Last updated on 30-08-2026 · version 2026-07-01
This data processing agreement applies when VeredAi (the controller) has personal data processed by VeredAi (the processor) while using the platform. This is a template; complete the company details and have it reviewed legally where needed.
The business customer is the controller of the personal data processed via the platform. VeredAi acts solely as processor and processes data only on the controller instructions.
The processing concerns the data the user enters or uploads to obtain legal support, for the term of the agreement and as long as needed for the service.
The processor applies appropriate technical and organisational measures: encryption at rest with AES-256, field encryption of sensitive content, isolation per workspace, access restriction, secure sessions and logging without sensitive content.
The following sub-processors are used for the service:
Personal data is not kept longer than necessary. The retention periods are configurable in the admin area and applied automatically; after the agreement ends, data is deleted or returned.
The processor helps the controller to comply with data subject requests such as access, correction, deletion and portability, and provides export and deletion features for this.
In the event of a personal data breach, the processor informs the controller without undue delay, with the relevant information known to it.
After termination, the personal data is deleted or returned on request, unless a statutory retention obligation requires otherwise.
This document is a customisable template with placeholders for company details. Finalise it and have it legally reviewed before offering it to customers.