Effective date: August 23, 2026 · Version 1.0

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between VertData, Inc. ("VertData", "Processor") and the customer identified in the applicable order or account ("Customer", "Controller") and governs VertData's processing of Personal Data on Customer's behalf. It reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and other applicable data-protection laws.

How to execute this DPA: If you require a countersigned copy, email privacy@vertdata.com with your legal entity name and address. For self-service acceptance, continued use of VertData's services constitutes agreement to the current version of this DPA.

1. Definitions

2. Roles and scope

The parties acknowledge that, for purposes of Applicable Data Protection Law, Customer is the Controller and VertData is the Processor of Personal Data submitted through the services. VertData will process Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do so by law.

Subject-matter, duration, nature, purpose

Subject-matterProvision of the VertData financial-intelligence platform, including search, enrichment, list management, and AI-scored insights.
DurationThe term of the underlying Customer subscription plus any retention period required by law or set out in §7 below.
Nature and purposeStorage, retrieval, structuring, analysis, and disclosure of Personal Data to Customer's authorized users, as directed by Customer.
Categories of Personal DataBusiness contact details, professional identifiers (bar numbers, licenses), publicly-available property and filing records, Customer-uploaded lists and notes, account/authentication metadata.
Categories of Data SubjectsCustomer's employees and end users; individuals identified in public business, property, and professional records; contacts uploaded by Customer.

3. VertData's obligations

  1. Process Personal Data only on Customer's documented instructions and only for the purposes set out in §2.
  2. Ensure that personnel authorized to process Personal Data are bound by written confidentiality obligations.
  3. Implement appropriate technical and organizational measures (see §6 and the Security page) to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
  4. Assist Customer, taking into account the nature of the processing, in responding to Data-Subject requests under Applicable Data Protection Law (see §5).
  5. Assist Customer in meeting its obligations under Articles 32-36 GDPR (security, breach notification, DPIAs, prior consultation) where applicable.
  6. At Customer's choice, delete or return all Personal Data at the end of the services (see §7).
  7. Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and allow for audits as described in §9.

4. Sub-processors

Customer provides general authorization for VertData to engage sub-processors, subject to the following:

5. Data-subject rights

Taking into account the nature of the processing, VertData will assist Customer through appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making).

If VertData receives a request directly from a Data Subject relating to Customer's processing, VertData will refer that Data Subject to Customer without responding to the request substantively, unless legally required to do so.

6. Security measures

VertData implements the following measures at minimum:

Details are set out on the Security page and may be updated from time to time provided the level of protection is not materially decreased.

7. Retention, return, and deletion

VertData retains Personal Data only for as long as necessary to provide the services and to comply with legal obligations. Standard retention periods:

Upon written request during the retention window, VertData will export Customer's data in a machine-readable format and/or permanently delete it, subject to any legal-hold or regulatory-retention requirements.

8. International transfers

VertData is headquartered in the United States. Where Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country not recognized as providing an adequate level of protection, the parties agree that such transfers are governed by the applicable Standard Contractual Clauses (Module Two: Controller-to-Processor), incorporated by reference into this DPA, with the following selections:

For UK transfers, the UK International Data Transfer Addendum to the EU SCCs applies. For Swiss transfers, references to GDPR are read as references to the Swiss Federal Act on Data Protection, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

9. Audits

Customer may audit VertData's compliance with this DPA once per calendar year on 30 days' prior written notice, during normal business hours, and subject to reasonable confidentiality obligations. In place of an on-site audit, VertData may satisfy this obligation by providing third-party audit reports (e.g., SOC 2), security questionnaires, or documented responses to Customer's reasonable inquiries. Costs are borne by Customer, except that VertData will bear its own personnel costs.

10. Personal-data breach

VertData will notify Customer without undue delay and in any event within 72 hours after becoming aware of a Personal-Data Breach affecting Customer's data. The notification will describe, to the extent known: the nature of the breach, categories and approximate number of Data Subjects and records concerned, likely consequences, and measures taken or proposed to address the breach and mitigate its effects.

11. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service, except where such limitation is prohibited by Applicable Data Protection Law.

12. Order of precedence and modifications

In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Personal Data. VertData may modify this DPA where required by changes in Applicable Data Protection Law; material changes will be notified via the revision log on the Privacy Policy.

13. Contact

Data-protection inquiries and DPA execution requests: privacy@vertdata.com.
Security matters: security@vertdata.com.
Postal address available on request to the above.