Data Processing Agreement
Veros Inc (operating as VeryAI) and Customer
Effective Date: 11 March 2025 | Last Updated: 9 July 2026
PLEASE NOTE. This Data Processing Agreement supplements the Master Services Agreement or other written agreement between Veros Inc and the Customer named in that agreement, and applies to the processing of Personal Data in connection with the Service.
This Data Processing Agreement (the "DPA") forms part of, and is incorporated into, the Master Services Agreement or other written agreement between Veros Inc, an exempted company incorporated with limited liability in the Cayman Islands with registration number OS-420535, doing business as VeryAI ("VeryAI"), and the customer named in that agreement ("Customer"), for VeryAI's provision of biometric verification services (the "Agreement"). VeryAI and Customer are each a "Party" and together the "Parties".
This DPA reflects the Parties' agreement on the processing of Personal Data in connection with the Service. In the event of any conflict between this DPA and the Agreement, this DPA prevails on matters relating to the processing of Personal Data, subject to the order of precedence in Section 16.1.
1. Definitions
1.1 Capitalised terms used but not defined in this DPA have the meanings given in the Agreement, the Terms of Use, the Privacy Policy or Data Protection Laws (as the context requires).
- "Audit Images" means limited, low-resolution images, crops or derived visual records of a palm capture retained solely for security, fraud prevention, liveness detection, quality assurance, debugging, audit and abuse-prevention purposes.
- "Biometric Data" means Palm Images, Palm Models and, where retained, Audit Images, and has the further meaning given in the Privacy Policy. Where used in this DPA, "Biometric Data" includes "biometric data" under Article 4(14) GDPR, "special category data" under Article 9 GDPR, "sensitive personal information" under the CCPA/CPRA, and "biometric identifiers" and/or "biometric information" under Biometric Privacy Laws.
- "Biometric Privacy Laws" means BIPA, CUBI, RCW 19.375, the New York City Biometric Identifier Information Law, and any other state, federal or international law regulating the collection, use, storage, retention, disclosure, sale or destruction of biometric identifiers or biometric information.
- "Customer" means the customer named in the Agreement.
- "Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under this DPA, including: (i) Regulation (EU) 2016/679 ("GDPR"); (ii) the United Kingdom General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"); (iii) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations ("CCPA/CPRA"); (iv) the Biometric Privacy Laws; (v) the Swiss Federal Act on Data Protection ("FADP"); and (vi) any other applicable laws regulating the processing of Personal Data.
- "Data Subject" has the meaning given in the GDPR (and equivalent meanings under other Data Protection Laws). "Controller", "Processor", "Processing", "Sub-processor", "Personal Data" and "Personal Data Breach" have correlative meanings.
- "EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as approved by Commission Implementing Decision (EU) 2021/914.
- "Palm Image" has the meaning given in the Terms of Use.
- "Palm Model" has the meaning given in the Terms of Use.
- "Privacy Policy" means VeryAI's Privacy Policy, as updated from time to time.
- "Pseudonymous Account Identifier" has the meaning given in the Terms of Use.
- "Restricted Transfer" means a transfer of Personal Data from a jurisdiction whose laws restrict the transfer of personal data to a third country (including from the EEA, the UK or Switzerland to a country not the subject of an adequacy decision).
- "Service" has the meaning given in the Terms of Use.
- "Terms of Use" means VeryAI's Terms of Use, as updated from time to time.
- "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
2. Scope; Roles; Subject Matter
2.1 Roles. With respect to Personal Data processed under the Agreement:
(a) Customer is the Controller (or, where Customer is itself a processor on behalf of an end-customer controller, the Customer is the processor and the end-customer controller is the Controller; references to Controller include such end-customer controller, and Customer warrants that it has the authority to instruct VeryAI on its behalf); and
(b) VeryAI is the Processor in respect of Personal Data processed on Customer's documented instructions.
