Data Processing Addendum

Effective date: 2026-07-09

Last updated: 2026-07-25

This Data Processing Addendum (this "DPA") is incorporated into and forms part of the agreement governing the Customer's use of the Service — the Terms of Service, available at verityops.ai/terms, accepted online, whether or not also countersigned via the Company's standard Agreement Cover Page (the "Agreement") — between Singleton Ventures LLC, a Utah limited liability company doing business as VerityOps (the "Company"), and the customer identified in the Agreement (the "Customer"). This DPA takes effect as of the effective date of the Agreement into which it is incorporated.

Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.

1. Definitions

1.1 "Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, which may include, to the extent applicable, the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), the GDPR as incorporated into the law of the United Kingdom ("UK GDPR"), the California Consumer Privacy Act as amended ("CCPA"), and other U.S. state privacy laws.

1.2 "Authorized User" means an individual who is authorized by the Customer to access the Customer's Workspace in the Service under the Customer's account.

1.3 "Customer Content" means all documents, files, questionnaire content, answers, policies, reports, and other materials that the Customer or its Authorized Users upload to, submit to, or generate within the Service.

1.4 "Customer Personal Data" means Personal Data Processed by the Company on behalf of the Customer in connection with providing the Service, as further described in Annex I.

1.5 "Personal Data," "Controller," "Processor," "Data Subject," "Processing" (and its cognates), and "Personal Data Breach" have the meanings given in Applicable Data Protection Law; where Applicable Data Protection Law uses equivalent terms (e.g., "business," "service provider," "consumer" under the CCPA), the corresponding terms apply.

1.6 "Portal Visitor" means an individual — typically a prospect, customer, or auditor of the Customer — who accesses the Customer's trust Portal or Deal Room via the access mechanisms provided by the Service.

1.7 "Service" means the VerityOps software-as-a-service offering made available at app.verityops.ai and associated customer-facing surfaces (including the trust Portal and Deal Room), as described in the Agreement.

1.8 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914, and "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner's Office.

1.9 "Subprocessor" means any third party engaged by the Company to Process Customer Personal Data on the Customer's behalf in connection with the Service.

1.10 "Usage Data" means data about the operation, performance, and use of the Service that is aggregated or de-identified such that it does not identify the Customer, any Authorized User, any Portal Visitor, or any other individual.

1.11 "Workspace" means the Customer's tenant environment within the Service.

2. Scope, Roles, and Duration

2.1 Roles. As between the parties, the Customer is the Controller of Customer Personal Data and the Company is a Processor acting on the Customer's behalf. Where the Customer itself acts as a Processor for its own customers, the Customer is the relevant Processor and the Company acts as the Customer's Subprocessor; in that case the Customer warrants that its instructions to the Company are consistent with the instructions of the relevant Controller.

2.2 Subject matter and duration. The subject matter of Processing is the provision of the Service under the Agreement. The duration of Processing is the term of the Customer's subscription plus the post-termination export and deletion windows described in Section 10.

2.3 Details of Processing. The nature and purpose of Processing, the categories of Data Subjects, and the categories of Personal Data are described in Annex I.

2.4 Customer responsibilities. The Customer is responsible for: (a) the accuracy, quality, and lawfulness of Customer Personal Data and the means by which it was acquired; (b) providing all notices and obtaining all consents or other legal bases required under Applicable Data Protection Law for the Company's Processing described in this DPA, including with respect to Personal Data contained within Customer Content and Personal Data of Portal Visitors; and (c) its configuration of the Service, including Portal access controls and the terms it presents to Portal Visitors.

3. Processing on Documented Instructions

3.1 The Company will Process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by law to which the Company is subject; in that case, the Company will inform the Customer of that legal requirement before Processing unless the law prohibits doing so on important grounds of public interest.

3.2 The Customer's documented instructions consist of: (a) the Agreement and this DPA; (b) the Customer's and its Authorized Users' use and configuration of the Service (including Portal and Deal Room access settings); and (c) any additional written instructions agreed by the parties. The Company will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, provided that the Company has no obligation to monitor the Customer's compliance or provide legal advice. For clarity, the Company may process technical and security telemetry (such as IP addresses, email-domain signals, and rate-limit counters) as an independent controller / "business" solely to detect and prevent security incidents, fraud, and abuse across the Service, as permitted by Applicable Data Protection Law; such processing is not subject to the Customer's instructions under this Section 3.

