What data we collect
Account, billing, support, usage, workspace configuration and business messaging data needed to operate Verbum.
See data categoriesPrivacy Policy
Review Verbum's privacy practices for AI-assisted business messaging, including data categories, customer rights, retention, subprocessors, cookies and enterprise review paths.
Related legal documents
EXECUTIVE SUMMARY
A procurement-friendly summary of the policy. Detailed sections below remain the controlling public overview.
Account, billing, support, usage, workspace configuration and business messaging data needed to operate Verbum.
See data categoriesTo provide the platform, support approved workflows, protect the service, manage subscriptions and respond to requests.
Review purposesGDPR, LGPD or similar rights may apply depending on location, role, data category and verification requirements.
Review rightsRetention depends on data category, workspace configuration, plan terms, approved DPA or written agreement.
Open retention matrixPublic security materials describe controls for access, encryption, audit history, incident response and qualified review.
Review securityConfirmed public subprocessors and qualified-review provider categories are linked for procurement review.
Review subprocessorsENTERPRISE PRIVACY MAP
Use these cards to find the part of the policy procurement, privacy and security teams usually review first.
Controller identity details for website, account, billing, support and contact-form data are coordinated through the Verbum legal/privacy review path.
Review rolesFor customer business messaging content and workspace workflow data, Verbum processes according to customer instructions and applicable terms.
Review subprocessorsInternational transfer context depends on configuration, providers and applicable data protection requirements.
Review transfersAccess, correction, deletion, portability, objection and restriction requests are routed through the legal/privacy contact path and reviewed after verification.
Review rightsRetention depends on data category, workspace configuration, plan terms, customer instructions and applicable agreement.
Review retentionSecurity measures and review materials support qualified privacy, procurement and security evaluation.
Review securityVerbum is a governed omnichannel messaging platform built for enterprise teams. We provide AI-assisted drafting, configurable approval controls, and traceable message history across channels including WhatsApp, email, and workplace messaging tools.
For customer business messaging content and workspace workflow data, Verbum acts as a processor or service provider according to customer instructions, the applicable agreement and DPA review context where applicable.
For website, account administration, billing, support, security and contact-form data, Verbum provides a legal/privacy contact path for privacy questions and data protection requests.
For privacy or data protection requests, use the Verbum legal/privacy contact path.
Privacy contact: [email protected].
Verbum is designed to support privacy-aware processing for organizations operating under LGPD, GDPR and similar data protection frameworks. Customers remain responsible for configuring their workflows and meeting their own regulatory obligations.
Customers can review what categories of personal data may be processed through Verbum and how workspace records are handled.
Ask for support correcting account or workspace data, or request context on deletion, retention and backup handling under applicable terms.
Raise restriction, objection or portability questions where applicable under LGPD, GDPR or similar frameworks.
Request data processing terms, public subprocessor context and security materials for qualified privacy or procurement review.
Related review resources:
For privacy or data protection requests, contact Verbum through the legal/privacy path on the Contact page.
We collect the data needed to provide governed messaging, maintain account and billing operations, respond to requests, protect the service and support customer-configured workflows.
| Data category | What it includes |
|---|---|
| Account data | Name, work email address, role and workspace membership when you create an account or are invited by an administrator. |
| Billing data | Subscription tier, billing contact and payment method identifiers. Full card data is handled by Stripe and is not stored in Verbum systems. |
| Product usage data | Platform usage signals such as page views, feature interactions and session duration used for reliability and product improvement. We do not profile individual users for advertising. |
| Support/contact data | Messages submitted through support, contact, privacy, legal or security forms, plus routing context needed to respond to the request. |
| Business messaging metadata and content | Inbound and outbound message content, AI-generated drafts, edits, approval decisions, delivery events and related metadata processed through your workspace channels. |
| Google user data (Gmail connection) | Google account email address and profile name, plus messages, headers, bodies and attachments from a Gmail or Google Workspace mailbox that a customer connects through Google Sign-In. See the Google user data section for scope, use, sharing and retention. |
| Workspace configuration | Routing rules, approval workflows, channel connection settings and workspace settings you configure in the platform. |
We use data to operate Verbum, manage accounts and billing, respond to requests, protect the service, support customer-configured workflows and meet applicable legal or contractual requirements.
We do not use your message content or customer data for marketing, advertising, or any purpose unrelated to platform operation.
Verbum may process customer conversation data, AI-assisted drafts, workflow metadata and audit history to provide governed AI messaging features, subject to customer configuration, configured providers and contractual terms.
Verbum does not use customer business messages to train public AI models unless explicitly stated and contractually allowed.
Customers can connect a Gmail or Google Workspace mailbox to Verbum through Google Sign-In (OAuth). This section describes which Google data Verbum accesses, how it is used, with whom it is shared, how long it is kept and how to revoke access.
Verbum's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The legal basis for processing depends on Verbum's role, the data category, customer configuration, jurisdiction and the applicable agreement.
Audit history helps customers understand who drafted, reviewed, approved, automated or sent messages. These records support governance, security review and accountability.
If your workspace processes messages on behalf of end customers, you are responsible for ensuring the lawful basis for that processing under applicable privacy law.
We do not sell, rent, or trade your data. We share data only with service providers that help us operate the platform, under strict contractual obligations.
A public subprocessor overview is available on the Subprocessors page for review. Qualified customers and enterprise evaluators may request additional details during security, privacy or DPA review.
Verbum uses Stripe to process payments. We do not store payment card data on our servers.
