Legal

# Data Processing Agreement

This agreement sets out how Veritio processes personal data contained in the evidence records you send to your tenant. For that data you are the controller and Veritio is your processor, as required by Article 28 of the GDPR.

Draft · Last updated 9 August 2026

This Data Processing Agreement (“DPA”) forms part of the[Terms of Service](/legal/terms/) between the customer (“Controller”) and the Veritio entity operating Veritio Cloud (“Processor”). Where it conflicts with the Terms on the processing of personal data, this DPA prevails.

The Processor under this agreement is **Yan Malinovskiy**(sole proprietor), Belchenstraße 2, 79276 Reute, Germany (see the [Imprint](/legal/imprint/)). Creating a Veritio Cloud organization does not by itself incorporate this DPA. It becomes binding only when the parties accept it through an authorized contracting process. Customers may request that process or a countersigned copy at[hello@getveritio.com](mailto:hello@getveritio.com).

## 1 Roles and scope

The Controller determines the purposes and means of processing the personal data contained in its tenant evidence records. The Processor processes that data only on the Controller’s behalf to provide Veritio Cloud. This DPA applies to that processing for as long as the Processor holds such data.

## 2 Subject matter and details of processing

-   **Subject matter** — hosting, storing, verifying, and exporting tamper-evident evidence records on the Controller’s instruction.
-   **Duration** — the term of the account, plus the export and deletion windows in Section 9.
-   **Nature and purpose** — append-only ingestion, hash-chained storage, integrity verification, querying, and export of evidence records.
-   **Types of personal data** — determined by what the Controller chooses to send. Veritio instructs Controllers to send stable identifiers rather than personal data and not to submit secrets or credentials, and applies deterministic redaction to sensitive fields, but the Controller decides the content.
-   **Categories of data subjects** — determined by the Controller (for example, the Controller’s own users, staff, or end customers referenced in its records).

## 3 Processing instructions

The Processor processes personal data only on the Controller’s documented instructions, including those given through the service and this DPA, unless required to act otherwise by law — in which case, where permitted, it will inform the Controller first. The Processor will inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.

## 4 Confidentiality

The Processor ensures that personnel authorized to process personal data are bound by confidentiality obligations and access such data only as needed to provide the service.

## 5 Security measures

Taking account of the state of the art and the risks of processing, the Processor implements appropriate technical and organizational measures, including:

-   **Integrity by design** — evidence records are append-only and hash-chained, so tampering with stored records is detectable, and records are hash-revalidated on read.
-   **Transport and managed storage** — production endpoints use encrypted transport, while storage protections follow the configured infrastructure providers and any separate signed commitments.
-   **Tenant isolation and access controls** — data is scoped per tenant, with authentication, least-privilege access, and security audit logging of sensitive actions.
-   **Data minimization** — product guidance favors stable identifiers and deterministic redaction of configured sensitive fields rather than unnecessary personal data.

## 6 Subprocessors

The Controller authorizes the Processor to engage the subprocessors listed below to provide the infrastructure of the service. Each subprocessor is bound by data-protection obligations no less protective than this DPA.

Subprocessor

Purpose

Location

Cloudflare, Inc.

Application compute, object storage for evidence records, and transactional email delivery

Provider-operated infrastructure; location depends on the configured service and provider terms

Neon, Inc. (on Amazon Web Services)

Managed Postgres databases holding tenant metadata and evidence sequence state

Provider-operated infrastructure; location depends on the configured service and provider terms

Polar Software, Inc.

Payment and subscription processing (planned — activated when billing goes live)

Provider-operated infrastructure

The Processor will give the Controller prior notice of any intended addition or replacement of a subprocessor so the Controller has an opportunity to object on reasonable data-protection grounds.

## 7 International transfers

Where processing a personal data transfer outside the EEA requires it, the parties rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses, which are incorporated by reference for such transfers, together with any supplementary measures required. A specific processing location is committed only where it appears in a separate signed agreement.

## 8 Assistance to the Controller

Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests — including access, rectification, erasure, restriction, and portability — and to meet the Controller’s obligations on security, breach notification, and data-protection impact assessments. The service’s query and export tools are the primary means of this assistance. The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data.

## 9 Return and deletion

On termination, the Controller may export its evidence data as verifiable bundles for the period stated in its account terms or a signed agreement. After that period, the Processor deletes or de-identifies the personal data it processes for the Controller, except to the extent retention is required by law. No fixed public export or deletion window is promised on this page.

## 10 Audits

The Processor makes available information reasonably necessary to demonstrate compliance with this DPA and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, security, and notice arrangements.

## 11 Not legal advice

Veritio supports compliance evidence workflows. This DPA and the service do not constitute legal advice and do not guarantee that the Controller’s processing is compliant with the GDPR or any other framework. The Controller remains responsible for the lawfulness of its processing.

## 12 Contact

Data-protection questions and requests under this DPA:[hello@getveritio.com](mailto:hello@getveritio.com).
