Effective date: August 23, 2026 · Version 1.0
This Data Processing Agreement ("DPA") forms part of the Terms of Service between VertData, Inc. ("VertData", "Processor") and the customer identified in the applicable order or account ("Customer", "Controller") and governs VertData's processing of Personal Data on Customer's behalf. It reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and other applicable data-protection laws.
How to execute this DPA: If you require a countersigned copy, email privacy@vertdata.com with your legal entity name and address. For self-service acceptance, continued use of VertData's services constitutes agreement to the current version of this DPA.
The parties acknowledge that, for purposes of Applicable Data Protection Law, Customer is the Controller and VertData is the Processor of Personal Data submitted through the services. VertData will process Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do so by law.
| Subject-matter | Provision of the VertData financial-intelligence platform, including search, enrichment, list management, and AI-scored insights. |
|---|---|
| Duration | The term of the underlying Customer subscription plus any retention period required by law or set out in §7 below. |
| Nature and purpose | Storage, retrieval, structuring, analysis, and disclosure of Personal Data to Customer's authorized users, as directed by Customer. |
| Categories of Personal Data | Business contact details, professional identifiers (bar numbers, licenses), publicly-available property and filing records, Customer-uploaded lists and notes, account/authentication metadata. |
| Categories of Data Subjects | Customer's employees and end users; individuals identified in public business, property, and professional records; contacts uploaded by Customer. |
Customer provides general authorization for VertData to engage sub-processors, subject to the following:
Taking into account the nature of the processing, VertData will assist Customer through appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making).
If VertData receives a request directly from a Data Subject relating to Customer's processing, VertData will refer that Data Subject to Customer without responding to the request substantively, unless legally required to do so.
VertData implements the following measures at minimum:
Details are set out on the Security page and may be updated from time to time provided the level of protection is not materially decreased.
VertData retains Personal Data only for as long as necessary to provide the services and to comply with legal obligations. Standard retention periods:
Upon written request during the retention window, VertData will export Customer's data in a machine-readable format and/or permanently delete it, subject to any legal-hold or regulatory-retention requirements.
VertData is headquartered in the United States. Where Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country not recognized as providing an adequate level of protection, the parties agree that such transfers are governed by the applicable Standard Contractual Clauses (Module Two: Controller-to-Processor), incorporated by reference into this DPA, with the following selections:
For UK transfers, the UK International Data Transfer Addendum to the EU SCCs applies. For Swiss transfers, references to GDPR are read as references to the Swiss Federal Act on Data Protection, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
Customer may audit VertData's compliance with this DPA once per calendar year on 30 days' prior written notice, during normal business hours, and subject to reasonable confidentiality obligations. In place of an on-site audit, VertData may satisfy this obligation by providing third-party audit reports (e.g., SOC 2), security questionnaires, or documented responses to Customer's reasonable inquiries. Costs are borne by Customer, except that VertData will bear its own personnel costs.
VertData will notify Customer without undue delay and in any event within 72 hours after becoming aware of a Personal-Data Breach affecting Customer's data. The notification will describe, to the extent known: the nature of the breach, categories and approximate number of Data Subjects and records concerned, likely consequences, and measures taken or proposed to address the breach and mitigate its effects.
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service, except where such limitation is prohibited by Applicable Data Protection Law.
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Personal Data. VertData may modify this DPA where required by changes in Applicable Data Protection Law; material changes will be notified via the revision log on the Privacy Policy.
Data-protection inquiries and DPA execution requests: privacy@vertdata.com.
Security matters: security@vertdata.com.
Postal address available on request to the above.