Data Processing Agreement
The UK GDPR Article 28 terms on which we process personal data on your behalf. This agreement forms part of our Terms of Business and prevails over it on data-protection matters.
01About this agreement
This Data Processing Agreement(the “DPA”) supplements and forms part of the Terms of Business between Vernius Limited(“Vernius”, “we”, “us”, “our”), a company registered in England & Wales under company number 17114305, and the customer (the “Client”, “you”, “your”). It is incorporated into each Order under which we process personal data on your behalf.
Our registered office is:
1 Albion Place, London W6 0QTIt applies only where, and to the extent that, we process personal data on your behalf as your processor under an Order. Where we determine the purposes and means of processing our own data, for example enquiries submitted through this website, we act as controller and our Privacy Policy applies instead, not this DPA.
Precedence. On any conflict about the processing of personal data, this DPA prevails over the rest of the Terms of Business. On all other matters the Terms of Business govern.
This DPA is in writing, including electronic form, as UK GDPR Article 28(9) permits. No separate signature is needed where an Order that incorporates it is agreed.
Delivery models.Each of our delivery models may involve processing: scoped fixed-price projects, retainer or hosted service, custom handoff builds, and productized services. For custom handoff builds, our role as processor ends when you take over hosting and operation of the software we build, from which point you are the controller and, where relevant, your own or a new processor’s obligations apply.
02Definitions
Capitalised terms used but not defined here take the meaning given in the Terms of Business. The following terms have the meanings set out below.
- UK GDPR: the retained EU General Data Protection Regulation (Regulation (EU) 2016/679) as it forms part of the law of England and Wales, Scotland and Northern Ireland.
- Data Protection Act 2018: the Act of that name, which supplements and tailors the UK GDPR.
- Applicable Data Protection Law: the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 where relevant, any successor or amending law, and applicable guidance and codes issued by the Information Commissioner’s Office (the “ICO”).
- controller, processor, personal data, processing, data subject, personal data breach and special category data: have the meanings given in the UK GDPR and the Data Protection Act 2018.
- sub-processor: any processor we engage to process personal data on your behalf in performing the Services.
- supervisory authority: the ICO, or any other authority with jurisdiction over the processing.
- Annex: one of the annexes to this DPA (Annex 1 to Annex 3), each set out as a numbered section below.
Order, Services, Client Materials, Hosted Services and Fees carry the meanings given in the Terms of Business and are not redefined here.
03Roles and scope of processing
For personal data processed under an Order, you are the controller and we are the processor.
The subject-matter and duration of the processing, its nature and purpose, the types of personal data and the categories of data subjects are as set out in Annex 1 and refined by each Order. Together these satisfy the particulars required by the UK GDPR Article 28(3) chapeau.
Where we determine the purposes and means of any processing, we are a controller for that processing and this DPA does not apply to it.
Your warranties. You warrant that you have a lawful basis for the processing you instruct, that you have provided any required privacy notices and obtained any required consents, and that your instructions comply with Applicable Data Protection Law. You are responsible for the accuracy, quality and legality of the Client Materials and personal data you provide.
Special category and criminal-offence data. We process special category data (UK GDPR Article 9) or criminal-offence data (Article 10) only where an Order expressly provides, and only where you have met the additional conditions those Articles require. You should not instruct the collection of such data through AI features, and you are responsible for what your users submit.
04Processing on documented instructions
We process personal data only on your documented instructions, including as to transfers of personal data outside the UK, unless required to do otherwise by UK or other law to which we are subject. If the law requires us to process otherwise, we will inform you before doing so, unless the law prohibits that on important grounds of public interest.
The Terms of Business, this DPA, each Order and your ordinary use of any Hosted Services are your initial documented instructions. Any further instruction must be given in writing.
We will inform you without undue delay if, in our opinion, an instruction infringes Applicable Data Protection Law, as required by the final paragraph of UK GDPR Article 28(3). We are not obliged to give you legal advice, and telling you is not a substitute for your own compliance.
Instructions outside the scope of the Order, or requiring changes to the Services, may be handled as a change under the Terms of Business and may attract additional Fees.
