Related legal documents

Review the privacy context alongside related legal resources.

EXECUTIVE SUMMARY

Privacy review in four questions.

A procurement-friendly summary of the policy. Detailed sections below remain the controlling public overview.

What data we collect

Account, billing, support, usage, workspace configuration and business messaging data needed to operate Verbum.

See data categories

Why we process it

To provide the platform, support approved workflows, protect the service, manage subscriptions and respond to requests.

Review purposes

Your rights

GDPR, LGPD or similar rights may apply depending on location, role, data category and verification requirements.

Review rights

Retention

Retention depends on data category, workspace configuration, plan terms, approved DPA or written agreement.

Open retention matrix

Security

Public security materials describe controls for access, encryption, audit history, incident response and qualified review.

Review security

Subprocessors

Confirmed public subprocessors and qualified-review provider categories are linked for procurement review.

Review subprocessors

ENTERPRISE PRIVACY MAP

Roles, transfer context and safeguards at a glance.

Use these cards to find the part of the policy procurement, privacy and security teams usually review first.

Controllers

Controller identity details for website, account, billing, support and contact-form data are coordinated through the Verbum legal/privacy review path.

Review roles

Processors

For customer business messaging content and workspace workflow data, Verbum processes according to customer instructions and applicable terms.

Review subprocessors

Transfers

International transfer context depends on configuration, providers and applicable data protection requirements.

Review transfers

Rights requests

Access, correction, deletion, portability, objection and restriction requests are routed through the legal/privacy contact path and reviewed after verification.

Review rights

Retention

Retention depends on data category, workspace configuration, plan terms, customer instructions and applicable agreement.

Review retention

Security measures

Security measures and review materials support qualified privacy, procurement and security evaluation.

Review security

Overview

Verbum is a governed omnichannel messaging platform built for enterprise teams. We provide AI-assisted drafting, configurable approval controls, and traceable message history across channels including WhatsApp, email, and workplace messaging tools.

For customer business messaging content and workspace workflow data, Verbum acts as a processor or service provider according to customer instructions, the applicable agreement and DPA review context where applicable.

For website, account administration, billing, support, security and contact-form data, Verbum provides a legal/privacy contact path for privacy questions and data protection requests.

For privacy or data protection requests, use the Verbum legal/privacy contact path.

Privacy contact: [email protected].

Privacy practices aligned with LGPD and GDPR.

Verbum is designed to support privacy-aware processing for organizations operating under LGPD, GDPR and similar data protection frameworks. Customers remain responsible for configuring their workflows and meeting their own regulatory obligations.

Privacy request support areas

  • Data access and transparency

    Customers can review what categories of personal data may be processed through Verbum and how workspace records are handled.

  • Correction, deletion and retention

    Ask for support correcting account or workspace data, or request context on deletion, retention and backup handling under applicable terms.

  • Restriction, objection and portability

    Raise restriction, objection or portability questions where applicable under LGPD, GDPR or similar frameworks.

  • Data processing, subprocessors and security review

    Request data processing terms, public subprocessor context and security materials for qualified privacy or procurement review.

Related review resources:

For privacy or data protection requests, contact Verbum through the legal/privacy path on the Contact page.

Data we collect

We collect the data needed to provide governed messaging, maintain account and billing operations, respond to requests, protect the service and support customer-configured workflows.

Data categories overviewThis table summarizes the main data categories described in this Privacy Policy for procurement and privacy review.
Data categoryWhat it includes
Account dataName, work email address, role and workspace membership when you create an account or are invited by an administrator.
Billing dataSubscription tier, billing contact and payment method identifiers. Full card data is handled by Stripe and is not stored in Verbum systems.
Product usage dataPlatform usage signals such as page views, feature interactions and session duration used for reliability and product improvement. We do not profile individual users for advertising.
Support/contact dataMessages submitted through support, contact, privacy, legal or security forms, plus routing context needed to respond to the request.
Business messaging metadata and contentInbound and outbound message content, AI-generated drafts, edits, approval decisions, delivery events and related metadata processed through your workspace channels.
Google user data (Gmail connection)Google account email address and profile name, plus messages, headers, bodies and attachments from a Gmail or Google Workspace mailbox that a customer connects through Google Sign-In. See the Google user data section for scope, use, sharing and retention.
Workspace configurationRouting rules, approval workflows, channel connection settings and workspace settings you configure in the platform.

