DATA PROCESSING

Public Data Processing Overview.

This public overview explains how Verbum approaches customer-data processing for governed AI messaging. It is not a signed DPA, does not publish countersignature terms and should be used to prepare qualified legal, privacy or procurement review.

Document metadata

Document: Data Processing Overview

Effective date: June 16, 2026

Last updated: June 18, 2026

Version: 1.0.1

Document owner/category: Legal / Privacy

Legal/privacy contact: [email protected]

PROCUREMENT REVIEW MAP

Review data-processing posture in one pass

Use this hub to identify what is public today, what requires qualified legal review and which materials support DPA, privacy and security assessment.

  • Overview

    Public overview, current DPA status and available review resources.

    Review section
  • Data Categories

    Customer data types used across workspace, messaging, AI and audit workflows.

    Review section
  • Processing Activities

    Compact matrix covering activity, data, purpose, retention reference and safeguards.

    Review section
  • Security Safeguards

    Public controls and qualified evidence paths for security review.

    Review section
  • International Transfers

    Transfer context and safeguards become commitments only in an approved contract or qualified legal review.

    Review section
  • Review Process

    How qualified procurement, privacy and legal teams request DPA and security review.

    Review section

Overview

This page is a public Data Processing Overview for general legal, procurement and privacy review. It summarizes how Verbum approaches customer data processing for its governed messaging platform and helps teams prepare DPA review questions.

This public overview does not replace the signed DPA.

It is not a customer compliance determination, does not guarantee that privacy or security risks are eliminated and does not create a hosting-region commitment.

Formal DPA status

A formal DPA is reviewed through the legal process when available for the applicable contracting scope.

This public overview does not publish a DPA version, effective date, signatory entity, transfer mechanism or countersignature workflow.

  • Available now: this Public Data Processing Overview, Privacy Policy, Security Overview, Trust Center and Subprocessors page.
  • Applicable contracting scope, DPA terms and transfer commitments are confirmed only through the legal process.
  • Confidentiality: non-public terms, evidence or deployment-specific details may require NDA or an appropriate confidentiality process.
  • Request path: use Request DPA review and include your company, use case, contracting context and procurement deadline.

Data Categories

Customer data processed through the platform may include the categories below, depending on enabled features, connected channels and customer instructions.

Customers retain ownership of their data under the applicable legal and contractual framework. Verbum processes Customer Data only to operate and provide the Service, to fulfil legal obligations, and, where applicable, to improve reliability and security.

  • Account, workspace, company and user profile data.
  • Conversation content, message history, contact identifiers and channel metadata.
  • AI prompts or inputs, generated drafts, summaries and configured workflow context.
  • Approval decisions, reviewer identity, timestamps, rules and audit events.
  • Billing metadata, support messages, procurement communications and privacy request metadata.
  • Security logs, access metadata, session information and incident investigation context.

Processing Activities

The matrix below condenses the main processing activities procurement teams usually review without repeating formal DPA availability language.

Verbum processes message context, AI draft inputs, approval workflow records and audit history so customers can operate AI-assisted messaging according to their instructions and configured controls.

Verbum does not use customer business messages to train public AI models unless explicitly stated and contractually allowed.

Customer message content is processed to provide configured AI-assisted drafting, routing, review and Verbum Automate workflows.

Customer message content is not used to train public or general-purpose AI models unless explicitly stated and contractually allowed.

Fine-tuning or training on customer message content requires explicit written authorization in the applicable agreement.

AI subprocessors may process prompts, message context and outputs only to provide the configured service, subject to applicable provider terms and approved customer configuration.

Retention of prompts, outputs and related workflow context follows the applicable workspace settings, plan terms, provider configuration, DPA, order form or written agreement.

ENTERPRISE PROCESSING MATRIX

Processing activities and safeguards

A compact matrix for legal, procurement and privacy teams to review processing activity, data categories, purpose, retention reference and safeguards. An approved contract, DPA or written agreement controls where applicable.