3.3 No sale; no unrelated use. The Company will not sell or share (as those terms are defined under the CCPA) Customer Personal Data, and will not retain, use, or disclose Customer Personal Data for any purpose other than providing the Service under the Agreement, including any commercial purpose outside the direct business relationship with the Customer. The Company certifies that it understands and will comply with the restrictions in this Section.

4. No AI Training

4.1 The Company does not use Customer Content or Customer Personal Data to train, fine-tune, or otherwise improve any artificial-intelligence or machine-learning model, whether the Company's own or a third party's.

4.2 AI inference used by the Service (for example, drafting suggested questionnaire answers) is performed only by the Subprocessor(s) identified for AI inference in Annex III, under service terms that prohibit retention of inference inputs and outputs and their use for model training.

5. Confidentiality of Processing Personnel

The Company will ensure that all persons it authorizes to Process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and Process Customer Personal Data only as needed to provide the Service.

6. Security

6.1 The Company will implement and maintain the technical and organizational measures described in Annex II, designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The Company may update those measures from time to time, provided that no update materially reduces the overall level of protection during the subscription term.

6.2 The Customer is responsible for securing its own accounts and credentials, including enforcing appropriate authentication settings for its Authorized Users and appropriate access configurations for its Portal.

7. Personal Data Breach Notification

7.1 The Company will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The Company is "aware" of a Personal Data Breach when it has established, with a reasonable degree of certainty, that a Personal Data Breach affecting Customer Personal Data has occurred. Unsuccessful or blocked attempts that do not result in unauthorized access to Customer Personal Data (for example, pings, port scans, denied login attempts, and malware blocked at the perimeter) are not Personal Data Breaches and do not trigger this Section 7.

7.2 The notification will, to the extent then known, describe the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. The Company may provide information in phases as it becomes available. The initial notification under Section 7.1 may be limited to the fact of the Personal Data Breach, the Customer Content or Workspace affected so far as then known, and a point of contact; the remaining details described in this Section 7.2 may follow in phases as the Company's investigation proceeds.

7.3 The Company's notification of, or response to, a Personal Data Breach is not an acknowledgment of fault or liability. The Customer is solely responsible for its own notification obligations to supervisory authorities and Data Subjects, and the Company will provide reasonable cooperation to support them.

8. Assistance to the Customer

8.1 Data Subject requests. Taking into account the nature of the Processing, the Company will assist the Customer by appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling the Customer's obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). The Service's self-serve export, edit, and deletion features are the primary means of that assistance. If the Company receives a request directly from a Data Subject relating to Customer Personal Data, it will (to the extent legally permitted) direct the Data Subject to the Customer and will not respond substantively except on the Customer's instruction or as required by law.

8.2 DPIAs and consultations. Taking into account the nature of the Processing and the information available to it, the Company will provide reasonable assistance with the Customer's data protection impact assessments and prior consultations with supervisory authorities, primarily by making available the documentation described in Section 11.

9. Subprocessors

9.1 General authorization. The Customer generally authorizes the Company to engage Subprocessors to Process Customer Personal Data. The Subprocessors engaged as of the effective date of this DPA are listed in Annex III. The current list is Annex III of this DPA as most recently published with the Agreement (the "Subprocessor List"); once the Company's public trust portal is live, the Subprocessor List will also be mirrored there.

9.2 Notice of changes. The Company will provide at least thirty (30) days' advance notice of the addition of any new Subprocessor by updating the Subprocessor List and providing notice by email or in-Service notification to the Customer's designated contact. The Customer is responsible for subscribing to or monitoring the Subprocessor List where a subscription mechanism is offered.

9.3 Objection. If the Customer objects to a new Subprocessor on reasonable data-protection grounds, the Customer's remedy is to terminate the Agreement by cancelling its subscription in accordance with the Agreement's cancellation terms, and the Company will refund pro-rata any prepaid fees covering the period after the effective date of termination. The Company offers the Service on standard terms and does not deploy per-customer Subprocessor configurations.

9.4 Flow-down and responsibility. The Company will impose on each Subprocessor, by written contract, data-protection obligations that are materially no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the services the Subprocessor provides. The Company remains responsible to the Customer for the performance of each Subprocessor's obligations.

10. Return and Deletion of Customer Personal Data

10.1 Self-serve export. During the subscription term, the Customer may export Customer Content and associated records at any time using the Service's export features.

10.2 Post-termination export window. For thirty (30) days after termination or expiration of the Agreement, the Company will make Customer Content available for export via the Service or another reasonable mechanism.