How we use data

We use data to operate Verbum, manage accounts and billing, respond to requests, protect the service, support customer-configured workflows and meet applicable legal or contractual requirements.

  • Delivering the Verbum platform: routing, drafting, approval workflows, and message delivery
  • Maintaining audit records and history as required by your workspace configuration
  • Billing and subscription management through our payment processor Stripe
  • Communicating with you about your account, plan changes, or critical product updates
  • Improving the platform using aggregated or privacy-preserving usage signals where enabled
  • Complying with applicable law and responding to valid legal requests

We do not use your message content or customer data for marketing, advertising, or any purpose unrelated to platform operation.

AI processing

Verbum may process customer conversation data, AI-assisted drafts, workflow metadata and audit history to provide governed AI messaging features, subject to customer configuration, configured providers and contractual terms.

AI data-use restriction

Verbum does not use customer business messages to train public AI models unless explicitly stated and contractually allowed.

  • Customer message content is processed to provide configured AI-assisted drafting, routing, review and Verbum Automate workflows.
  • Customer message content is not used to train public or general-purpose AI models unless explicitly stated and contractually allowed.
  • Fine-tuning or training on customer message content requires explicit written authorization in the applicable agreement.
  • AI subprocessors may process prompts, message context and outputs only to provide the configured service, subject to applicable provider terms and approved customer configuration.
  • Retention of prompts, outputs and related workflow context follows the applicable workspace settings, plan terms, provider configuration, DPA, order form or written agreement.

Operation and drafting context

  • Customer conversation data may provide the context needed to draft, route, review or automate business messages inside a configured workspace.
  • AI-assisted drafts are generated from the message context and workspace configuration needed to support the requested workflow.

Audit and workflow metadata

  • Workflow metadata can include channel, routing, approval, policy and delivery context used to operate Verbum Sense, Verbum Assist and Verbum Automate workflows.
  • Enabled workflow events can be recorded with available message, reviewer, rule, channel and timestamp context, subject to workspace configuration, plan capabilities and provider support.

Provider and retention context

  • Provider configuration and contractual terms can affect how AI data is handled, retained and protected where applicable.

Google user data

Customers can connect a Gmail or Google Workspace mailbox to Verbum through Google Sign-In (OAuth). This section describes which Google data Verbum accesses, how it is used, with whom it is shared, how long it is kept and how to revoke access.

Connecting and revoking access

  • A workspace administrator creates the connection on Google's consent screen. Verbum never receives the Google account password.
  • Access can be revoked at any time from the Google account permissions page or by disconnecting the email channel in the Verbum console.

Google data we access

  • Email address and profile name of the connected Google account (openid, email and profile scopes): used to identify the connected mailbox and show which account is linked to the channel.
  • Email messages from the connected mailbox, including headers, body and attachments (gmail.modify scope): used to display conversations in the Inbox, send replies from the same mailbox, mark messages as read in Gmail when they are opened in Verbum and, when the customer enables it, generate AI analyses and drafts.

What we do not do with Google data

  • We do not sell Google user data.
  • We do not use Google user data for advertising.
  • We do not transfer Google user data to third parties, except to the subprocessors needed to operate the service: AWS for storage and processing, and the AI provider when the customer enables AI analysis.
  • We do not use Google user data to develop, improve or train generalized AI or machine-learning models.
  • Humans read Google user data only with the customer's consent, for support, for security purposes or when required by law.

Retention and deletion

  • Messages and attachments imported from the connected mailbox are stored while the channel stays connected and according to the workspace retention configuration.
  • When the channel is disconnected, the Google access tokens are revoked and deleted.
  • Deletion of imported messages and attachments follows the customer's request through the legal/privacy path on the Contact page.

Limited Use disclosure

Verbum's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Business messaging data

Audit history helps customers understand who drafted, reviewed, approved, automated or sent messages. These records support governance, security review and accountability.