The current public website inventory is limited to browser storage for language and cookie-preference state, consent-gated analytics dispatch and Stripe checkout cookies and similar technologies when checkout is opened.
Optional analytics runs only after consent and only when an approved provider is configured.
For a detailed list of cookies used on vrbm.app, review the Cookie Policy for the current inventory.
We retain data according to workspace settings, plan configuration and applicable legal, security, operational and contractual requirements.
The matrix below is a public overview for procurement and privacy review. Specific retention commitments may be defined by workspace settings, plan terms, an approved DPA, an order form or another written agreement.
| Data category | Purpose | Default retention | Control | Deletion process | Legal/contractual notes |
|---|---|---|---|---|---|
| Plan-level conversation history | Provide governed messaging, routing, review, delivery context and customer workflow history. | Defined by workspace settings, plan terms, customer instructions, approved implementation scope or written agreement. | Customers control business messaging data and workspace configuration; Verbum processes it to provide the service. | Handled through workspace configuration, offboarding, customer instruction or verified request, subject to operational, legal and security constraints. | Customers remain responsible for the lawful basis and retention choices for their own business messages. |
| Account data | Create, authenticate, administer and support Verbum accounts and workspace membership. | Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle. | Verbum controls account administration data; customer administrators control workspace membership where applicable. | Deleted, deactivated or minimized through account closure, verified privacy request or customer offboarding, subject to required records. | Some references may remain where required for billing, security, dispute, legal or contractual purposes. |
| Contact, demo and signup leads | Respond to demo, signup, legal, privacy, security, procurement and support requests. | Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle. | Verbum controls public website and contact-form lead records. | Deleted, suppressed or minimized after a verified privacy request unless retention is required for legal, security or dispute purposes. | Lead records are separate from customer workspace message content. |
| Security logs | Protect the platform, investigate abuse, monitor access and support incident response. | Defined by approved security policy, applicable agreement, legal requirements and operational security needs. | Verbum controls security logging required to protect the service. | Deleted through log lifecycle controls when no longer required for security, legal or operational purposes. | Security logs may be retained despite account deletion requests where necessary to protect the service or comply with law. |
| Billing records | Manage subscriptions, invoices, billing contacts, payment processor references and accounting obligations. | Retained as required for tax, accounting, chargeback, legal, contractual or payment-processing obligations. | Verbum controls billing metadata; Stripe handles full payment card data under its own terms. | Removed or minimized when no longer required, subject to accounting, payment, legal and contractual retention requirements. | Verbum does not store full payment card numbers on its servers. |
| Backups | Support resilience, recovery and business continuity. | Managed under approved operational backup lifecycle, infrastructure policy or applicable agreement. | Verbum controls backup lifecycle and recovery processes. | Deleted through backup lifecycle controls; immediate item-level deletion from backups may not be technically available. | Restored data remains subject to the same deletion and retention rules after recovery. |
| Support and procurement communications | Respond to support, legal, privacy, procurement, security and vendor review requests. | Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle. | Verbum controls support, procurement and review communications submitted to Verbum. | Deleted, minimized or archived through support lifecycle controls or verified privacy request where applicable. | Security package, DPA review and vendor review materials may require confidentiality review or applicable agreement terms. |
Deletion and retention requests are reviewed subject to applicable law, customer instructions, security obligations, backup lifecycle controls and the applicable agreement. This overview does not replace a signed DPA or order form.
Depending on where you are located and how Verbum processes the data, you may have GDPR, LGPD or similar privacy rights. Verbum routes privacy/legal requests for review according to applicable law, customer configuration and verification requirements.
| Right | What it means | How to request |
|---|---|---|
| Access | Request a copy of personal data we hold about you. | Use the legal/privacy path on the Contact page; verification may be required. |
| Correction | Request correction of inaccurate personal data. | Use the legal/privacy path on the Contact page; verification may be required. |
| Erasure | Request deletion of your personal data, subject to legal retention requirements. | Use the legal/privacy path on the Contact page; verification may be required. |
| Portability | Request an export of data you provided in a machine-readable format. | Use the legal/privacy path on the Contact page; verification may be required. |
| Objection | Object to processing based on legitimate interests. | Use the legal/privacy path on the Contact page; verification may be required. |
| Restriction | Request that we limit how we process your data in certain circumstances. | Use the legal/privacy path on the Contact page; verification may be required. |
To exercise any of these rights, use the legal/privacy path on the Contact page. We respond to verified requests according to applicable law and verification requirements.
Verbum operates on cloud infrastructure that may be located outside your country. Transfer details may depend on customer configuration, providers and applicable data protection requirements.
We implement technical and organizational measures designed to protect your data against unauthorized access, loss, or misuse.
No system is completely secure. We encourage you to use strong passwords and enable MFA on your Verbum account.
Verbum is a business-to-business platform designed for enterprise teams. It is not directed at individuals under the age of 16.
We do not knowingly collect personal data from anyone under 16 years of age. If you believe a minor has provided us with personal data, use the legal/privacy path on the Contact page so the request can be reviewed.
We may update this document to reflect product, operational, legal or regulatory changes. Material updates will be communicated where required by applicable law or contract.
Questions about this Privacy Policy or how Verbum handles your data?
For privacy or data protection requests, contact Verbum through the legal/privacy path on the Contact page.
PRIVACY AND LEGAL REVIEW
Use the privacy/legal path for data rights questions, DPA review or privacy documentation.