Data Processing Addendum
Version 1.0 · Last updated: August 10, 2026 · Forms part of the Terms of Service.
This Data Processing Addendum (“DPA”) applies where Verit Global Labs Inc. (“Verit”, the “Processor”) processes personal data on behalf of the Customer (the “Controller”) in providing DiaCroma for Agents. It is incorporated into the Terms of Service; for personal-data processing it prevails over them.
1 · Scope of processing
| Subject matter | Operation of a governance boundary for the Customer’s AI agents. |
|---|---|
| Duration | The subscription term, plus the retention period in Section 4 of the Privacy Policy. |
| Nature and purpose | Registration of agents; derivation of proposed constraints from Customer-provided missions and documents; signature workflow; per-call governance decisions; signed audit ledger; billing metering. |
| Categories of data | Identification and contact data of Customer personnel (names, emails, sign-in identifiers); any personal data the Customer includes in missions, documents, tool arguments or agent output submitted for governance. |
| Data subjects | Customer personnel and authorized signers; individuals referenced in Customer content. |
2 · Processor obligations
- Process personal data only on the Customer’s documented instructions — the Terms, this DPA, and the Customer’s configuration and use of the Service — unless the law requires otherwise, in which case Verit informs the Customer unless prohibited.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement the technical and organizational measures in the Annex, appropriate to the risk (Art. 32 GDPR).
- Assist the Customer, taking into account the nature of processing, with data-subject requests and with the Customer’s obligations under Articles 32–36 GDPR.
- Notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting Customer data, with the information reasonably needed for the Customer’s own notifications.
- At termination, delete or return (at the Customer’s choice, via API export) all personal data, unless law requires retention.
- Make available information reasonably necessary to demonstrate compliance, and allow audits — first satisfied by documentation and reports, then, where legally required, by an on-notice audit not more than once per year, at the Customer’s cost, without access to other customers’ data or Verit’s proprietary source.
3 · Subprocessors
The Customer authorizes the subprocessors listed in Section 3 of the Privacy Policy. Verit will give at least thirty (30) days’ notice (by updating that list and emailing subscribers) before adding or replacing a subprocessor; if the Customer reasonably objects on data-protection grounds and no resolution is found, the Customer may terminate the affected subscription. Verit imposes data-protection obligations on subprocessors no less protective than this DPA and remains liable for their performance.
4 · International transfers
The Service is hosted in the United States. Where personal data protected by EEA, UK or Swiss law is transferred to Verit, the parties are deemed to have entered into the EU Standard Contractual Clauses (Module 2: controller → processor), as published by the European Commission and as supplemented for the UK by the ICO Addendum, which are incorporated by reference; Annex I is completed by Section 1 above and Annex II by the Annex below.
5 · Liability and order of precedence
Liability under this DPA is subject to the limitations of the Terms of Service. In case of conflict: SCCs → this DPA → the Terms.
Annex · Technical and organizational measures
- Encryption of data in transit (TLS 1.2+).
- API credentials stored only as salted hashes; the plaintext key is shown once and never stored.
- Secrets held in the cloud platform’s managed secret store, referenced — never echoed — in configuration; scheduled rotation supported.
- Signed, append-only event chains for governance decisions and organization changes; integrity is verifiable and declared by the service itself.
- Logical isolation per organization; least-privilege service identities.
- Infrastructure hosted on Microsoft Azure with its physical and network security controls; deployments are reproducible from versioned sources.
- Access to production limited to authorized personnel; administrative actions leave audit trails.
Contact
Verit Global Labs Inc. · diacroma@veritglobal.com