データ処理契約

ガバナンスされたメッセージングのためのデータ処理

この公開概要では、Verbumがガバナンスされたメッセージングにおける顧客データ処理にどのように取り組むかを説明します。これは署名済みDPAではなく、対署名条件を公開するものでもありません。法務、プライバシー、調達レビューの準備に使用してください。

Document metadata

Document: Data Processing Overview

Effective date: June 16, 2026

最終更新日: June 18, 2026

Version: 1.0.1

Document owner/category: Legal / Privacy

Legal/privacy contact: [email protected]

PROCUREMENT REVIEW MAP

Review data-processing posture in one pass

Use this hub to identify what is public today, what requires qualified legal review and which materials support DPA, privacy and security assessment.

  • Overview

    Public overview, current DPA status and available review resources.

    Review section
  • Data Categories

    Customer, workspace, messaging, AI, audit, billing and review data at a glance.

    Review section
  • Processing Activities

    Compact matrix covering activity, data, purpose, retention reference and safeguards.

    Review section
  • Security Safeguards

    Public control overview and qualified security-package path.

    Review section
  • International Transfers

    Transfer context stays subject to approved contract, DPA or qualified legal review.

    Review section
  • Review Process

    How legal, privacy and procurement teams request DPA and security review.

    Review section

1. 目的

このページでは、ガバナンスされたメッセージングプラットフォームの提供に関連して、Verbumが顧客データの処理にどのようにアプローチするかを説明しています。

GDPR、LGPD、または同等の法律に基づく正式な、対署名されたデータ処理契約を必要とする顧客は、お問い合わせフォームの法務/プライバシー経路をご利用ください。

It is not a customer compliance determination, does not guarantee that privacy or security risks are eliminated and does not create a hosting-region commitment.

Formal DPA status

A formal DPA is reviewed through the legal process when available for the applicable contracting scope.

This public overview does not publish a DPA version, effective date, signatory entity, transfer mechanism or countersignature workflow.

  • Available now: this Public Data Processing Overview, Privacy Policy, Security Overview, Trust Center and Subprocessors page.
  • Applicable contracting scope, DPA terms and transfer commitments are confirmed only through the legal process.
  • Confidentiality: non-public terms, evidence or deployment-specific details may require NDA or an appropriate confidentiality process.
  • Request path: use Request DPA review and include your company, use case, contracting context and procurement deadline.

4. 顧客データ

プラットフォームを通じて処理される顧客データには、アカウントとワークスペース情報、ユーザーとチームのプロフィールデータ、チャンネルの設定とメタデータ、会話コンテンツとメッセージ履歴、AIドラフトのコンテキスト、承認アクション、監査ログ、請求と連絡先情報が含まれる場合があります。

顧客は常にデータの所有権を保持します。Verbumはサービスを運営・提供するためだけに顧客データを処理します。

  • Account, workspace, company and user profile data.
  • Conversation content, message history, contact identifiers and channel metadata.
  • AI prompts or inputs, generated drafts, summaries and configured workflow context.
  • Approval decisions, reviewer identity, timestamps, rules and audit events.
  • Billing metadata, support messages, procurement communications and privacy request metadata.
  • Security logs, access metadata, session information and incident investigation context.

5. 処理活動

Verbumは、設定されたチャンネルを通じてメッセージをルーティングするため、AI支援ドラフトと要約を生成するため、承認ワークフローを管理するため、監査記録を維持するため、ユーザーを認証するため、請求処理を行うため、顧客サポートを提供するため、プラットフォームの信頼性を向上させるために顧客データを処理します。

Verbumは、お客様の指示と設定済みコントロールに従ってAI支援メッセージングを運用できるよう、メッセージコンテキスト、AIドラフト入力、承認ワークフローレコード、監査履歴を処理します。

Verbum does not use customer business messages to train public AI models unless explicitly stated and contractually allowed.

Customer message content is processed to provide configured AI-assisted drafting, routing, review and Verbum Automate workflows.

Customer message content is not used to train public or general-purpose AI models unless explicitly stated and contractually allowed.

Fine-tuning or training on customer message content requires explicit written authorization in the applicable agreement.

AI subprocessors may process prompts, message context and outputs only to provide the configured service, subject to applicable provider terms and approved customer configuration.

Retention of prompts, outputs and related workflow context follows the applicable workspace settings, plan terms, provider configuration, DPA, order form or written agreement.

ENTERPRISE PROCESSING MATRIX

Processing activities and safeguards

A compact matrix for legal, procurement and privacy teams to review processing activity, data categories, purpose, retention reference and safeguards. An approved contract, DPA or written agreement controls where applicable.