  • Enabled workflow events can be recorded with available actor, decision, channel, rule and timestamp context, subject to workspace configuration, plan capabilities and provider support.
  • Audit records are designed to preserve workflow context after the event for customer review and accountability.
  • Audit review or export workflows may be available by plan, configuration and approved implementation scope.
  • Retention handling depends on workspace configuration, plan terms, customer instructions, approved implementation scope or written agreement.

If your workspace processes messages on behalf of end customers, you are responsible for ensuring the lawful basis for that processing under applicable privacy law.

Sharing and subprocessors

We do not sell, rent, or trade your data. We share data only with service providers that help us operate the platform, under strict contractual obligations.

  • Cloud infrastructure providers: hosting, storage, and database services for platform operation.
  • AI model providers: used exclusively to generate message drafts within your workspace context.
  • Payment processor (Stripe): billing and subscription management.
  • Analytics or measurement services, where enabled: aggregated or privacy-preserving usage signals for reliability and product improvement.

A public subprocessor overview is available on the Subprocessors page for review. Qualified customers and enterprise evaluators may request additional details during security, privacy or DPA review.

Payment data

Verbum uses Stripe to process payments. We do not store payment card data on our servers.

  • Credit or debit card numbers are collected and stored by Stripe, our third-party payment processor.
  • Verbum only stores non-sensitive billing identifiers (Stripe customer ID, subscription tier, billing contact email).
  • Stripe's privacy policy governs how Stripe handles payment data. You can review it at stripe.com/privacy.

Cookies and analytics

The current public website inventory is limited to browser storage for language and cookie-preference state, consent-gated analytics dispatch and Stripe checkout cookies and similar technologies when checkout is opened.

  • verbum-locale: Stores the selected public-site language preference in localStorage.
  • verbum-cookie-preferences: Stores the visitor's cookie preference-center choices in localStorage, including analytics and marketing status.
  • verbum-analytics-consent: Stores whether analytics consent has been accepted before optional analytics dispatch can run.
  • Stripe checkout cookies and similar technologies: Supports secure checkout and payment session continuity when checkout is opened.

Optional analytics runs only after consent and only when an approved provider is configured.

For a detailed list of cookies used on vrbm.app, review the Cookie Policy for the current inventory.

Data retention and deletion

We retain data according to workspace settings, plan configuration and applicable legal, security, operational and contractual requirements.

The matrix below is a public overview for procurement and privacy review. Specific retention commitments may be defined by workspace settings, plan terms, an approved DPA, an order form or another written agreement.

Retention overview by data categoryDefault retention depends on the data category, customer configuration, plan terms and applicable legal or contractual requirements.
Data categoryPurposeDefault retentionControlDeletion processLegal/contractual notes
Plan-level conversation historyProvide governed messaging, routing, review, delivery context and customer workflow history.Defined by workspace settings, plan terms, customer instructions, approved implementation scope or written agreement.Customers control business messaging data and workspace configuration; Verbum processes it to provide the service.Handled through workspace configuration, offboarding, customer instruction or verified request, subject to operational, legal and security constraints.Customers remain responsible for the lawful basis and retention choices for their own business messages.
Account dataCreate, authenticate, administer and support Verbum accounts and workspace membership.Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle.Verbum controls account administration data; customer administrators control workspace membership where applicable.Deleted, deactivated or minimized through account closure, verified privacy request or customer offboarding, subject to required records.Some references may remain where required for billing, security, dispute, legal or contractual purposes.
Contact, demo and signup leadsRespond to demo, signup, legal, privacy, security, procurement and support requests.Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle.Verbum controls public website and contact-form lead records.Deleted, suppressed or minimized after a verified privacy request unless retention is required for legal, security or dispute purposes.Lead records are separate from customer workspace message content.
Security logsProtect the platform, investigate abuse, monitor access and support incident response.Defined by approved security policy, applicable agreement, legal requirements and operational security needs.Verbum controls security logging required to protect the service.Deleted through log lifecycle controls when no longer required for security, legal or operational purposes.Security logs may be retained despite account deletion requests where necessary to protect the service or comply with law.
Billing recordsManage subscriptions, invoices, billing contacts, payment processor references and accounting obligations.Retained as required for tax, accounting, chargeback, legal, contractual or payment-processing obligations.Verbum controls billing metadata; Stripe handles full payment card data under its own terms.Removed or minimized when no longer required, subject to accounting, payment, legal and contractual retention requirements.Verbum does not store full payment card numbers on its servers.
BackupsSupport resilience, recovery and business continuity.Managed under approved operational backup lifecycle, infrastructure policy or applicable agreement.Verbum controls backup lifecycle and recovery processes.Deleted through backup lifecycle controls; immediate item-level deletion from backups may not be technically available.Restored data remains subject to the same deletion and retention rules after recovery.
Support and procurement communicationsRespond to support, legal, privacy, procurement, security and vendor review requests.Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle.Verbum controls support, procurement and review communications submitted to Verbum.Deleted, minimized or archived through support lifecycle controls or verified privacy request where applicable.Security package, DPA review and vendor review materials may require confidentiality review or applicable agreement terms.

