

  • Categories of Data Subject. The Customer's customers, prospects and leads, contacts at customer organizations, the Customer's employees, technicians, and crew, and recipients of messages the Customer sends.
  • Categories of Personal Data. Names, email addresses, telephone numbers, postal and service addresses, business and job details, appointment times, communications content, estimate and invoice contents, photographs of premises and work sites which may incidentally include people, signatures captured on accepted estimates, and any other data the Customer chooses to enter.
  • Special categories. The Service is not designed to process special category data under Article 9, nor data relating to criminal convictions. The Customer must not submit it. If the Customer does so anyway, it does so on its own responsibility and warrants it has a lawful basis.

3. 3. Processing on documented instructions

VERA processes Personal Data only on the Customer's documented instructions, including for international transfers, unless required otherwise by law to which VERA is subject, in which case VERA will inform the Customer before processing unless that law prohibits it on important grounds of public interest.

The Terms of Service, this DPA, the configuration the Customer sets in the Service, and the actions the Customer takes or approves in the Service together constitute the Customer's documented instructions. Additional instructions require agreement, and may attract a fee where they require work outside the Service's ordinary functionality.

VERA will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.

VERA does not sell Personal Data, does not share it for cross-context behavioral advertising, and does not retain, use, or disclose it for any purpose other than performing the Service, as required by the CCPA. VERA certifies that it understands and will comply with these restrictions.

4. 4. Confidentiality

VERA ensures that personnel authorized to process Personal Data are bound by an appropriate obligation of confidentiality and are granted access only where needed to perform their role.

Access to production data is limited to personnel who require it to operate and support the Service. Administrative actions taken by VERA operators are recorded in an append-only administrative audit log.

5. 5. Security measures

VERA implements appropriate technical and organizational measures to protect Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. The measures in place are described in detail in the Security Policy and summarized here:

  • Encryption in transit. HTTPS throughout, HTTP requests redirected to HTTPS in production, and HTTP Strict Transport Security asserted with a two-year max-age and includeSubDomains.
  • Encryption of credentials at rest. Third-party connector tokens and API keys encrypted with AES-256-GCM using a dedicated key that is required to be set in production and is separate from the session-signing secret.
  • Authentication. Passwords hashed with bcrypt at a work factor of 12, mandatory email verification before password sign-in, single-use time-limited reset tokens, and a session revocation counter that invalidates every issued session at once.
  • Access control. Every query is scoped to the authenticated account. Administrative access is restricted to an explicit operator allowlist configured in the environment.
  • Application hardening. A Content Security Policy, framing denied, MIME sniffing disabled, a restrictive referrer policy, camera, microphone, and geolocation disabled by Permissions-Policy, durable rate limiting on authentication endpoints, and validation of server-side fetches against private and internal network ranges.
  • Integrity of external events. Inbound webhooks verified against each provider's signature scheme and deduplicated by event id so a replayed delivery cannot be applied twice.
  • Auditability. An append-only audit trail of every proposal, approval, execution, and security event in the account.
  • Configuration safety. Startup validation that refuses to run in production with a default session secret or a missing encryption key.

6. 6. Subprocessors

The Customer grants VERA general authorization to engage Subprocessors. The current list, with each one's role and location, is published on the Subprocessor List page, which forms part of this DPA.

VERA will give the Customer at least 30 days' notice before adding or replacing a Subprocessor, by updating that page and notifying account holders. The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused remainder of the term.

VERA imposes on each Subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for a Subprocessor's performance.

7. 7. International transfers

VERA processes Personal Data in the United States. Where the Customer transfers Personal Data subject to the EU GDPR, UK GDPR, or Swiss law to VERA, the parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and apply as follows.

Module Two (controller to processor) applies where the Customer is a controller. Module Three (processor to processor) applies where the Customer is itself a processor. In Clause 7, the docking clause applies. In Clause 9, Option 2 (general written authorization) applies with the 30-day notice period in section 6. In Clause 11, the optional independent dispute resolution body is not selected. In Clause 17, the clauses are governed by the law of Ireland. In Clause 18(b), disputes are resolved before the courts of Ireland. Annex I is populated by section 2 of this DPA and the Subprocessor List; Annex II is populated by section 5.

For transfers subject to the UK GDPR, the UK Addendum applies to the SCCs, with Tables 1 to 3 populated as above and, in Table 4, neither party may end the Addendum as set out in Section 19. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the clauses also protect data of legal entities.

8. 8. Assistance to the Customer

Taking into account the nature of the processing, VERA assists the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to Data Subject requests under Chapter III of the GDPR and equivalent laws.

In practice, the Service itself provides most of that capability: the Customer can find, correct, export, and delete records about a Data Subject directly. Where a request reaches VERA rather than the Customer, VERA will not respond to it substantively; it will inform the Data Subject to contact the Customer and will notify the Customer without undue delay.

VERA assists the Customer in complying with Articles 32 to 36, taking into account the information available to VERA, including with data protection impact assessments and prior consultation with a Supervisory Authority.

9. 9. Personal Data Breach

VERA notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.

The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not available at once, VERA provides information in phases without undue further delay.

VERA's notification is not an acknowledgment of fault or liability. Notifying Supervisory Authorities and Data Subjects is the Customer's responsibility as Controller; VERA will provide reasonable assistance.

10. 10. Return and deletion

The Customer can export its data and delete its account at any time from within the Service, which permanently removes Personal Data from the live database as described in the Account Deletion Policy.

On termination or expiry of the Terms of Service, VERA will, at the Customer's choice, delete or return Personal Data and delete existing copies, unless a law to which VERA is subject requires continued storage. If the Customer makes no election, VERA will retain the data while the account exists and delete it when the account is deleted.

The limited records that survive account deletion are named in the Account Deletion Policy. They consist of billing records held by our payment processor, operator accountability logs, anti-abuse counters, and provider-held infrastructure logs and backup snapshots that age out on the provider's cycle.

11. 11. Audit rights

VERA makes available to the Customer the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.

In the first instance VERA will satisfy an audit request by providing this DPA, the Security Policy, the Subprocessor List, and written responses to a reasonable security questionnaire. VERA does not currently hold a SOC 2 or ISO 27001 report to offer in place of one.

Where that is genuinely insufficient to demonstrate compliance, the Customer may conduct an on-site or remote audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, without unreasonably disrupting VERA's operations, and without access to any other customer's data or to VERA's multi-tenant infrastructure internals beyond what the audit requires. The Customer bears its own costs and VERA's reasonable costs. A Supervisory Authority may audit at any time as the law provides.

12. 12. Liability and term

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, to the extent permitted by Data Protection Law. Nothing in this DPA limits a Data Subject's rights under the Standard Contractual Clauses.

This DPA takes effect when the Customer accepts the Terms of Service and continues until VERA no longer processes Personal Data on the Customer's behalf. Sections concerning confidentiality, deletion, and liability survive.

To request a countersigned copy, or to raise a question about this DPA, write to support@myvera.io.

Change history

Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.

  1. v1.0July 28, 2026

    Initial Data Processing Addendum published.

Questions about this document?

Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.

Related

This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.