2.2 Independent Controller. Notwithstanding Section 2.1, VeryAI acts as an independent Controller (and not as a Processor) only in respect of: (i) account creation and authentication of end users registering directly with VeryAI; (ii) fraud prevention, abuse prevention, liveness detection and security; (iii) compliance with VeryAI's legal and regulatory obligations; (iv) establishment, exercise or defence of legal claims; and (v) internal improvement of fraud-detection, liveness-detection, abuse-prevention, quality-assurance, debugging, audit and security mechanisms, only to the extent disclosed in the Terms of Use, the Privacy Policy and the in-app consent flow, and permitted by Applicable Law. Where VeryAI processes Personal Data as independent Controller, it does so under its own privacy notice and on its own lawful basis. For such processing, VeryAI is responsible for ensuring an appropriate lawful basis, transparency, and, where Article 22 GDPR applies to automated decisions with legal or similarly significant effects, a route to human review. VeryAI does not act as independent Controller for general product development or for training, fine-tuning or improvement of any third-party AI/ML model.
2.3 Subject Matter and Duration. The subject matter, duration, nature, purpose, categories of Personal Data and categories of Data Subjects are set out in Annex 1 (Description of Processing).
3. Customer Instructions; Compliance
3.1 VeryAI will process Personal Data only on the documented instructions of the Controller, including with regard to Restricted Transfers, except where required to do otherwise by Applicable Law (in which case VeryAI will inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest).
3.2 The Agreement, this DPA, the Customer's configuration of the Service and any further written instructions agreed between the Parties constitute the Controller's complete and final documented instructions. Additional or alternative instructions must be agreed separately and may be subject to additional fees.
3.3 VeryAI will inform the Controller without undue delay if, in VeryAI's reasonable opinion, an instruction infringes Data Protection Laws.
3.4 Customer Responsibilities. Customer represents, warrants and undertakes that it is, and at all times remains, solely responsible for:
- determining the lawfulness of its deployment and use case for the Service;
- providing all notices required by Data Protection Laws to Data Subjects (including notices required by Article 13 and 14 GDPR, the CCPA/CPRA and the Biometric Privacy Laws);
- obtaining all consents, written releases and authorisations required under Data Protection Laws and the Biometric Privacy Laws (including BIPA § 15(b) written release) from each Data Subject before any Biometric Data is collected through the Service, unless the Parties have expressly agreed in writing that VeryAI's standard in-app enrolment flow will collect such notices and consents on Customer's behalf;
- ensuring that any Customer decision using outputs of the Service has an appropriate lawful basis and complies with Data Protection Laws (including any human-review and Article 22 GDPR requirements applicable to that decision);
- handling user-facing rights processes (including rights of access, rectification, erasure, objection, restriction, portability, opt-out, limit-use and against automated decision-making) for any onboarding, access, financial-services, gaming, community-membership, employment, government or other eligibility decision made by Customer using the Service;
- not using the Service for one-to-many identification, surveillance, law enforcement, employment, credit, housing, education or other high-risk or sensitive use cases unless expressly authorised in the Agreement and supported by appropriate legal review by Customer; and
- Customer's own configuration, integration, security controls and access management in respect of the Service.
3.5 Compliance with Laws. Each Party will comply with the Data Protection Laws applicable to it. Customer warrants that the processing instructed by it has a valid legal basis and that any disclosures to VeryAI are made in compliance with Data Protection Laws.