Processing activities and safeguards
Processing activityData categoriesPurposeRetention referenceSafeguards/securityReview note
Account and workspace administrationAccount, workspace, user profile and access metadata.Administer workspaces, users, roles and account settings.Account lifecycle, subscription terms, workspace settings or written agreement.Access controls, encrypted transport and hosting/account operations providers where applicable.Controller/processor allocation depends on the applicable agreement and workspace role.
Omnichannel message routingConversation content, message history, contact identifiers and channel metadata.Route, draft, review and deliver messages through configured channels.Workspace configuration, plan terms, customer instructions or written agreement.Channel, hosting and infrastructure safeguards/providers where applicable.Subprocessor and channel-provider details can be reviewed for the approved workspace scope.
AI-assisted drafting and context processingMessage context, AI inputs, generated drafts and workflow metadata.Generate drafts, summaries or routing suggestions for enabled workflows.Conversation, workflow and audit records, provider terms or applicable agreement.AI infrastructure safeguards/providers where AI features are enabled for the workspace.Customer business messages are not used to train Verbum-owned foundation models.
Approval workflows and audit historyReviewer identity, decisions, timestamps, rules and audit events.Record human review, automation decisions and traceable messaging history.Plan configuration, workspace settings or written agreement.Hosting, observability and security safeguards/providers where applicable.Audit-history availability depends on enabled workflow events, plan capabilities and configuration.
Security, access, incident response and continuitySecurity logs, session metadata, event records and backup service data.Protect the service, monitor reliability, investigate incidents and maintain recoverability.Operational and backup lifecycles defined by policy, infrastructure or agreement.Security, monitoring, hosting, infrastructure and backup safeguards/providers where applicable.Deletion and return requests are reviewed against legal obligations, security needs and backup lifecycle controls.
Business, billing and review supportBilling metadata, support messages, privacy requests and review communications.Administer billing, support, privacy assistance and vendor review.Request lifecycle and accounting, tax, contract, security, operational or legal obligations.Payment, support, communication and document-review safeguards/providers where applicable.Privacy rights assistance and procurement requests are handled through the legal/privacy review path.

7. セキュリティ措置

Verbumは顧客データを保護するための技術的および組織的な措置を実施しています。これには、役割ベースのアクセス制御、TLSによる転送中の暗号化、継続的なモニタリング、追跡可能な監査履歴、安全な開発慣行が含まれます。

これらの措置は、顧客データの性質と機密性に応じた適切なセキュリティ水準を提供するよう設計されています。セキュリティおよびコンプライアンス資料は、対象となるレビュー向けに提供できます。

  • 顧客データは、顧客のアカウントが有効な期間および法的、規制的、または契約上の義務を履行するために必要な追加期間、保持されます。
  • 早期削除のリクエストは、お問い合わせフォームのプライバシー経路から送信できます。

10. 国際的な転送

顧客データは、顧客の管轄外の国々、同等レベルのデータ保護を提供していない国々を含めてVerbumまたはそのサブプロセッサーによって処理される場合があります。

特定の転送制限がある管轄が関係する場合、適切な保護措置は該当するDPA、契約条件、またはエンタープライズセキュリティレビューで確認できます。

  • 現在のサブプロセッサーカテゴリと提供者のリストは、サブプロセッサーページで管理されています。
  • 該当する場合、Verbumは顧客が個人のデータ主体の権利(アクセス、訂正、消去など)を行使するリクエストに対応する際に支援します。
  • 顧客データに影響するセキュリティインシデントが発生した場合、Verbumは適用法と契約上のコミットメントに従って影響を受ける顧客に通知します。

Review Process

DPA review questions can be routed through the legal/privacy contact path.

Because DPA review and supporting materials may include non-public terms or evidence, access may require qualified review, an applicable order form, NDA or the appropriate confidentiality process.

Useful review materials can include this overview, the Privacy Policy, Subprocessors page, Security Overview, Trust Center and the contact path linked below.

  • DPA review workflow and data-processing terms
  • Subprocessors information
  • Security overview and control review materials
  • Privacy documentation

PROCUREMENT AND LEGAL REVIEW

Vendor review package for DPA and security questions

This page is the public overview. Qualified customers can route DPA questions through legal review alongside Trust Center, Security Overview, Subprocessors and Privacy Policy context. Formal DPA terms remain subject to legal approval and applicable contracting scope.

DPAレビューが必要ですか?

対署名されたデータ処理契約を要求するためにお問い合わせください。