Version 1.0 · B2B
Data Processing Agreement
Last updated July 27, 2026
This DPA explains how Verbrio protects personal data it processes for business customers. It forms part of the Verbrio Terms and any applicable order.
1. Agreement and parties
This Data Processing Agreement (DPA) is between Verbrio B.V., registered at Hoedemakerplein 2, 7511 JP Enschede, the Netherlands, with the Dutch Chamber of Commerce under number 96023325 and VAT ID NL867435276B01 (Verbrio), and the business that accepts the Verbrio Terms or enters into an order with Verbrio (Customer). It applies when Verbrio processes personal data on Customer's behalf.
The DPA is incorporated into the agreement between the parties and becomes binding when an authorized representative accepts that agreement. GDPR terms have their GDPR meanings. Customer Personal Data means personal data that Customer submits to, connects with, or asks Verbrio to process through the service.
2. Our roles
Customer is the controller and Verbrio is the processor of Customer Personal Data. Verbrio remains an independent controller for account, billing, support, security, and similar business data it uses for its own lawful purposes, as described in the Privacy Policy.
If Customer processes data for another controller, Verbrio acts as Customer's subprocessor. Customer confirms that it has authority to appoint Verbrio and will pass through all instructions and obligations that apply to Verbrio.
3. Processing details
- Subject matter
Providing, operating, securing, and supporting Verbrio's B2B software service and the integrations Customer chooses to enable.
- Duration
For the service term, the 30-day post-termination export period, and afterwards only for deletion from encrypted backups or retention required by law.
- Nature and purpose
Hosting, storing, retrieving, organizing, OCR, extracting, classifying, normalizing, transmitting, integrating, supporting, securing, exporting, and deleting data so Customer can manage documents, contacts, orders, invoices, and related workflows.
- Types of personal data
Business contact and account details; correspondence and email metadata; documents, attachments, orders, invoices, and payment references; integration identifiers; activity, audit, and technical data. Special-category and criminal-offence data are not intended unless the parties agree otherwise in writing.
- Categories of data subjects
Customer's staff and contractors, customers and prospective customers, suppliers, marketplace or integration contacts, and other people whose data Customer places in the service.
4. Instructions
Verbrio processes Customer Personal Data only on Customer's documented instructions. The agreement, Customer's use and configuration of the service, enabled integrations, and written support requests are documented instructions. Verbrio may process data when EU or Member State law requires it, but will tell Customer beforehand unless the law prohibits notice.
Verbrio will promptly tell Customer if an instruction appears to breach data protection law and may pause the affected processing while the parties resolve it. Instructions outside the service's normal scope require written agreement and may involve reasonable costs.
Customer responsibilities
Customer is responsible for the lawfulness, fairness, and accuracy of Customer Personal Data and instructions, including a valid legal basis, required notices, handling data-subject requests, and obtaining any permissions needed for integrations. Customer will use appropriate settings and limit data to what is necessary.
Customer will not intentionally submit special-category or criminal-offence data unless the parties have agreed in writing on the need and additional safeguards.
5. Confidentiality and security
Verbrio limits access to people who need Customer Personal Data to perform their work. They are bound by confidentiality and receive appropriate security and privacy guidance.
Verbrio maintains technical and organizational measures appropriate to the risk, state of the art, implementation cost, and nature of the processing. These include:
identity and access controls, least-privilege access, and access reviews;
encryption in transit and at rest, with protected credentials, keys, and secrets;
logging, monitoring, vulnerability management, and incident-response procedures; and
resilience, encrypted backups, recovery procedures, supplier review, and periodic testing.
6. Assistance and incidents
Taking account of the processing, Verbrio will reasonably help Customer respond to requests to exercise data-subject rights. Verbrio will send a request it receives about Customer Personal Data to Customer and will not answer it itself unless Customer instructs it or the law requires it.
Verbrio will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, Verbrio will describe the breach, affected data and people, likely consequences, and mitigation, and will reasonably cooperate with Customer's response. Notice is not an admission of fault.
Verbrio will also provide reasonable assistance with Customer's duties under GDPR Articles 32 to 36, including security assessments, breach notifications, data protection impact assessments, and prior consultation. Work beyond the service's standard capabilities may be charged at reasonable rates unless caused by Verbrio's breach of this DPA.
7. Subprocessors
Customer gives Verbrio general written authorization to use subprocessors. Verbrio selects providers that offer appropriate data-protection guarantees, binds them to obligations no less protective than the relevant parts of this DPA, and remains responsible for their performance as required by law.
The current providers, their roles, locations, and status are listed in the subprocessor register. Verbrio will email the Customer account contact at least 30 days before adding or replacing a subprocessor. If urgent legal or security needs make that impracticable, Verbrio will give as much notice as reasonably possible.
Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith on a practical solution. If none is available, Customer may terminate the affected service before the change takes effect, without a termination charge and subject to payment for service already provided.
8. International transfers
Verbrio transfers Customer Personal Data outside the European Economic Area only on Customer's documented instructions, including this DPA and Customer's enabled integrations, and only with a lawful transfer mechanism. The subprocessor register identifies relevant processing locations.
Where there is no adequacy decision, Verbrio will use safeguards such as the European Commission's Standard Contractual Clauses and supplementary measures where needed, and will reasonably assist with transfer assessments. Applicable Standard Contractual Clauses prevail over conflicting terms of this DPA.
9. Information and audits
Verbrio will provide information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, questionnaires, certifications, or independent reports. Customer will keep non-public information confidential and may consider available third-party assurance before requesting an audit.
If that information is insufficient, Customer may conduct one audit per year at its expense through an independent, non-competing auditor, with at least 30 days' notice, during business hours, and without accessing other customers' data or creating security risk. These limits do not apply where a regulator requires an audit, after a relevant breach, or where Customer has reasonable evidence of material non-compliance.
10. Return, export, and deletion
At the end of the service, Customer may choose return through the available export tools or deletion of Customer Personal Data. Unless Customer asks for earlier deletion, Verbrio keeps active workspace data available for export for 30 days after termination. Customer is responsible for completing its export during that period. Verbrio then deletes active workspace data.
Encrypted backup copies remain protected, expire through Verbrio's backup-retention lifecycle, and are not restored except for disaster recovery; if restored, the deletion process is reapplied. Verbrio may retain only records required by EU or Member State law, keeping them isolated, access-restricted, and unused for other purposes.
11. Term, precedence, and liability
This DPA starts when it is incorporated into the parties' agreement and continues until Verbrio has deleted all Customer Personal Data as described above. Material changes will be notified under the amendment and notice rules in the Terms.
For data-processing matters, applicable Standard Contractual Clauses prevail first, then this DPA, then the Terms or order. The liability limits and remedies in the Terms apply to this DPA except where mandatory law requires otherwise. The governing-law and court provisions in the Terms also apply.
12. Contact
Send data-protection instructions, incident notices, subprocessor objections, and DPA questions to:
Verbrio B.V.KvK 96023325
Hoedemakerplein 2
7511 JP Enschede, The Netherlands
legal@verbrio.com