4. Permitted Processing; Restrictions
4.1 VeryAI will process Personal Data only as necessary to provide the Service, in accordance with this DPA and the Agreement. VeryAI will not:
- sell Personal Data, share Personal Data for cross-context behavioural advertising, or rent, lease or otherwise commercially exploit Personal Data. For clarity, ordinary service fees payable by Customer for access to the Service are not consideration for the sale, lease, trade or disclosure of Personal Data or Biometric Data;
- retain, use or disclose Personal Data outside of the direct business relationship with Customer or for any purpose other than the specific purposes set out in this DPA, except as expressly permitted by Data Protection Laws;
- combine Personal Data received from Customer with personal information from other sources, except as permitted by the CCPA/CPRA and its implementing regulations or as strictly necessary to provide the Service; or
- use Personal Data or Biometric Data to train, fine-tune, adapt or improve any artificial intelligence, machine-learning, biometric or automated decisioning system, except for narrowly limited internal improvement of fraud-detection, liveness-detection, abuse-prevention, quality-assurance, debugging, audit and security mechanisms, in each case: (i) on VeryAI infrastructure only; (ii) not for the training, fine-tuning or improvement of any third-party AI/ML model; (iii) not for advertising or cross-context behavioural targeting; (iv) not resulting in the disclosure of underlying Biometric Data to Customers or third parties; and (v) only to the extent expressly authorised in the Agreement or Customer's documented instructions, disclosed in the Terms of Use, the Privacy Policy and the in-app consent flow, and permitted by Applicable Law.
4.2 No Sale; No Profit on Biometric Data. VeryAI does not sell, lease, trade or otherwise profit from Biometric Data. Ordinary service fees payable by Customer for access to the Service are not consideration for the sale, lease, trade or disclosure of Biometric Data.
4.3 CCPA/CPRA Service Provider Certification. VeryAI certifies that it understands the restrictions set out in this Section 4 and the CCPA/CPRA, and will comply with them. VeryAI is a "Service Provider" within the meaning of the CCPA/CPRA in respect of Personal Information processed under this DPA.
5. Confidentiality
5.1 VeryAI will ensure that all personnel and contractors authorised to process Personal Data are bound by appropriate written confidentiality obligations (or are subject to a statutory duty of confidence) and are made aware of the confidential nature of the Personal Data.
6. Sub-processors
6.1 General Authorisation. Customer provides VeryAI with general written authorisation to engage Sub-processors, subject to this Section 6.
6.2 Current List. VeryAI maintains a current list of Sub-processors (the "Sub-processor List"), with details required under the EU SCCs, available to Customer upon written request to legal@very.org. Notice of additions or replacements is provided in accordance with Section 6.3.
6.3 Notification of New Sub-processors. VeryAI will notify Customer of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance (or such shorter period as is reasonable in cases of urgent security need).
6.4 Right to Object; Limited Termination. Customer may, on reasonable grounds relating to the protection of Personal Data, object to the appointment of a new Sub-processor by written notice to VeryAI within thirty (30) days of notification. The Parties will discuss the objection in good faith. If the Parties cannot agree on a resolution and VeryAI cannot reasonably accommodate the objection (including by offering an alternative Sub-processor or technical workaround), Customer may terminate only the affected portion of the Service on written notice, with a pro-rata refund of any pre-paid, unused fees attributable to that affected portion of the Service for the period after termination. For the avoidance of doubt, Customer has no right to terminate any unaffected portion of the Service or the Agreement as a whole on this ground, and no other refund, credit, damages or liability arises in respect of an unaccommodated Sub-processor objection.
6.5 Sub-processor Obligations; Liability. VeryAI will impose data protection obligations on each Sub-processor that are no less protective of Personal Data than those in this DPA. VeryAI remains liable to Customer for the acts and omissions of its Sub-processors as if they were its own, subject to the limitations and exclusions of liability in the Agreement.
7. Security Measures
7.1 VeryAI will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the data, including the measures set out in Annex 2 (Technical and Organisational Measures) to the extent implemented and applicable to the Service. VeryAI will maintain the certifications (if any) expressly identified in the Agreement, and will make available current audit reports or equivalent assurance materials upon Customer's reasonable written request. VeryAI will not materially diminish its security posture without reasonable prior notice to Customer.
8. Personal Data Breach Notification
8.1 VeryAI will notify Customer without undue delay and, where reasonably practicable, within twenty-four (24) hours after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA. "Becoming aware" means VeryAI has a reasonable degree of certainty that a security incident has occurred which led to Personal Data being compromised.
8.2 The notification will include, to the extent then known and updated as further information becomes available: (i) the nature of the breach, including (where known) the categories and approximate number of Data Subjects and records affected; (ii) the contact details of VeryAI's security or data protection contact; (iii) the likely consequences of the breach; and (iv) the measures taken or proposed to address the breach and mitigate its possible adverse effects.