Deletion and retention requests are reviewed subject to applicable law, customer instructions, security obligations, backup lifecycle controls and the applicable agreement. This overview does not replace a signed DPA or order form.

Your rights

Depending on where you are located and how Verbum processes the data, you may have GDPR, LGPD or similar privacy rights. Verbum routes privacy/legal requests for review according to applicable law, customer configuration and verification requirements.

Privacy rights overviewRights availability depends on location, Verbum's role, data category and verification requirements.
RightWhat it meansHow to request
AccessRequest a copy of personal data we hold about you.Use the legal/privacy path on the Contact page; verification may be required.
CorrectionRequest correction of inaccurate personal data.Use the legal/privacy path on the Contact page; verification may be required.
ErasureRequest deletion of your personal data, subject to legal retention requirements.Use the legal/privacy path on the Contact page; verification may be required.
PortabilityRequest an export of data you provided in a machine-readable format.Use the legal/privacy path on the Contact page; verification may be required.
ObjectionObject to processing based on legitimate interests.Use the legal/privacy path on the Contact page; verification may be required.
RestrictionRequest that we limit how we process your data in certain circumstances.Use the legal/privacy path on the Contact page; verification may be required.

To exercise any of these rights, use the legal/privacy path on the Contact page. We respond to verified requests according to applicable law and verification requirements.

International data transfers

Verbum operates on cloud infrastructure that may be located outside your country. Transfer details may depend on customer configuration, providers and applicable data protection requirements.

  • Where required, appropriate transfer mechanisms may be addressed through qualified legal review, an approved DPA, an order form or enterprise security review.
  • Data residency requirements can be reviewed from Business where supported by configuration and provider availability.
  • International transfer context can be reviewed through data processing and security materials.

Security measures

We implement technical and organizational measures designed to protect your data against unauthorized access, loss, or misuse.

  • Data in transit is protected using TLS. Encryption at rest is documented where applicable for platform storage.
  • Access to customer data is restricted by role-based access control (RBAC) and requires authentication.
  • We operate a documented incident response process. In the event of a breach affecting personal data, we aim to notify affected customers in accordance with applicable legal requirements.
  • To report a security vulnerability, use the security path on the contact form. We review reports through our security response process.

No system is completely secure. We encourage you to use strong passwords and enable MFA on your Verbum account.

Children's privacy

Verbum is a business-to-business platform designed for enterprise teams. It is not directed at individuals under the age of 16.

We do not knowingly collect personal data from anyone under 16 years of age. If you believe a minor has provided us with personal data, use the legal/privacy path on the Contact page so the request can be reviewed.

Changes to this document

We may update this document to reflect product, operational, legal or regulatory changes. Material updates will be communicated where required by applicable law or contract.

Contact privacy/legal

Questions about this Privacy Policy or how Verbum handles your data?

For privacy or data protection requests, contact Verbum through the legal/privacy path on the Contact page.

PRIVACY AND LEGAL REVIEW

Contact privacy/legal

Use the privacy/legal path for data rights questions, DPA review or privacy documentation.