05Confidentiality of personnel
We ensure that persons authorised to process the personal data are bound by an appropriate duty of confidentiality, whether contractual or statutory.
We limit access to those personnel who need it to deliver the Services, applying the principle of least privilege.
These obligations are in addition to the confidentiality obligations in the Terms of Business.
06Security measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing as well as the risks to data subjects, as required by UK GDPR Article 32.
A summary of the measures we apply is set out in Annex 2. The measures for a given engagement may be supplemented by its Order.
No certification claimed. We make no claim to any certification. We do not hold ISO 27001, SOC 2 or Cyber Essentials, and we hold no independent security audit. We describe our measures honestly and do not warrant more than we do.
For Hosted Services, we configure and maintain the security of the environment we operate. For custom handoff builds, you are responsible for security once you take over operation, and we will share reasonable information to help you secure the solution.
07Sub-processors
You give general written authorisation to our engaging the sub-processors listed at Sub-processors and any additional sub-processors named in the relevant Order. Our core sub-processors are Vercel (hosting and AI gateway), Anthropic (AI model inference), Neon (managed database) and Resend (transactional email), described further in Annex 3.
We impose data-protection obligations on each sub-processor by written contract that are materially equivalent to those in this DPA, in particular the requirements of UK GDPR Article 28. We remain fully liable to you for the acts and omissions of our sub-processors.
Notice and objection. We give you prior notice of any intended addition or replacement of a sub-processor, by updating the Sub-processors page and, where practicable, by email. You may object on reasonable, documented data-protection grounds within 14 days of the notice.
If you object, the parties will work in good faith to find an alternative. If no reasonable alternative is available, either party may terminate the affected Services on written notice. A reasonable objection handled this way is not treated as a breach by us.
08Assistance with data subject rights
Taking account of the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects to exercise their rights, including access, rectification, erasure, restriction, portability and objection.
If we receive a request directly from a data subject in relation to personal data we process for you, we will promptly notify you and will not respond ourselves, except on your documented instruction or as required by law.
The assistance required by UK GDPR Article 28 is preserved. Where assistance goes beyond what is reasonably built into the Services, we may charge for it on a time-and-materials basis so far as permitted.
09Assistance with security, breach, DPIAs and prior consultation
Taking account of the nature of the processing and the information available to us, we assist you in complying with your obligations under UK GDPR Articles 32 to 36: security of processing, notification of personal data breaches, communication of breaches to data subjects, data protection impact assessments, and prior consultation with the ICO.
Breach notification. We notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data we process for you.
So far as the information is available to us, the notification will describe the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information. We provide further information in phases as it becomes known.
Notifying the ICO under Article 33 and, where required, communicating to data subjects under Article 34 remains your responsibility as controller, unless otherwise agreed in writing. Our notification to you is not an admission of fault or liability.
Assistance with a data protection impact assessment or prior consultation that goes beyond the ordinary scope of the Services may be charged for, so far as permitted, without limiting the assistance UK GDPR Article 28 requires.
10Return or deletion of personal data
At the end of the provision of the relevant Services, at your choice, we delete or return all the personal data we process for you and delete existing copies, unless UK or other law requires us to retain it.
Where the law requires retention, we keep the personal data confidential and process it only as the law requires.
Default. If you give us no return or deletion instruction within 30 days after the relevant engagement ends, we may delete the personal data. Backups are overwritten on their ordinary cycle rather than isolated for individual deletion.
For custom handoff builds, the personal data typically transfers to you with the solution, and we retain no copy beyond the handover. Return in a particular format or on particular media may be chargeable.
11Records and audit
We make available to you the information reasonably necessary to demonstrate compliance with UK GDPR Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
Information first. We satisfy audit requests in the first instance by providing written information and records. On-site or deeper audits take place only where reasonably necessary to address a matter that written information cannot resolve.
Frequency. Audits take place no more than once in any 12 month period, except where required by a supervisory authority or following a personal data breach affecting your personal data.
Conditions.You give reasonable prior written notice, of at least 30 days, and audits take place during business hours, subject to confidentiality, without unreasonable disruption to our operations, and not extending to other clients’ data or our confidential commercial information.