8.3 VeryAI will provide reasonable assistance to Customer in notifying competent supervisory authorities and Data Subjects where required by Data Protection Laws. Notification of a Personal Data Breach by VeryAI is not, and shall not be construed as, an acknowledgement of fault or liability by VeryAI.
9. Data Subject Requests; Cooperation
9.1 Taking into account the nature of the processing, VeryAI will assist Customer by appropriate technical and organisational measures, insofar as reasonably possible, to fulfil Customer's obligations to respond to Data Subject requests for the exercise of their rights. Where VeryAI receives a Data Subject request directly relating to Personal Data processed on Customer's behalf, VeryAI will promptly inform the Data Subject to address the request to Customer (or to VeryAI directly where VeryAI is the Controller for the relevant processing) and will not respond except on Customer's instructions or where required by Applicable Law.
10. Data Protection Impact Assessments; Prior Consultation
10.1 VeryAI will provide Customer with reasonable assistance with: (i) data protection impact assessments under Article 35 GDPR (and equivalent provisions); and (ii) prior consultations with supervisory authorities under Article 36 GDPR, in each case taking into account the nature of the processing and the information available to VeryAI.
11. International Data Transfers
11.1 Restricted Transfers. The Parties acknowledge that processing under the Agreement may involve Restricted Transfers. The Parties agree that the following transfer mechanisms apply, in each case to the extent the relevant mechanism is available and applies to the relevant transfer:
- EU SCCs. The EU SCCs are incorporated into this DPA and apply to Restricted Transfers from the EEA. The modules selected, and details of processing, are set out in Annex 4. Modules are selected by reference to the role of each Party in the relevant processing context (Controller-to-Processor, Processor-to-Sub-processor, or Controller-to-Controller, as applicable).
- UK Addendum. The UK Addendum is incorporated into this DPA and applies to Restricted Transfers from the United Kingdom.
- Swiss Amendments. For Restricted Transfers from Switzerland, the EU SCCs apply with the amendments set out in Annex 4.
- Adequacy. Where the receiving country benefits from an adequacy decision applicable to the relevant transfer, that mechanism may apply in addition to or instead of the SCCs as appropriate.
11.2 Transfer Impact Assessment. Where required by Data Protection Laws in connection with a Restricted Transfer, the Parties will co-operate in good faith to assess the lawfulness of the transfer, including by conducting or updating any required transfer impact assessment. VeryAI will provide reasonable information regarding its processing, transfer mechanism and supplementary measures, to the extent reasonably necessary for that assessment and taking into account the nature of the processing and the information available to VeryAI.
12. Audits; Inspections
12.1 VeryAI will make available to Customer, on reasonable written request, the information necessary to demonstrate compliance with this DPA and Article 28(3) GDPR. Customer's audit rights under this Section 12 are exercisable as set out below.
12.2 Tiered Assurance. Customer must, in the first instance, seek to satisfy its audit and information rights by relying on:
- current SOC 2 Type II reports, iBeta certification, GDPR compliance documentation, and equivalent third-party audit reports, in each case where available;
- penetration test summaries, where available;
- responses to standard written security questionnaires (including SIG or CAIQ); and
- VeryAI's written responses and reasonable supporting materials.
12.3 On-Site Audits. An on-site audit is permitted only as a last resort, and only where:
- the audit is required by Data Protection Laws or by a competent supervisory authority;
- the assurance materials referred to in Section 12.2 are demonstrably insufficient to address Customer's reasonable concerns;
- the audit is limited to systems, premises and records relevant to Customer Personal Data;
- the audit does not give access to (i) other customers' data, (ii) VeryAI source code, (iii) trade secrets or confidential information of VeryAI or its licensors, or (iv) highly sensitive security information whose disclosure could compromise the security of the Service;
- the audit is subject to strict written confidentiality obligations on Customer and any third-party auditor (who must not be a competitor of VeryAI);
- the audit is conducted no more than once in any twelve (12) month period, except where required following a confirmed Personal Data Breach affecting Customer Personal Data or by a competent supervisory authority;
- the audit is on at least thirty (30) days' prior written notice (except where a shorter period is required by Data Protection Laws or a regulator) and does not unreasonably interfere with VeryAI's operations; and
- Customer bears VeryAI's reasonable costs (at VeryAI's standard rates) for any on-site audit and any unusually burdensome assistance.
