Legal

Data Processing Addendum

Draft v0.1·Last updated 2026-07-31

1. Parties and roles

This Data Processing Addendum forms part of the Terms of Service between Saintrac, the company behind Verela, and the customer organization that uses the Verela platform.
  • Controller: the customerThe customer organization is the controller. The controller determines the purposes and means of processing personal data submitted to the platform, including the verification policies it configures, the retention periods it sets, and the team members it invites.
  • Processor: SaintracSaintrac is the processor. The processor processes personal data on behalf of the controller, on the controller's documented instructions, and only to provide the platform services described in the Terms of Service.

2. Processing purpose

The processor processes personal data on behalf of the controller for the following purposes:
  • VerificationOperating the synthetic identity verification workflows, policy engine, review queue, and audit trail that constitute the platform.
  • AuthenticationAuthenticating team members, managing organization membership, and enforcing role-based access control.
  • BillingManaging subscriptions, recording usage, processing payments, and issuing invoices.
  • CommunicationCommunicating with the organization owner about account status, security notices, and product changes.
The processor does not process personal data for its own purposes and does not use the data for advertising, profiling, or any purpose other than providing the platform to the controller.

3. Processing duration

The processor processes personal data for the duration of the controller's subscription plus the retention period the controller configures. When the retention period expires, the associated evidence is deleted. Metadata history is retained for audit purposes. After subscription cancellation, the controller's data remains accessible and the controller may request export before termination takes effect.

4. Processor obligations

  • Documented instructionsProcess personal data only on the controller's documented instructions and only for the purposes described above.
  • ConfidentialityEnsure that personnel authorized to process personal data are bound by confidentiality obligations.
  • Security measuresImplement technical and organizational measures to ensure a level of security appropriate to the risk, including encrypted evidence storage, hashed API keys, server-resolved organization scope, and role-based access control.
  • RecordsMaintain a record of processing activities and make it available to the controller on request.
  • Breach notificationNotify the controller without undue delay upon becoming aware of a personal data breach affecting the controller's data.
  • Data-subject rightsAssist the controller with data-subject correction requests, access requests, and other rights exercised through the platform.

5. Subprocessors

The processor engages subprocessors to provide the infrastructure and services that operate the platform. Each subprocessor is engaged under a data processing agreement that imposes obligations equivalent to those described in this addendum. The current list of subprocessors, including the processing purpose and region for each, is published on the Subprocessors page. The processor will provide notice of material changes to the subprocessor list through the platform or by email to the organization owner.

6. Data-subject rights

The controller is responsible for responding to data-subject requests. The processor assists the controller by providing the in-session correction flow, the team management tools, and the billing management tools that allow the controller to fulfill correction, access, and deletion requests. The processor does not respond directly to data subjects.

7. Data transfer

The platform is hosted in the United States. Subprocessors may be located in the United States or the European Union. The controller acknowledges that personal data may be transferred to these regions. The processor applies appropriate safeguards for any cross-border transfer, consistent with the security measures described above.

8. Audit

The processor maintains audit history for every verification decision, policy change, team management action, and billing mutation. The controller may request access to its audit history through the platform. The processor does not represent that it has completed any external audit or formal compliance assessment. See the Trust and security page for the security model.

9. Changes to this addendum

This Data Processing Addendum is a draft and may change pending qualified legal review. See the Terms of Service and the Privacy Policy for related terms.