Veribix
← Back to home

Data Processing Addendum

Last updated: August 6, 2026

This Data Processing Addendum (the "DPA") is incorporated into the Terms of Service between NextAI Forge, LLC, a Delaware limited liability company operating the Veribix service ("Provider"), and the customer who accepts those Terms ("Client"). Capitalized terms not defined here have the meanings given in the Terms of Service.

Provider's registered office in Delaware is 131 Continental Dr, Suite 305, Newark, Delaware 19713, New Castle County. Provider's registered agent at that address is Legalinc Corporate Services Inc.

1. Scope and roles

This DPA applies only to personal data that Provider processes on Client's behalf to provide the service ("Client Personal Data"). For Client Personal Data, Client is the controller and Provider is the processor.

Provider is an independent controller for account administration, billing, fraud prevention, security, legal compliance, and service improvement using aggregated or de-identified data.

The service is intended to measure companies and public business information. Client must not supply sensitive personal data, special-category data, children's data, or data about private individuals.

2. Processing details

  • Subject matter: provision of the Veribix measurement service.
  • Duration: the term of Client's account, plus the retention periods stated

in the Privacy Policy.

  • Nature and purpose: ingesting aggregated analytics and log data,

redacting it, joining it into a reporting model, measuring AI assistant answers, and delivering reports, alerts, and exports.

  • Categories of data subjects: Client's website visitors, and Client's own

personnel who hold accounts.

  • Categories of personal data: aggregated website and analytics metrics;

redacted log samples from which query parameters outside an allowlist and IP addresses have been removed; account contact details of Client personnel.

  • Special categories: none. Client must not provide any.

3. Client instructions

Provider processes Client Personal Data only on Client's documented instructions, which consist of this DPA, the Terms of Service, and Client's configuration within the application. Provider will inform Client if, in its opinion, an instruction infringes applicable data protection law.

4. Provider obligations

Provider will:

  • process Client Personal Data only for the purposes in section 2;
  • ensure personnel with access are bound by confidentiality;
  • implement the security measures in section 5;
  • assist Client, taking into account the nature of processing, with data

subject requests, security incidents, data protection impact assessments, and consultations with supervisory authorities;

  • make available the information reasonably necessary to demonstrate compliance

with this DPA.

5. Security measures

  • Encryption of data in transit, and encryption at rest for credentials,

tokens, and service account keys.

  • Read-only access to every Client data source, granted by Client and revocable

by Client at any time without Provider's involvement.

  • Redaction of personal data at the point of log ingestion, with raw uploaded

logs deleted after extraction.

  • Append-only, integrity-verified storage for measurement evidence, so records

cannot be altered after the fact.

  • Least-privilege access control, logical separation of Client environments,

and audit logging of administrative access.

  • Secrets are never written to application logs.

6. Personal data breaches

Provider will notify Client without undue delay, and in any event within seventy-two hours, after becoming aware of a personal data breach affecting Client Personal Data. The notification will describe the nature of the breach, the likely consequences, the measures taken, and a contact point, to the extent known, and will be updated as more becomes known.

7. Subprocessors

Client provides general authorisation for Provider to engage subprocessors. The current list is published at veribix.com/subprocessors.

Provider will give Client at least thirty days' notice before adding or replacing a subprocessor, by updating that page and notifying account holders by email. Client may object on reasonable data protection grounds within that period, in which case the parties will discuss in good faith; if no resolution is reached, Client may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.

Provider imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains liable for its subprocessors' performance.

8. U.S. state privacy law terms

Provider is a "service provider" or "processor" as those terms are defined in applicable U.S. state privacy laws. Provider will not sell or share Client Personal Data, will not retain, use, or disclose it for any purpose other than performing the service, will not combine it with personal information from other sources except as permitted by law, and will not act outside the direct business relationship with Client. Provider certifies that it understands and will comply with these restrictions.

9. European, UK, and Swiss terms

Where Client Personal Data is subject to the GDPR, the UK GDPR, or the Swiss FADP, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor) are incorporated by reference, with Client as data exporter and Provider as data importer, Delaware law and Irish supervisory authority selections as permitted, and the UK International Data Transfer Addendum applying where the UK GDPR governs. The details in section 2 populate Annex I, and section 5 populates Annex II.

10. Data subject requests

Provider will not respond directly to a data subject request concerning Client Personal Data other than to direct the individual to Client, unless legally required. Provider will assist Client in responding, including by providing export and deletion functions that Client can operate without contacting Provider.

11. Audits

Provider will respond to Client's reasonable written information requests about its processing and security. Where Client is required by law to conduct an on-site audit, the parties will agree scope and timing in advance, no more than once in any twelve-month period absent a breach, at Client's expense, subject to confidentiality.

12. De-identified and aggregated data

Provider may create aggregated and de-identified data from processing and use it to operate, secure, and improve the service and to publish research. Provider will not attempt to re-identify it and will not publish anything from which a Client or a data subject can be identified.

13. Return and deletion

On termination, Client may export all data in its account, including the measurement evidence trail, using self-serve export. Provider will delete Client Personal Data within ninety days of termination, except where retention is required by law, and will delete or de-identify backups on their ordinary cycle.

14. Liability

Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service.

15. Conflict

If this DPA conflicts with the Terms of Service on the processing of Client Personal Data, this DPA controls.

16. Contact

privacy@veribix.com

NextAI Forge, LLC
131 Continental Dr, Suite 305
Newark, Delaware 19713
United States