13. Return; Deletion
13.1 VeryAI will handle Biometric Data and other Personal Data in accordance with the Terms of Use, the Privacy Policy and the applicable Customer configuration, including:
- Palm Images: captured during enrolment and re-enrolment and processed to derive the Palm Model. A low-resolution Audit Image derived from the palm may be embedded in the Palm Model and separately retained (see Audit Images below). Ordinary palm verification/sign-in does not capture or store an image;
- Audit Images: retained for up to one hundred eighty (180) days in VeryAI's working store, except that Audit Images arising from flagged or rejected enrolments may be retained for a longer period for model-quality and fraud-detection analysis, in each case in accordance with the Privacy Policy and VeryAI's biometric retention policy;
- Palm Models: retained in accordance with the Privacy Policy, the Terms of Use and the applicable Customer configuration; and
- Other Personal Data: retained for the periods set out in the Privacy Policy.
13.2 Return or Deletion on Termination. On termination or expiration of the Agreement, or following a verified erasure request, VeryAI will, at the Controller's election, delete or return end-user Biometric Data (Palm Models) and other Personal Data processed on its behalf under this DPA from production systems within ninety (90) days, following a grace period of up to ninety (90) days during which erasure remains reversible, except: (i) where retention is required by Applicable Law (in which case VeryAI will continue to protect the data and limit further processing to that retention purpose); (ii) Pseudonymous Account Identifiers and transaction metadata, which may be retained for the periods stated in the Privacy Policy for audit, security and legal purposes; and (iii) encrypted, access-restricted backup archives, which will not be restored except for disaster recovery, legal or security purposes, and which are overwritten in the ordinary course as part of VeryAI's standard backup rotation and expiry cycle. Where return is requested, the Parties will agree a secure method and format for return, taking into account technical feasibility, the sensitivity of the Personal Data and the security of the Service. VeryAI will provide written certification of deletion on the Controller's reasonable written request. For clarity, this Section 13.2 applies only to Personal Data processed by VeryAI as Processor on behalf of Customer. Personal Data processed by VeryAI as independent Controller is retained and deleted in accordance with the Privacy Policy, the Terms of Use and Applicable Law.
14. Liability; Indemnification
14.1 Liability under this DPA. Each Party's liability arising out of or relating to this DPA, whether in contract, tort, breach of statutory duty or otherwise, is subject to and forms part of the aggregate limitations of liability, exclusions and disclaimers set out in the Agreement, except where, and to the extent that, applicable Data Protection Laws (including Article 82 GDPR) require otherwise. Nothing in this DPA limits or excludes liability that cannot be limited or excluded by Applicable Law.
14.2 VeryAI Indemnity. VeryAI will indemnify Customer against third-party claims to the extent finally determined (by a court of competent jurisdiction or arbitral tribunal, or by settlement agreed in writing by VeryAI) to have resulted from VeryAI's material breach of this DPA. The indemnity in this Section 14.2: (i) applies only to third-party claims; (ii) is subject to the liability cap, exclusions and disclaimers in the Agreement; and (iii) does not apply to the extent any loss, damage, claim or liability arises from or is caused by (A) Customer's instructions or configuration, (B) Customer's deployment, integration or use of the Service, (C) Customer's failure to establish a lawful basis or to obtain required notices, consents, written releases or authorisations, (D) Customer's misuse of the Service, or (E) Customer's use of Service outputs to make any onboarding, access, financial-services, gaming, community, employment, government or other eligibility decision.