10.3 Deletion. Following the export window in Section 10.2, the Company will delete Customer Personal Data within thirty (30) days, except to the extent retention is required by applicable law (in which case the Company will isolate and protect the retained data and delete it when the requirement lapses). As a standing documented instruction, the Company will retain Portal Visitor NDA and clickwrap acceptance records (excluding the underlying gated documents) for up to seven (7) years from acceptance as evidence of the applicable agreement, for the benefit of the Customer and the accepting Data Subject, unless the Customer instructs earlier deletion in writing.

10.4 Backups. Customer Personal Data residing in system backups will expire and be overwritten on a rolling basis in accordance with the Company's standard backup retention cycle (no more than thirty-five (35) days) and is not restored to live systems following deletion under Section 10.3 except as necessary for disaster recovery, in which case deletion obligations re-attach to any restored data.

11. Audits and Demonstrating Compliance

11.1 The Company will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, in the following order and manner, which the parties agree satisfies the audit and information rights under Applicable Data Protection Law given the nature, scale, and single-operator structure of the Company's business:

(a) Security questionnaires. The Company will complete the Customer's reasonable written security questionnaires within a reasonable period;

(b) Documentation. The Company will make available its trust Portal documentation describing its security program and, when and if available, its then-current SOC 2 report and other third-party attestations under confidentiality; and

(c) Written audit. No more than once per twelve (12) month period (except following a Personal Data Breach affecting the Customer or where required by a supervisory authority), and at the Customer's cost, the Company will respond in writing to a reasonable written audit request that cannot be satisfied by (a) and (b).

11.2 On-site audits and audits involving direct access to the Company's systems, infrastructure, or other customers' data are excluded, except to the extent that (a) an on-site inspection is required by a supervisory authority with jurisdiction over the Customer, or (b) Applicable Data Protection Law grants the Customer a mandatory inspection right that cannot be satisfied through Section 11.1. Any such inspection will be subject to: reasonable advance written notice; a mutually agreed scope, duration, and (if the Customer uses a third-party auditor) an auditor bound by confidentiality and not a competitor of the Company; no access to other customers' data; no more than one inspection in any twelve (12) month period except following a Personal Data Breach affecting the Customer; conduct during normal business hours; and the Customer bearing its own costs and reimbursing the Company's reasonable costs of participation.

11.3 As of July 25, 2026, the Company is pursuing a SOC 2 Type II examination but does not yet hold a SOC 2 report, and nothing in this DPA is a representation that any certification or attestation is currently held.

12. International Transfers

12.1 The Company provisions all production infrastructure, including database hosting, in United States regions (currently AWS us-east-1), and Customer Personal Data is stored at rest in the United States. Network-transit, DNS, and content-delivery services may traverse global points of presence without persistent storage outside the United States, and Subprocessors may perform limited processing from other jurisdictions in connection with their own support and operations, subject to the flow-down obligations in Section 9.4 and, where applicable, the transfer mechanisms in this Section 12.

12.2 To the extent the Customer's transfer of Customer Personal Data to the Company is subject to the GDPR, the SCCs (Module Two: controller-to-processor) are incorporated into this DPA by reference, with the Customer as data exporter and the Company as data importer; Annexes I and II of this DPA serve as Annexes I and II of the SCCs, and Annex III serves as the list of subprocessors. To the extent such transfer is subject to the UK GDPR, the UK Addendum is incorporated and modifies the SCCs accordingly.

12.3 Where the Customer acts as Processor on behalf of its own customers (Section 2.1), Module Three (processor-to-processor) of the SCCs applies in place of Module Two, mutatis mutandis.

12.4 If the SCCs or UK Addendum conflict with this DPA, the SCCs or UK Addendum control to the extent of the conflict for the transfers they govern.

13. Liability

The liability of each party under or in connection with this DPA (including under the SCCs, to the maximum extent permitted) is subject to the exclusions and limitations of liability set forth in the Agreement, and references in the Agreement to a party's liability mean the aggregate liability of that party under the Agreement and this DPA together.

14. Term; Order of Precedence; General

14.1 Term. This DPA is effective for as long as the Company Processes Customer Personal Data under the Agreement, including the export and deletion windows in Section 10.

14.2 Order of precedence. In the event of conflict: (a) the SCCs and UK Addendum control over this DPA for the transfers they govern; (b) this DPA controls over the Agreement with respect to the Processing of Customer Personal Data; and (c) the Agreement controls in all other respects.

