Last updated: August 6, 2026
This Data Processing Addendum (the "DPA") is incorporated into the Terms of Service between NextAI Forge, LLC, a Delaware limited liability company operating the Veribix service ("Provider"), and the customer who accepts those Terms ("Client"). Capitalized terms not defined here have the meanings given in the Terms of Service.
Provider's registered office in Delaware is 131 Continental Dr, Suite 305, Newark, Delaware 19713, New Castle County. Provider's registered agent at that address is Legalinc Corporate Services Inc.
This DPA applies only to personal data that Provider processes on Client's behalf to provide the service ("Client Personal Data"). For Client Personal Data, Client is the controller and Provider is the processor.
Provider is an independent controller for account administration, billing, fraud prevention, security, legal compliance, and service improvement using aggregated or de-identified data.
The service is intended to measure companies and public business information. Client must not supply sensitive personal data, special-category data, children's data, or data about private individuals.
in the Privacy Policy.
redacting it, joining it into a reporting model, measuring AI assistant answers, and delivering reports, alerts, and exports.
personnel who hold accounts.
redacted log samples from which query parameters outside an allowlist and IP addresses have been removed; account contact details of Client personnel.
Provider processes Client Personal Data only on Client's documented instructions, which consist of this DPA, the Terms of Service, and Client's configuration within the application. Provider will inform Client if, in its opinion, an instruction infringes applicable data protection law.
Provider will:
subject requests, security incidents, data protection impact assessments, and consultations with supervisory authorities;
with this DPA.
tokens, and service account keys.
by Client at any time without Provider's involvement.
logs deleted after extraction.
cannot be altered after the fact.
and audit logging of administrative access.
Provider will notify Client without undue delay, and in any event within seventy-two hours, after becoming aware of a personal data breach affecting Client Personal Data. The notification will describe the nature of the breach, the likely consequences, the measures taken, and a contact point, to the extent known, and will be updated as more becomes known.
Client provides general authorisation for Provider to engage subprocessors. The current list is published at veribix.com/subprocessors.
Provider will give Client at least thirty days' notice before adding or replacing a subprocessor, by updating that page and notifying account holders by email. Client may object on reasonable data protection grounds within that period, in which case the parties will discuss in good faith; if no resolution is reached, Client may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
Provider imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains liable for its subprocessors' performance.
Provider is a "service provider" or "processor" as those terms are defined in applicable U.S. state privacy laws. Provider will not sell or share Client Personal Data, will not retain, use, or disclose it for any purpose other than performing the service, will not combine it with personal information from other sources except as permitted by law, and will not act outside the direct business relationship with Client. Provider certifies that it understands and will comply with these restrictions.
Where Client Personal Data is subject to the GDPR, the UK GDPR, or the Swiss FADP, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor) are incorporated by reference, with Client as data exporter and Provider as data importer, Delaware law and Irish supervisory authority selections as permitted, and the UK International Data Transfer Addendum applying where the UK GDPR governs. The details in section 2 populate Annex I, and section 5 populates Annex II.
Provider will not respond directly to a data subject request concerning Client Personal Data other than to direct the individual to Client, unless legally required. Provider will assist Client in responding, including by providing export and deletion functions that Client can operate without contacting Provider.
Provider will respond to Client's reasonable written information requests about its processing and security. Where Client is required by law to conduct an on-site audit, the parties will agree scope and timing in advance, no more than once in any twelve-month period absent a breach, at Client's expense, subject to confidentiality.
Provider may create aggregated and de-identified data from processing and use it to operate, secure, and improve the service and to publish research. Provider will not attempt to re-identify it and will not publish anything from which a Client or a data subject can be identified.
On termination, Client may export all data in its account, including the measurement evidence trail, using self-serve export. Provider will delete Client Personal Data within ninety days of termination, except where retention is required by law, and will delete or de-identify backups on their ordinary cycle.
Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service.
If this DPA conflicts with the Terms of Service on the processing of Client Personal Data, this DPA controls.
NextAI Forge, LLC
131 Continental Dr, Suite 305
Newark, Delaware 19713
United States