Processing activities and safeguards
Processing activityData categoriesPurposeRetention referenceSafeguards/securityReview note
Account and workspace administrationAccount, workspace, user profile and access metadata.Administer workspaces, users, roles and account settings.Account lifecycle, subscription terms, workspace settings or written agreement.Access controls, encrypted transport and hosting/account operations providers where applicable.Controller/processor allocation depends on the applicable agreement and workspace role.
Omnichannel message routingConversation content, message history, contact identifiers and channel metadata.Route, draft, review and deliver messages through configured channels.Workspace configuration, plan terms, customer instructions or written agreement.Channel, hosting and infrastructure safeguards/providers where applicable.Subprocessor and channel-provider details can be reviewed for the approved workspace scope.
AI-assisted drafting and context processingMessage context, AI inputs, generated drafts and workflow metadata.Generate drafts, summaries or routing suggestions for enabled workflows.Conversation, workflow and audit records, provider terms or applicable agreement.AI infrastructure safeguards/providers where AI features are enabled for the workspace.Customer business messages are not used to train Verbum-owned foundation models.
Approval workflows and audit historyReviewer identity, decisions, timestamps, rules and audit events.Record human review, automation decisions and traceable messaging history.Plan configuration, workspace settings or written agreement.Hosting, observability and security safeguards/providers where applicable.Audit-history availability depends on enabled workflow events, plan capabilities and configuration.
Security, access, incident response and continuitySecurity logs, session metadata, event records and backup service data.Protect the service, monitor reliability, investigate incidents and maintain recoverability.Operational and backup lifecycles defined by policy, infrastructure or agreement.Security, monitoring, hosting, infrastructure and backup safeguards/providers where applicable.Deletion and return requests are reviewed against legal obligations, security needs and backup lifecycle controls.
Business, billing and review supportBilling metadata, support messages, privacy requests and review communications.Administer billing, support, privacy assistance and vendor review.Request lifecycle and accounting, tax, contract, security, operational or legal obligations.Payment, support, communication and document-review safeguards/providers where applicable.Privacy rights assistance and procurement requests are handled through the legal/privacy review path.

Security Safeguards

Verbum implements technical and organisational measures designed to protect Customer Data, including role-based access controls, least-privilege principles, encrypted transport, encryption at rest where applicable, monitoring and alerting, audit records and secure development practices.

These measures are designed to provide an appropriate level of security given the nature and sensitivity of Customer Data. Security and privacy review materials are available for qualified review.

  • Customer Data retention depends on workspace configuration, plan terms, customer instructions, provider configuration, legal obligations and the applicable agreement.
  • Deletion requests are reviewed subject to applicable legal obligations, operational requirements, security considerations and backup lifecycle controls.

International Transfers

Customer Data may be processed by Verbum or its subprocessors in countries outside the customer's jurisdiction, including countries that may not provide the same level of data protection as the customer's home jurisdiction.

Transfer mechanisms, regions and related safeguards become contractual commitments only when approved in the applicable contract, DPA or qualified legal review. Customers can request transfer-context review through the legal/privacy path.

  • A public overview of confirmed subprocessor information is maintained on the Subprocessors page. Additional provider names, regional details, processing purposes and transfer context may be shared with qualified customers during enterprise security or procurement review, subject to the appropriate confidentiality process.
  • Where applicable, Verbum will assist customers in responding to requests from individuals exercising data subject rights, including access, rectification, deletion, portability, restriction or objection, to the extent the relevant data is within Verbum's control and subject to applicable law.
  • In the event of a security incident that affects Customer Data, Verbum will notify affected customers as required by applicable law and its contractual commitments. Notifications will include sufficient information to enable customers to meet their own reporting obligations where relevant.

Review Process

Qualified customers can request DPA review through the legal/privacy path on the contact form. Include your company, expected workspace use case and whether the request is for procurement, privacy review, security review or contracting.

Because DPA review and supporting materials may include non-public terms or evidence, access may require qualified review, an applicable order form, NDA or the appropriate confidentiality process.

Useful review materials can include this overview, the Privacy Policy, Subprocessors page, Security overview, Trust Center and the contact path linked below.

  • DPA review workflow and data-processing terms
  • Subprocessors information
  • Security overview
  • privacy documentation

PROCUREMENT AND LEGAL REVIEW

Vendor review package for DPA and security questions

This page is the public overview. Qualified customers can route DPA questions through legal review alongside Trust Center, Security overview, subprocessors and privacy documentation. Formal DPA terms remain subject to legal approval and applicable contracting scope.

Need DPA or security review?

Request DPA review and related privacy, security and subprocessor context for qualified procurement or legal review.