This agreement sets out how Veritio processes personal data contained in the evidence records you send to your tenant. For that data you are the controller and Veritio is your processor, as required by Article 28 of the GDPR.
Draft · Last updated 17 July 2026
This Data Processing Agreement (“DPA”) forms part of theTerms of Service between the customer (“Controller”) and the Veritio entity operating Veritio Cloud (“Processor”). Where it conflicts with the Terms on the processing of personal data, this DPA prevails.
The Processor under this agreement is Yan Malinovskiy(sole proprietor), Belchenstraße 2, 79276 Reute, Germany (see the Imprint). This Data Processing Agreement is accepted electronically as part of account creation — opening a Veritio Cloud organization incorporates it into the contract under the Terms of Service. Enterprise customers may request a countersigned copy athello@getveritio.com.
The Controller determines the purposes and means of processing the personal data contained in its tenant evidence records. The Processor processes that data only on the Controller’s behalf to provide Veritio Cloud. This DPA applies to that processing for as long as the Processor holds such data.
The Processor processes personal data only on the Controller’s documented instructions, including those given through the service and this DPA, unless required to act otherwise by law — in which case, where permitted, it will inform the Controller first. The Processor will inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.
The Processor ensures that personnel authorized to process personal data are bound by confidentiality obligations and access such data only as needed to provide the service.
Taking account of the state of the art and the risks of processing, the Processor implements appropriate technical and organizational measures, including:
The Controller authorizes the Processor to engage the subprocessors listed below to provide the infrastructure of the service. Each subprocessor is bound by data-protection obligations no less protective than this DPA.
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application compute, object storage for evidence records, and transactional email delivery | Region pinned to the customer’s chosen storage region |
| Neon, Inc. (on Amazon Web Services) | Managed Postgres databases holding tenant metadata and evidence sequence state | Region pinned to the customer’s chosen storage region |
| Polar Software, Inc. | Payment and subscription processing (planned — activated when billing goes live) | Provider-operated infrastructure |
The Processor will give the Controller prior notice of any intended addition or replacement of a subprocessor so the Controller has an opportunity to object on reasonable data-protection grounds.
Where processing a personal data transfer outside the EEA requires it, the parties rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses, which are incorporated by reference for such transfers, together with any supplementary measures required. Region pinning lets the Controller keep evidence data within a chosen region.
Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests — including access, rectification, erasure, restriction, and portability — and to meet the Controller’s obligations on security, breach notification, and data-protection impact assessments. The service’s query and export tools are the primary means of this assistance. The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data.
On termination, the Controller may export its evidence data as verifiable bundles for 30 days. After that window, the Processor deletes or de-identifies the personal data it processes for the Controller, except to the extent retention is required by law. This reflects the append-only, verifiable nature of the evidence trail.
The Processor makes available information reasonably necessary to demonstrate compliance with this DPA and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, security, and notice arrangements.
Veritio supports compliance evidence workflows. This DPA and the service do not constitute legal advice and do not guarantee that the Controller’s processing is compliant with the GDPR or any other framework. The Controller remains responsible for the lawfulness of its processing.
Data-protection questions and requests under this DPA:hello@getveritio.com.