14.3 Amendments for law. The Company may update this DPA from time to time as reasonably required to reflect changes in Applicable Data Protection Law or in the Service, provided that updates do not materially reduce the protections for Customer Personal Data during the subscription term.

14.4 Governing law. This DPA is governed by the law governing the Agreement (the laws of the State of Utah), except where Applicable Data Protection Law or the SCCs require otherwise.

14.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect.


Annex I — Description of Processing

A. List of Parties

Data exporterData importer
NameThe Customer identified in the AgreementSingleton Ventures LLC d/b/a VerityOps
AddressAs set forth in the Agreement or the OrderAs set forth in the Agreement
ContactThe Customer's designated contactlegal@verityops.ai
RoleController (or Processor per Section 2.1)Processor

B. Categories of Data Subjects

  • Authorized Users — the Customer's personnel and other individuals the Customer authorizes to use its Workspace.
  • Portal Visitors — individuals (typically the Customer's prospects, customers, or auditors) who access the Customer's trust Portal or Deal Room.
  • Individuals identified in Customer Content — Customer Content consists primarily of business documents (e.g., SOC 2 reports, security policies, penetration-test summaries, questionnaire responses) that may incidentally contain Personal Data such as names, business contact details, and job titles of the Customer's personnel, auditors, or vendors.

C. Categories of Personal Data

  • Authorized User account data — name, email address, authentication identifiers, role/permission assignments, and activity records within the Workspace.
  • Portal Visitor data — email address; NDA acceptance records, including signature name, timestamp, and a SHA-256 fingerprint of the accepted document; IP address; and access/activity logs (e.g., pages viewed, documents downloaded) generated on the Customer's behalf.
  • Personal Data contained within Customer Content — as described in Section B above; the categories depend on what the Customer uploads.
  • Sensitive data: the Service is not designed or intended for special categories of Personal Data (Article 9 GDPR) or equivalent sensitive data; the Customer agrees not to submit such data except as incidentally contained in Customer Content, and remains responsible for it.

D. Nature and Purpose of Processing

Hosting, storage, transmission, indexing, retrieval, display, AI-assisted drafting, export, and deletion of Customer Content and associated records, in order to provide the Service: security-questionnaire drafting, the evidence Library, the customer-branded trust Portal, the Deal Room, and the Inbox (when available), together with related support, security, and account administration.

E. Duration

The subscription term, plus the thirty (30) day post-termination export window and the subsequent deletion window described in Section 10.

F. Frequency

Continuous, for the duration described in Section E.


Annex II — Technical and Organizational Measures

The Company maintains the following measures. This Annex states the measures actually in place; it does not claim certifications or attestations the Company does not hold.

  1. Encryption in transit. All data in transit is encrypted using TLS 1.2 or higher.
  2. Encryption at rest. All Customer Personal Data at rest is encrypted using AES-256.
  3. Tenant isolation. Workspace data is logically separated per tenant, enforced at the database layer via row-level security.
  4. Key management. Encryption keys are managed through AWS Key Management Service (KMS) with key rotation enabled.
  5. Access control. Access to systems and Customer Personal Data is restricted via role-based access control on the principle of least privilege.
  6. Audit logging. Sensitive surfaces (including Portal access and NDA acceptance events) generate append-only audit/activity logs.
  7. Secrets management. Credentials and API keys are held in a managed secrets system and rotated on defined schedules.
  8. Change control. Infrastructure is defined as code and version-controlled; production infrastructure changes are deployed only from committed state in the version-controlled repository.
  9. Hosting. Production infrastructure is hosted in Amazon Web Services, region us-east-1 (United States). The production databases are operated by Neon, LLC as a managed PostgreSQL service, provisioned by the Company in the AWS us-east-1 region.
  10. Assurance roadmap. The Company is pursuing a SOC 2 Type II examination. No SOC 2 report or other certification is currently held, and this Annex should not be read as claiming one.

Annex III — Subprocessors

This Annex III is the authoritative, current Subprocessor List (see Section 9.1). As of July 25, 2026:

SubprocessorPurposeLocation
Amazon Web Services, Inc.Cloud hosting, storage, and AI inference (Amazon Bedrock)United States
Neon, LLC (an affiliate of Databricks, Inc.)Managed PostgreSQL database hosting (application and communications databases)United States
Vercel Inc.Application hostingUnited States
Clerk Inc.AuthenticationUnited States
Stripe, Inc.Payment processingUnited States
Cloudflare, Inc.DNS, network services, and email routingUnited States / global edge network
Plus Five Five, Inc. (d/b/a Resend)Transactional emailUnited States