14.3 Customer Indemnity. Customer will indemnify, defend and hold harmless VeryAI, its affiliates and their respective officers, directors, employees and agents against all claims, damages, losses, costs and expenses (including reasonable legal fees) arising out of or relating to: (i) Customer's instructions that infringe Data Protection Laws or any other Applicable Law; (ii) Customer's breach of its representations, warranties or obligations under this DPA, including under Section 3.4 (Customer Responsibilities); (iii) Customer's failure to provide the notices, consents, written releases or authorisations required under Data Protection Laws or the Biometric Privacy Laws; (iv) Customer's deployment of the Service in a manner not expressly authorised in the Agreement or for any high-risk use case not approved in writing by VeryAI; and (v) any decision made by Customer using outputs of the Service, including onboarding, access, financial-services, gaming, community, employment, government or other eligibility decisions.
15. Term; Survival
15.1 This DPA takes effect on the Effective Date and continues for the duration of the Agreement.
15.2 Sections 1 (Definitions), 2.2 (Independent Controller), 4 (Permitted Processing; Restrictions), 5 (Confidentiality), 11 (International Data Transfers) (to the extent of any continuing transfers), 12 (Audits; Inspections) (to the extent of any retained Personal Data), 13 (Return; Deletion), 14 (Liability; Indemnification), this Section 15.2, and Section 16 (General) will survive termination or expiration of this DPA.
16. General
16.1 Order of Precedence. In the event of conflict, the order of precedence is: (i) the EU SCCs (where applicable to the relevant transfer); (ii) the UK Addendum (where applicable to the relevant transfer); (iii) this DPA; (iv) the Agreement.
16.2 Governing Law; Forum. Except where the EU SCCs or the UK Addendum require otherwise, this DPA is governed by, and subject to the courts and dispute resolution mechanism specified in, the Agreement. Where the Agreement is VeryAI's standard form, this DPA is governed by the laws of the Cayman Islands and any dispute is subject to arbitration administered by the London Court of International Arbitration in accordance with the dispute resolution provisions of the Agreement, save that nothing in this DPA limits the rights of Data Subjects or supervisory authorities to bring proceedings in the forum required by Data Protection Laws.
16.3 Severability; Variation. If any provision of this DPA is held unenforceable, the remainder will continue in full force. This DPA may be varied only by written agreement signed by both Parties (or, where required by Data Protection Laws or to reflect updated regulatory requirements, by VeryAI on reasonable notice to Customer).
16.4 Entire Agreement on Data Protection. This DPA, together with its Annexes, sets out the Parties' entire agreement on the processing of Personal Data under the Agreement and supersedes all prior data-protection arrangements between them.
Annex 1 — Description of Processing
Parties. Data Exporter / Controller: Customer (and, where applicable, Customer's end-customer controller). Contact: [as set out in the Agreement]. Data Importer / Processor: Veros Inc, an exempted company incorporated with limited liability in the Cayman Islands with registration number OS-420535, doing business as VeryAI. Contact: legal@very.org. Activities: provision of palm-recognition biometric verification services (the Service).
Categories of Data Subjects. Customer's end users who enrol in and use the Service.
Categories of Personal Data. Palm Images: captured during enrolment and re-enrolment and processed to derive the Palm Model. A low-resolution Audit Image derived from the palm may be embedded in the Palm Model and separately retained (see Audit Images below). Ordinary palm verification/sign-in does not capture or store an image. Palm Models (stored as Biometric Data); Audit Images (where retained): limited, low-resolution images, crops or derived visual records of a palm capture, retained for up to one hundred eighty (180) days in VeryAI's working store for security, fraud prevention, liveness detection, quality assurance, debugging, audit and abuse-prevention purposes; Audit Images arising from flagged or rejected enrolments may be retained for a longer period for model-quality and fraud-detection analysis (including the development and evaluation of VeryAI's own detection models); Audit Images may be processed by the third-party AI/model providers identified in Annex 3 for classification purposes. Audit Images and Palm Models are treated as Biometric Data and/or sensitive personal information where required by Applicable Law; Pseudonymous Account Identifiers; authentication and activity logs; device information; and (optional) email addresses for account recovery and important Service communications.
