Data Processing Addendum
The processor terms that apply where Verinten processes personal data on your instructions.
- Version
- 1.0
- Effective
- Contact
- Legal team
In counsel review — not yet binding. This document is published for transparency while Verinten prepares for launch. It is not yet the binding version of this policy.
1. When this addendum applies
This addendum applies where Kollekting Apps LLC (“processor”) processes personal data on the documented instructions of your organisation (“controller”) in the course of providing the Verinten service. It forms part of the Terms of Service. Where Verinten determines its own purposes — account administration, security, billing — it acts as a controller and the Privacy Policy governs instead.
2. Subject matter and duration
Processing continues for as long as your workspace exists, and thereafter only for the periods set out in the Data Retention Policy.
3. Nature and purpose
Collecting publicly available material about the businesses you configure, classifying and summarising it, computing deterministic measurements, generating reports, and presenting the results to authorised members of your workspace.
4. Categories of data subject and data
- Your personnel: workspace members — name, email, role, locale, session and audit records.
- Authors of public material: the display name and content published by a reviewer or poster, minimised as described in the Privacy Policy.
Patient data is out of scope and prohibited. Verinten does not process it, and the Acceptable Use Policy forbids submitting it. Special-category data is not sought or used to characterise any individual.
5. Processor obligations
- Process only on documented instructions from the controller.
- Ensure that personnel with access are bound by confidentiality.
- Implement the technical and organisational measures summarised in the Security Overview.
- Engage subprocessors only under equivalent obligations, with prior notice and a right to object — see Subprocessors.
- Assist the controller with data-subject requests, impact assessments, and regulator consultations.
- Notify the controller without undue delay after becoming aware of a personal-data breach, with the information available at the time.
- Delete or return personal data at the end of the service, subject to legal retention obligations.
- Make available the information necessary to demonstrate compliance and allow for audits, which may be satisfied by documentation and attestations where these answer the controller’s question.
6. International transfers
Where personal data is transferred outside the controller’s jurisdiction, the transfer relies on an approved mechanism such as the Standard Contractual Clauses, together with the supplementary measures described in the Security Overview.
7. Controller obligations
The controller warrants that it has a lawful basis for the processing it instructs, that it has the right to add each business and public profile it configures, and that it will not submit patient data or other prohibited content.
Change history
- 1.0
First published version.