Data Processing Agreement
Purpose
This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies when Verified Workflows processes personal data on your behalf. Capitalized terms not defined here have the meanings given in the GDPR.
Roles
You are the Controller. We are the Processor. If you are a Processor for your own customers, you are a Controller for the personal data you submit to us and you are responsible for having a lawful basis to do so.
Subject matter and duration
Subject matter: provision of the human-in-the-loop review Service. Duration: the term of your use of the Service, plus the data retention period in our Privacy Policy.
Nature and purpose of processing
Submitted content is processed solely to provide human review. Reviewers see only the content they need to review. The reviewed output, the reviewer's verdict, and the reviewer's ID are returned to you and stored in your account.
Categories of data
Personal data you submit (which may include special categories of data such as health data if you choose to submit clinical content for medical review). We do not require or expect special category data for the standard Service.
Controller obligations
You warrant that you have a lawful basis under Article 6 (and Article 9, if applicable) of the GDPR to submit the personal data to us for review, and that you have provided your data subjects with the information required by Articles 13 and 14.
Processor obligations
We will: (a) process the personal data only on your documented instructions, including with regard to international transfers; (b) ensure that persons authorized to process the personal data are committed to confidentiality; (c) implement appropriate technical and organizational measures; (d) engage sub-processors only with your prior specific or general authorization and notify you of changes; (e) assist you in fulfilling your obligations to respond to data subject requests; (f) assist you in ensuring compliance with Articles 32–36; (g) at your choice, delete or return the personal data at the end of the provision of the Service; and (h) make available all information necessary to demonstrate compliance.
Sub-processors
See our GDPR notice for the current list of sub-processors. We will notify you of any intended changes via email at least 30 days in advance, giving you the opportunity to object.
Security measures
We implement encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, audit logging, intrusion detection, and regular vulnerability scanning. A summary of our security practices is available on request.
Signatures
By accepting the Terms of Service, you agree to this DPA. To request a counter-signed PDF DPA, email legal@verifiedworkflows.com.