Special Categories of Data. Biometric Data within the meaning of Article 9(1) GDPR. Processed only on the basis of the Data Subject's explicit consent under Article 9(2)(a) GDPR (and/or for the establishment, exercise or defence of legal claims under Article 9(2)(f) GDPR), in addition to the relevant Article 6 basis.
Allocation of consent responsibility. Customer is responsible for ensuring that each Data Subject receives all notices and provides all consents, written releases and authorisations required under Data Protection Laws, including the Biometric Privacy Laws, unless the Parties have expressly agreed in writing that VeryAI's standard in-app enrolment flow will collect such notice and consent on Customer's behalf.
Frequency. Continuous, in connection with each enrolment and authentication event.
Nature and Purpose of Processing. Capture and processing of Palm Images to derive the Palm Model; generation, encryption and storage of Palm Models; comparison of Palm Models for authentication; retention and use of Audit Images (including low-resolution images embedded in or derived from Palm Models) for security, fraud prevention, liveness detection, quality assurance, debugging, audit and abuse-prevention purposes, including classification by third-party AI/model providers, in accordance with the Terms of Use and the Privacy Policy; transmission of Pseudonymous Account Identifier and verification result to Customer integrations on Data Subject authorisation; logging for security and audit; compliance with VeryAI's legal obligations.
Duration of Processing. For the term of the Agreement, plus the retention periods set out in the Privacy Policy.
Recipients. Sub-processors listed in Annex 3; competent authorities to the extent required by Applicable Law; Customer integrations to the extent of authenticated metadata only (Pseudonymous Account Identifier; verification timestamp; verification result; and any specifically authorised attributes).
Annex 2 — Technical and Organisational Measures
VeryAI implements the following measures, in each case where implemented and as described in the applicable security documentation referenced in the Agreement (and subject to update from time to time, provided that the overall level of protection is not materially diminished).
Encryption. TLS 1.2+ for external network traffic (certain internal system connections may not be TLS-encrypted); encryption at rest using the cloud infrastructure provider's default disk encryption (provider-managed keys); Palm Models are stored as a non-reversible mathematical/cryptographic representation of the palm, except that a low-resolution Audit Image may be embedded in or separately associated with the Palm Model as described in Annex 1 and Section 13.1.
Network and Infrastructure Security. Dedicated virtual private cloud / network environments; firewalls; intrusion detection or equivalent; protections against denial-of-service attacks; regular vulnerability scanning.
Access Controls. Role-based access control on a least-privilege basis; multi-factor authentication for internal access to systems processing Personal Data; periodic access reviews.
Data Segregation. Palm Models and any retained Audit Images stored in an isolated, encrypted biometric environment, segregated from non-biometric account data.
Personnel. Written confidentiality and acceptable-use agreements with personnel processing Personal Data; US Criminal background checks on personnel with access to Personal Data; privacy and security training at hire and periodically thereafter.
Logging and Monitoring. Logging of access to systems processing Personal Data; documented incident response procedures.
Resilience and Continuity. Documented business continuity and disaster recovery plans with recovery point objectives (RPO) and recovery time objectives (RTO) as set out in VeryAI's applicable policies and tested in accordance with those policies; routine encrypted backups.
Vendor Management. Due diligence on Sub-processors; written data protection contracts with Sub-processors; ongoing monitoring.
Independent Assurance. SOC 2 Type II — achieved. iBeta — achieved. GDPR compliant. Independent penetration testing — in progress.
Schrems II Supplementary Measures (where applicable). Contractual measures (transparency around government access requests; challenge of disproportionate requests); technical measures (encryption with key management arrangements as set out in the applicable security documentation); and organisational measures.