Cost. You bear your own and our reasonable costs of an audit you request, except where the audit reveals material non-compliance by us, in which case we bear our own costs of that audit.
12International transfers
Personal data may be transferred to, or accessed from, outside the UK, including the United States, because certain sub-processors are based there. Passing end-user messages to an AI model for inference can involve such a transfer.
Any restricted transfer relies on an appropriate safeguard under Chapter V of the UK GDPR: the UK Extension to the EU-US Data Privacy Framework where the importer is certified under it, or otherwise the UK International Data Transfer Agreement (the “IDTA”) or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures a transfer risk assessment shows to be needed.
Where a sub-processor is certified under the UK Extension to the EU-US Data Privacy Framework, we may rely on that mechanism for transfers to it. Where it is not, or ceases to be, certified, the IDTA or the UK Addendum applies instead. Our current sub-processors are listed on our Sub-processors page.
The relevant transfer clauses are incorporated by reference and prevail on transfer matters to the extent of any conflict with this DPA. We process personal data as to transfers only on your documented instructions.
13Liability
Liability under this DPA is subject to the exclusions and limitations, including the liability cap, set out in the Terms of Business.
Nothing in this DPA excludes or limits liability that cannot be excluded or limited by law, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, and any statutory liability under Applicable Data Protection Law that cannot be limited.
Where both parties are responsible for damage caused to a data subject by processing, each bears the share of any liability that reflects its responsibility, consistent with UK GDPR Article 82.
14Duration and precedence
This DPA takes effect when the first Order involving processing is agreed and continues for as long as we process personal data on your behalf. It survives termination of individual Orders until return or deletion of the personal data is complete.
This DPA prevails over the rest of the Terms of Business on data-protection matters, as set out above.
This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with the Terms of Business.
For anything about this DPA, email contact@vernius.co.uk.
15Annex 1: details of processing
This Annex sets out the general position and examples. The definitive particulars for a given engagement are set by its Order.
- Subject-matter. Processing of personal data as necessary to provide the Services under each Order.
- Duration. The term of the relevant Order, plus any legally required retention. Specifics are set per Order.
- Nature and purpose.Building, hosting, operating, maintaining and supporting software and AI features for you. For example: handling website enquiry data, storing customer and contact records, operating account or user data for an application we build, and passing an end user’s message to an AI model to generate a reply. AI features are not intended to make solely automated decisions producing legal or similarly significant effects on data subjects under UK GDPR Article 22. If an Order changes that, you handle the Article 22 safeguards as controller. API inputs are not used to train the AI models.
- Types of personal data. For example: names, email addresses, phone numbers, account credentials and identifiers, message and enquiry content, and other data the application is configured to collect. Special category data only where an Order expressly provides.
- Categories of data subjects. For example: your customers, prospects and enquirers; your staff and contractors; and end users of your website or application.
16Annex 2: technical and organisational measures
The measures below describe our approach honestly. They may evolve, and no certification is claimed. The applicable measures for an engagement may be supplemented by its Order.
- Access control and least privilege. Access limited to authorised personnel who need it, with individual credentials and multi-factor authentication where the platform supports it.
- Encryption in transit.TLS for data in transit, with reliance on providers’ encryption at rest where offered.
- Segregation. Logical separation of client environments and data.
- Logging and monitoring. Activity and access logging in the platforms used, to support detection and investigation. This includes operational and support logging of AI prompt and response data, to which the return and deletion obligations apply.
- Supplier due diligence. Use of established providers under data-processing terms, namely Vercel, Anthropic, Neon and Resend.
- Secure development practices. Version control, code review, dependency and secret management, and least privilege for service credentials.
- Resilience and recovery.Reliance on providers’ managed backups and availability features, and the ability to restore from provider backups.
17Annex 3: sub-processors
The current, authoritative list is published at Sub-processors. The core sub-processors and their roles are:
- Vercel: hosting and AI gateway.
- Anthropic: AI model inference for the on-site assistant and AI features.
- Neon: managed Postgres database.
- Resend: transactional email.
Project-specific sub-processors are named in the relevant Order. Changes are notified, and may be objected to on reasonable data-protection grounds, under the Sub-processors section above.