VERTAL Data Processing Agreement (DPA)
Effective Date: June 21, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between VERTAL ("VERTAL", "Controller", "Processor", "we", "our", or "us") and the customer, client, organization, or individual using VERTAL Services ("Customer").
This DPA governs the processing of Personal Data in connection with the Services provided through https://vertal.app.
1. Purpose
The purpose of this DPA is to establish the terms under which Personal Data is processed by VERTAL on behalf of the Customer and to ensure compliance with applicable data protection laws, including:
- General Data Protection Regulation (GDPR) (EU) 2016/679;
- UK GDPR;
- Brazilian General Data Protection Law (LGPD);
- California Consumer Privacy Act (CCPA), where applicable;
- Other applicable privacy and data protection laws.
2. Definitions
Personal Data
Any information relating to an identified or identifiable natural person.
Processing
Any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, deletion, or analysis.
Controller
The entity determining the purposes and means of processing Personal Data.
Processor
The entity processing Personal Data on behalf of the Controller.
Data Subject
An individual whose Personal Data is processed.
Subprocessor
A third party engaged by VERTAL to assist in processing Personal Data.
3. Scope of Processing
VERTAL may process Personal Data solely for the purpose of:
- Providing Services;
- Operating platform functionality;
- Customer support;
- Security and fraud prevention;
- Compliance obligations;
- Infrastructure management;
- Artificial Intelligence services requested by the Customer.
VERTAL shall process Personal Data only according to documented instructions from the Customer unless otherwise required by law.
4. Customer Responsibilities
The Customer represents and warrants that:
- It has all necessary rights and legal bases to provide Personal Data to VERTAL;
- It complies with applicable privacy laws;
- It has provided appropriate notices to Data Subjects;
- It has obtained any required consents.
The Customer remains responsible for determining the lawful basis for processing Personal Data.
5. VERTAL Responsibilities
VERTAL agrees to:
- Process Personal Data lawfully;
- Maintain confidentiality obligations;
- Implement appropriate security measures;
- Assist the Customer in responding to Data Subject requests where applicable;
- Notify the Customer of Personal Data Breaches when legally required;
- Comply with applicable privacy regulations.
6. Security Measures
VERTAL maintains administrative, technical, and organizational safeguards designed to protect Personal Data.
Such measures include:
- Encryption in transit and at rest;
- Access controls;
- Multi-factor authentication;
- Security monitoring;
- Vulnerability management;
- Incident response procedures;
- Secure cloud infrastructure;
- Employee confidentiality obligations.
Cybersecurity operations throughout the VERTAL ecosystem are supported by Cyber Segurit Infinit.
7. Subprocessors
The Customer authorizes VERTAL to engage Subprocessors as necessary to provide Services.
Examples may include:
- Cloud infrastructure providers;
- Payment processors;
- Authentication providers;
- Customer support platforms;
- Analytics services;
- Security providers.
VERTAL shall ensure that Subprocessors are subject to appropriate contractual data protection obligations.
8. International Data Transfers
Personal Data may be transferred to and processed in countries outside the Customer's jurisdiction.
Where required by law, VERTAL shall implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs);
- Adequacy decisions;
- Contractual protections;
- Other legally recognized transfer mechanisms.
9. Data Subject Rights
To the extent required by applicable law, VERTAL shall provide reasonable assistance to the Customer in responding to requests concerning:
- Access;
- Correction;
- Deletion;
- Restriction;
- Portability;
- Objection to processing;
- Withdrawal of consent.
The Customer remains responsible for responding to Data Subject requests.
10. Personal Data Breaches
In the event of a confirmed Personal Data Breach affecting Customer data, VERTAL shall:
- Investigate the incident;
- Take reasonable measures to mitigate harm;
- Notify the Customer without undue delay when legally required;
- Provide relevant information regarding the incident.
11. Confidentiality
VERTAL shall ensure that personnel with access to Personal Data:
- Are bound by confidentiality obligations;
- Receive appropriate training;
- Access data only as necessary for their duties.
12. Data Retention and Deletion
Upon termination of the Services, VERTAL shall:
- Delete Customer Personal Data; or
- Return Customer Personal Data;
unless retention is required by law, regulation, legal process, or legitimate security requirements.
Backup copies may remain for limited periods consistent with disaster recovery and compliance obligations.
13. Audit Rights
Where required by applicable law, and subject to reasonable notice, the Customer may request information demonstrating VERTAL's compliance with this DPA.
Any audit shall:
- Be conducted during normal business hours;
- Avoid disruption of Services;
- Respect confidentiality obligations;
- Be limited to information relevant to compliance verification.
14. Liability
Liability under this DPA shall be governed by the liability provisions contained in the applicable Terms of Service unless otherwise required by law.
15. Term
This DPA remains in effect for as long as VERTAL processes Personal Data on behalf of the Customer.
Termination of the Services automatically terminates this DPA, except for provisions that survive by their nature.
16. Governing Law
This DPA shall be governed by the laws specified in the applicable VERTAL Terms of Service, unless otherwise required by mandatory data protection laws.
17. Contact Information
For privacy, security, or data protection inquiries, contact:
VERTAL Privacy & Data Protection Office
- Website: https://vertal.app
- Support: support@vertal.app
- DPO: dpo@vertal.app
- Legal Department: legal@vertal.app
Annex I — Description of Processing
Categories of Data Subjects
- Customers
- End Users
- Business Users
- Partners
- Website Visitors
- Authorized Representatives
Categories of Personal Data
- Identification information
- Contact information
- Account information
- Device and usage information
- Transaction records
- Authentication information
- Support communications
Purpose of Processing
- Service delivery
- Account management
- Security and compliance
- Customer support
- Analytics and performance improvements
- AI-powered platform functionality
Duration of Processing
For the duration of the Customer relationship and any legally required retention period.
© 2026 VERTAL. All Rights Reserved.
VERTAL — Trusted Infrastructure for Artificial Intelligence, Security, Blockchain, and Enterprise Innovation.
