VERTAL Data Processing Agreement (DPA)

Effective Date: June 21, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between VERTAL ("VERTAL", "Controller", "Processor", "we", "our", or "us") and the customer, client, organization, or individual using VERTAL Services ("Customer").

This DPA governs the processing of Personal Data in connection with the Services provided through https://vertal.app.

1. Purpose

The purpose of this DPA is to establish the terms under which Personal Data is processed by VERTAL on behalf of the Customer and to ensure compliance with applicable data protection laws, including:

  • General Data Protection Regulation (GDPR) (EU) 2016/679;
  • UK GDPR;
  • Brazilian General Data Protection Law (LGPD);
  • California Consumer Privacy Act (CCPA), where applicable;
  • Other applicable privacy and data protection laws.

2. Definitions

Personal Data

Any information relating to an identified or identifiable natural person.

Processing

Any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, deletion, or analysis.

Controller

The entity determining the purposes and means of processing Personal Data.

Processor

The entity processing Personal Data on behalf of the Controller.

Data Subject

An individual whose Personal Data is processed.

Subprocessor

A third party engaged by VERTAL to assist in processing Personal Data.

3. Scope of Processing

VERTAL may process Personal Data solely for the purpose of:

  • Providing Services;
  • Operating platform functionality;
  • Customer support;
  • Security and fraud prevention;
  • Compliance obligations;
  • Infrastructure management;
  • Artificial Intelligence services requested by the Customer.

VERTAL shall process Personal Data only according to documented instructions from the Customer unless otherwise required by law.

4. Customer Responsibilities

The Customer represents and warrants that:

  • It has all necessary rights and legal bases to provide Personal Data to VERTAL;
  • It complies with applicable privacy laws;
  • It has provided appropriate notices to Data Subjects;
  • It has obtained any required consents.

The Customer remains responsible for determining the lawful basis for processing Personal Data.

5. VERTAL Responsibilities

VERTAL agrees to:

  • Process Personal Data lawfully;
  • Maintain confidentiality obligations;
  • Implement appropriate security measures;
  • Assist the Customer in responding to Data Subject requests where applicable;
  • Notify the Customer of Personal Data Breaches when legally required;
  • Comply with applicable privacy regulations.

6. Security Measures

VERTAL maintains administrative, technical, and organizational safeguards designed to protect Personal Data.

Such measures include:

  • Encryption in transit and at rest;
  • Access controls;
  • Multi-factor authentication;
  • Security monitoring;
  • Vulnerability management;
  • Incident response procedures;
  • Secure cloud infrastructure;
  • Employee confidentiality obligations.

Cybersecurity operations throughout the VERTAL ecosystem are supported by Cyber Segurit Infinit.

7. Subprocessors

The Customer authorizes VERTAL to engage Subprocessors as necessary to provide Services.

Examples may include:

  • Cloud infrastructure providers;
  • Payment processors;
  • Authentication providers;
  • Customer support platforms;
  • Analytics services;
  • Security providers.

VERTAL shall ensure that Subprocessors are subject to appropriate contractual data protection obligations.

8. International Data Transfers

Personal Data may be transferred to and processed in countries outside the Customer's jurisdiction.

Where required by law, VERTAL shall implement appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs);
  • Adequacy decisions;
  • Contractual protections;
  • Other legally recognized transfer mechanisms.

9. Data Subject Rights

To the extent required by applicable law, VERTAL shall provide reasonable assistance to the Customer in responding to requests concerning:

  • Access;
  • Correction;
  • Deletion;
  • Restriction;
  • Portability;
  • Objection to processing;
  • Withdrawal of consent.

The Customer remains responsible for responding to Data Subject requests.

10. Personal Data Breaches

In the event of a confirmed Personal Data Breach affecting Customer data, VERTAL shall:

  • Investigate the incident;
  • Take reasonable measures to mitigate harm;
  • Notify the Customer without undue delay when legally required;
  • Provide relevant information regarding the incident.

11. Confidentiality

VERTAL shall ensure that personnel with access to Personal Data:

  • Are bound by confidentiality obligations;
  • Receive appropriate training;
  • Access data only as necessary for their duties.

12. Data Retention and Deletion

Upon termination of the Services, VERTAL shall:

  • Delete Customer Personal Data; or
  • Return Customer Personal Data;

unless retention is required by law, regulation, legal process, or legitimate security requirements.

Backup copies may remain for limited periods consistent with disaster recovery and compliance obligations.

13. Audit Rights

Where required by applicable law, and subject to reasonable notice, the Customer may request information demonstrating VERTAL's compliance with this DPA.

Any audit shall:

  • Be conducted during normal business hours;
  • Avoid disruption of Services;
  • Respect confidentiality obligations;
  • Be limited to information relevant to compliance verification.

14. Liability

Liability under this DPA shall be governed by the liability provisions contained in the applicable Terms of Service unless otherwise required by law.

15. Term

This DPA remains in effect for as long as VERTAL processes Personal Data on behalf of the Customer.

Termination of the Services automatically terminates this DPA, except for provisions that survive by their nature.

16. Governing Law

This DPA shall be governed by the laws specified in the applicable VERTAL Terms of Service, unless otherwise required by mandatory data protection laws.

17. Contact Information

For privacy, security, or data protection inquiries, contact:

VERTAL Privacy & Data Protection Office

Annex I — Description of Processing

Categories of Data Subjects

  • Customers
  • End Users
  • Business Users
  • Partners
  • Website Visitors
  • Authorized Representatives

Categories of Personal Data

  • Identification information
  • Contact information
  • Account information
  • Device and usage information
  • Transaction records
  • Authentication information
  • Support communications

Purpose of Processing

  • Service delivery
  • Account management
  • Security and compliance
  • Customer support
  • Analytics and performance improvements
  • AI-powered platform functionality

Duration of Processing

For the duration of the Customer relationship and any legally required retention period.

© 2026 VERTAL. All Rights Reserved.

VERTAL — Trusted Infrastructure for Artificial Intelligence, Security, Blockchain, and Enterprise Innovation.