Skip to content

Legal

Data Processing Agreement

This agreement applies where an organisation using Verixad (the customer, acting as controller) stores personal data in the service and Verixad processes it on their instructions (as processor). It forms part of the Terms of Service. Version dated 14 September 2026.

How this document was written. It was drafted with AI assistance against the UK GDPR and published regulatory guidance, and it describes what the product actually does. It has not yet been reviewed by a solicitor. That review is planned before Verixad advertises at scale. If your organisation needs a lawyer-reviewed agreement before signing, tell us and we will say where we have got to.

1. Roles and scope

The customer organisation determines the purposes and means of processing the personal data it records in Verixad (typically details of landlords, tenants, applicants, contractors and team members) and is the controller. Verixad processes that data only to provide the service described in the Terms of Service, on the customer’s documented instructions as expressed through their use of the product, and is the processor.

Verixad processes personal data only on those instructions, including in relation to transfers outside the UK. If Verixad forms the view that an instruction would breach UK data protection law, it will say so to the customer rather than carry it out silently. Where this agreement and the Terms of Service disagree about the handling of personal data, this agreement governs. It applies for as long as Verixad holds the customer’s data.

2. What is processed

Data subjects: the customer’s team members, landlords, tenants, applicants, contractors and other contacts the customer records. Categories: names, contact details, tenancy and property records, compliance documents and their contents, maintenance and screening records, and communications the customer logs or sends. Verixad does not require, and asks customers not to store, payment card numbers, bank credentials or full credit files; the product is designed so identity-check records can be held as the fact that a check happened rather than the underlying documents.

3. Security measures

Every organisation’s records are segregated at the database layer by row-level security, and uploaded files live in private storage reachable only through short-lived signed URLs scoped to the organisation. Data is encrypted in transit and at rest. Access within a customer organisation is governed by that organisation’s own roles and permissions. Administrative actions on Verixad’s side are restricted to account metadata, protected by multi-factor authentication, and recorded on an append-only audit trail.

4. Verixad staff access

Verixad’s operators cannot browse customer records. Support access to an organisation’s data exists only when that organisation’s owner grants it from their own settings. Each grant is scoped, is time-limited to a maximum of 30 days and records the reason, and every grant, past and present, remains visible to the customer. Routine operation uses account metadata only (plan, usage, counts, billing state).

5. Confidentiality

Everyone at Verixad who could reach customer data is bound to keep it confidential, by their contract of engagement and for as long after it ends as the obligation can lawfully run. That duty is separate from the access controls in section 4: the controls are what make access rare, and this is what binds the few people who have it.

6. Sub-processors

Verixad uses the following sub-processors to run the service. The customer gives a general authorisation for these and for any replacement. We will update this page before adding or replacing a sub-processor, and a customer who objects may terminate under the Terms. Each sub-processor is engaged under a written contract placing obligations on it that are equivalent to the ones in this agreement, and Verixad remains responsible to the customer for what its sub-processors do.

ProviderPurposeData involved
SupabaseDatabase, authentication and file storageAll service data, hosted in the EU (Stockholm, eu-north-1)
VercelApplication hosting and deliveryRequests to the application; no service data at rest
StripeSubscription billingBilling contact and payment details; card data is held by Stripe, never by Verixad
ResendTransactional email deliveryRecipient addresses and message content of emails the customer sends or triggers
AnthropicAI document reading, when a customer uses itThe content of documents submitted for extraction; used to provide the feature, not to train models
GoCardlessDirect Debit collection, when a customer connects their own GoCardless accountPayer names and bank details are collected and held by GoCardless directly; Verixad stores the connection, mandate and payment references

7. AI features

Two features use an AI sub-processor: document extraction, and the in-app assistant. Both run only when someone in the customer’s organisation uses them, so each use is an instruction from the customer to process that data for that purpose. Only what the feature needs is sent, not the organisation’s wider records. The provider’s commercial terms do not permit training on the data, and extraction can be switched off for the whole organisation in its settings.

What these features produce is a suggestion, not a finding. Output is shown for a person to accept, edit or reject, is recorded with its provenance, and never alters a record by itself. Verixad makes no automated decision producing legal effects concerning a person, or similarly significantly affecting them, so Article 22 of the UK GDPR is not engaged. Customers should not rely on an AI suggestion without checking it, and remain responsible for any decision they take after reading one.

8. Assistance, breach notification and audits

Verixad assists the customer in meeting their own obligations: the product provides a complete self-serve export of the organisation’s data and per-record access suitable for responding to data-subject requests. If Verixad becomes aware of a personal-data breach affecting a customer’s data, it will notify that customer without undue delay with the information available. Customers may reasonably request written information about the measures in this agreement; audits beyond that are by arrangement, on reasonable notice, no more than once a year unless a regulator or a breach requires otherwise, and subject to confidentiality.

Verixad also assists the customer, so far as it reasonably can and given the information available to it, with the customer’s own duties on security, on notifying a breach to the Information Commissioner or to affected people, on data protection impact assessments, and on any prior consultation with the regulator that follows from one. Where a data subject contacts Verixad directly, Verixad will not answer on the customer’s behalf: it will tell the person who holds their records and pass the request to the customer.

9. Retention, return and deletion

Service data is retained for as long as the organisation’s account exists. Records the customer deletes are recoverable by the customer for 60 days and then permanently removed, files included. Deleting an organisation is a customer-initiated action with a seven-day cooling-off period. When it completes, every record and file belonging to that organisation is permanently removed, and only the bare fact of the deletion (organisation, date, requester) is retained. Customers can export everything themselves at any time before either happens.

At the end of the service the choice is the customer’s: they may take their data back, or have it deleted. Export is available in the product throughout, so a customer who exports and then deletes their organisation has done both. If a customer asks for the data to be returned another way, Verixad will provide it within 30 days of the request. After the deletion completes, Verixad keeps no copy except where UK law requires one, and backups age out on their own retention cycle rather than being edited, which is stated here because a claim of instant erasure from backups would not be true of any system of this kind.

10. Where Verixad acts as a controller

Not everything Verixad does with data sits inside the processor role, and saying so is cleaner than blurring it. Verixad is the controller for the account and billing records of the people who sign up, for the security and audit logs it keeps to protect the service, and for its own correspondence with customers. Those are Verixad’s decisions, made for Verixad’s purposes, and the Privacy Policy sets out the lawful basis for each. Everything the customer puts into the service about properties, tenancies and people remains the customer’s, under this agreement.

11. What the customer is responsible for

As controller, the customer decides why and how the data is processed, and the duties that follow are theirs:

  • Having a lawful basis for everything they record, and giving Verixad lawful instructions.
  • Giving their own privacy notice to the tenants, applicants and contractors whose details they enter. Verixad’s policy explains Verixad’s part; it is not a substitute for the customer’s notice, and a tenant asking about their data will be pointed back to the customer.
  • Registering with the Information Commissioner where the law requires it of them.
  • Answering subject access requests and other rights requests about their own records.
  • Keeping the data accurate, and deciding who in their organisation may see it.
  • Not storing what this agreement asks them to keep out, including payment card numbers, bank credentials and full credit files, and not putting criminal offence or health data into free-text fields where it does not belong.

12. International transfers

Service data is hosted in the European Union. Where a sub-processor processes data outside the UK or EU (for example, email or AI processing), transfers rely on that provider’s standard contractual safeguards.

13. Getting a signed copy

This page is the current DPA and applies automatically to every customer. If your organisation needs a countersigned copy for its own records, contact us and we will provide one.