Overview
Public overview, current DPA status and available review resources.
Review sectionDATA PROCESSING
This public overview explains how Verbum approaches customer-data processing for governed AI messaging. It is not a signed DPA, does not publish countersignature terms and should be used to prepare qualified legal, privacy or procurement review.
PROCUREMENT REVIEW MAP
Use this hub to identify what is public today, what requires qualified legal review and which materials support DPA, privacy and security assessment.
Public overview, current DPA status and available review resources.
Review sectionCustomer data types used across workspace, messaging, AI and audit workflows.
Review sectionCompact matrix covering activity, data, purpose, retention reference and safeguards.
Review sectionPublic controls and qualified evidence paths for security review.
Review sectionTransfer context and safeguards become commitments only in an approved contract or qualified legal review.
Review sectionHow qualified procurement, privacy and legal teams request DPA and security review.
Review sectionThis page is a public Data Processing Overview for general legal, procurement and privacy review. It summarizes how Verbum approaches customer data processing for its governed messaging platform and helps teams prepare DPA review questions.
This public overview does not replace the signed DPA.
It is not a customer compliance determination, does not guarantee that privacy or security risks are eliminated and does not create a hosting-region commitment.
A formal DPA is reviewed through the legal process when available for the applicable contracting scope.
This public overview does not publish a DPA version, effective date, signatory entity, transfer mechanism or countersignature workflow.
Customer data processed through the platform may include the categories below, depending on enabled features, connected channels and customer instructions.
Customers retain ownership of their data under the applicable legal and contractual framework. Verbum processes Customer Data only to operate and provide the Service, to fulfil legal obligations, and, where applicable, to improve reliability and security.
The matrix below condenses the main processing activities procurement teams usually review without repeating formal DPA availability language.
Verbum processes message context, AI draft inputs, approval workflow records and audit history so customers can operate AI-assisted messaging according to their instructions and configured controls.
Verbum does not use customer business messages to train public AI models unless explicitly stated and contractually allowed.
Customer message content is processed to provide configured AI-assisted drafting, routing, review and Verbum Automate workflows.
Customer message content is not used to train public or general-purpose AI models unless explicitly stated and contractually allowed.
Fine-tuning or training on customer message content requires explicit written authorization in the applicable agreement.
AI subprocessors may process prompts, message context and outputs only to provide the configured service, subject to applicable provider terms and approved customer configuration.
Retention of prompts, outputs and related workflow context follows the applicable workspace settings, plan terms, provider configuration, DPA, order form or written agreement.
ENTERPRISE PROCESSING MATRIX
A compact matrix for legal, procurement and privacy teams to review processing activity, data categories, purpose, retention reference and safeguards. An approved contract, DPA or written agreement controls where applicable.
| Processing activity | Data categories | Purpose | Retention reference | Safeguards/security | Review note |
|---|---|---|---|---|---|
| Account and workspace administration | Account, workspace, user profile and access metadata. | Administer workspaces, users, roles and account settings. | Account lifecycle, subscription terms, workspace settings or written agreement. | Access controls, encrypted transport and hosting/account operations providers where applicable. | Controller/processor allocation depends on the applicable agreement and workspace role. |
| Omnichannel message routing | Conversation content, message history, contact identifiers and channel metadata. | Route, draft, review and deliver messages through configured channels. | Workspace configuration, plan terms, customer instructions or written agreement. | Channel, hosting and infrastructure safeguards/providers where applicable. | Subprocessor and channel-provider details can be reviewed for the approved workspace scope. |
| AI-assisted drafting and context processing | Message context, AI inputs, generated drafts and workflow metadata. | Generate drafts, summaries or routing suggestions for enabled workflows. | Conversation, workflow and audit records, provider terms or applicable agreement. | AI infrastructure safeguards/providers where AI features are enabled for the workspace. | Customer business messages are not used to train Verbum-owned foundation models. |
| Approval workflows and audit history | Reviewer identity, decisions, timestamps, rules and audit events. | Record human review, automation decisions and traceable messaging history. | Plan configuration, workspace settings or written agreement. | Hosting, observability and security safeguards/providers where applicable. | Audit-history availability depends on enabled workflow events, plan capabilities and configuration. |
| Security, access, incident response and continuity | Security logs, session metadata, event records and backup service data. | Protect the service, monitor reliability, investigate incidents and maintain recoverability. | Operational and backup lifecycles defined by policy, infrastructure or agreement. | Security, monitoring, hosting, infrastructure and backup safeguards/providers where applicable. | Deletion and return requests are reviewed against legal obligations, security needs and backup lifecycle controls. |
| Business, billing and review support | Billing metadata, support messages, privacy requests and review communications. | Administer billing, support, privacy assistance and vendor review. | Request lifecycle and accounting, tax, contract, security, operational or legal obligations. | Payment, support, communication and document-review safeguards/providers where applicable. | Privacy rights assistance and procurement requests are handled through the legal/privacy review path. |
Verbum implements technical and organisational measures designed to protect Customer Data, including role-based access controls, least-privilege principles, encrypted transport, encryption at rest where applicable, monitoring and alerting, audit records and secure development practices.
These measures are designed to provide an appropriate level of security given the nature and sensitivity of Customer Data. Security and privacy review materials are available for qualified review.
Customer Data may be processed by Verbum or its subprocessors in countries outside the customer's jurisdiction, including countries that may not provide the same level of data protection as the customer's home jurisdiction.
Transfer mechanisms, regions and related safeguards become contractual commitments only when approved in the applicable contract, DPA or qualified legal review. Customers can request transfer-context review through the legal/privacy path.
Qualified customers can request DPA review through the legal/privacy path on the contact form. Include your company, expected workspace use case and whether the request is for procurement, privacy review, security review or contracting.
Because DPA review and supporting materials may include non-public terms or evidence, access may require qualified review, an applicable order form, NDA or the appropriate confidentiality process.
Useful review materials can include this overview, the Privacy Policy, Subprocessors page, Security overview, Trust Center and the contact path linked below.
PROCUREMENT AND LEGAL REVIEW
This page is the public overview. Qualified customers can route DPA questions through legal review alongside Trust Center, Security overview, subprocessors and privacy documentation. Formal DPA terms remain subject to legal approval and applicable contracting scope.
Request DPA review and related privacy, security and subprocessor context for qualified procurement or legal review.