GDPR-compliant DPA for enterprise customers
The complete Data Processing Agreement, including Standard Contractual Clauses (SCCs) for international data transfers, is provided to enterprise customers during validation program onboarding.
Request DPAVericor's Data Processing Agreement (DPA) governs how we process customer data on behalf of enterprise customers. The DPA is designed to comply with GDPR, CCPA, and other global privacy regulations.
This page provides a summary of key DPA provisions. The full DPA is executed during enterprise validation program onboarding and can be requested by contacting our legal team.
Provision of identity verification and fraud detection services as described in the Master Service Agreement.
For the term of the Master Service Agreement, plus 30 days following termination for data export.
Processing of emails, invoices, and identity documents to provide verification signals and fraud risk assessments.
Personal data processed under this DPA may relate to the following categories of data subjects:
Vericor implements technical and organizational measures to ensure a level of security appropriate to the risk, including:
Vericor engages the following categories of sub-processors to provide the Services:
| Sub-Processor | Service | Location |
|---|---|---|
| Cloud Infrastructure Provider | Hosting and infrastructure | United States |
| LLM Provider | AI analysis services | United States |
| Email Service Provider | Transactional emails | United States |
Customers will be notified of any changes to sub-processors with 30 days' notice and may object to new sub-processors.
Vericor will assist customers in responding to data subject requests, including:
Customers remain responsible for responding to data subject requests. Vericor will provide reasonable assistance within 10 business days of receiving a request.
In the event of a personal data breach, Vericor will:
Customer data is stored in US-based infrastructure by default. For customers subject to GDPR, Vericor provides:
Vericor retains customer data according to the following schedule:
Upon termination or customer request, Vericor will delete all customer data within 30 days and provide a certificate of deletion.
Customers have the right to audit Vericor's compliance with this DPA. Vericor will:
For questions about this DPA or to request the full executed agreement:
Email: [email protected]
Subject: Data Processing Agreement Request