Annex 3 — Sub-processors
VeryAI maintains the current list of Sub-processors, including their name, location, role and processing activity, available to Customer upon written request to legal@very.org. Customer is deemed to have consented to the Sub-processors listed at the Effective Date and to additions made in accordance with Section 6. As of the Effective Date, VeryAI's Sub-processors are set out in the table below.
| Sub-processor | Purpose | Data Received | Region |
|---|---|---|---|
| Google Cloud (Google LLC) | Hosting (GKE), object storage (audit images), database backups | Account data, IP address/user-agent, palm Audit Images | United States |
| OpenRouter, Inc. | LLM gateway for Audit Image classification | Palm Audit Images | United States |
| OpenAI, L.L.C. | Audit Image fraud/quality classification (GPT-4.1) | Palm Audit Images | United States |
| Google LLC (Gemini API) | Audit Image classification (Gemini 2.5 Flash) | Palm Audit Images | United States |
| Amazon Web Services, Inc. (SES) | Transactional email | Email addresses | United States |
| Privy (Stel Labs, Inc.) | Embedded wallet provisioning | Per-user identifiers, wallet records | United States |
| Google (Firebase FCM + Analytics) | Push notification delivery and mobile analytics | Push tokens, device/usage data | United States |
| Mixpanel, Inc. | Product analytics | App events, user identity/properties | United States |
| RedRock Biometrics | Palm-model native technology (in-process); license validation | Biometric data processed in-process; build-time license key fetch | United States |
This table reflects VeryAI's Sub-processors as of the Effective Date and is provided for convenience; the authoritative, current list is available upon request as described above.
Annex 4 — EU SCCs Module Selection; UK Addendum; Swiss Amendments
EU SCCs. The Parties incorporate the EU SCCs into this DPA. Modules are selected by reference to the role of each Party in the relevant processing context:
- where Customer is the Controller, Module Two (Controller-to-Processor) applies;
- where Customer is itself a Processor on behalf of an end-customer Controller, Module Three (Processor-to-Sub-processor) applies; and
- where Personal Data is transferred to VeryAI for processing in its capacity as independent Controller (as set out in Section 2.2 of this DPA), Module One (Controller-to-Controller) applies in respect of that processing.
Where multiple modules apply because Personal Data is processed in more than one capacity, each module applies to the relevant processing.
Clause 7 (docking clause): selected, allowing additional parties to accede.
Clause 9 (sub-processors): Option 2 (general written authorisation), with a notice period of 30 days, as set out in Section 6.
Clause 11(a) (independent dispute resolution body): optional language not selected.
Clause 17 (governing law): the law of the Republic of Ireland applies.
Clause 18(b) (forum): the courts of the Republic of Ireland.
Annex I.A: as set out in Annex 1 above. Annex I.B: as set out in Annex 1 above. Annex I.C: the competent supervisory authority shall be determined in accordance with Clause 13 of the EU SCCs and applicable Data Protection Laws. The Parties make no representation that any particular supervisory authority is the lead supervisory authority for VeryAI under Article 56 GDPR. Annex II: as set out in Annex 2 above. Annex III: as set out in Annex 3 above.
UK Addendum. Tables 1–3 of the UK Addendum are completed by reference to Annexes 1, 2 and 3 above. Table 4: neither Party may end the UK Addendum under Section 19 of Part 2 of the UK Addendum.
Swiss Amendments. Where applicable, references in the EU SCCs to: (i) the GDPR include the FADP; (ii) the European Commission include the Swiss Federal Data Protection and Information Commissioner; (iii) Member State courts include Swiss courts; and (iv) Article 79 GDPR include the FADP equivalent. Data Subjects whose habitual residence is in Switzerland may exercise their rights in their place of habitual residence.
Annex 5 — EU AI Act Allocation
Purpose; No legal determination. This Annex 5 is for allocation purposes only and is not a legal determination or an admission of any classification under Regulation (EU) 2024/1689 (the "EU AI Act"). The classification of the Service, and the role of each Party, under the EU AI Act depends on the actual deployment context, intended purpose, Customer use case, technical configuration, the terms of the Agreement and applicable guidance from competent authorities.
Current understanding. VeryAI's current understanding is that one-to-one biometric verification used solely to confirm that a specific person is who they claim to be is generally treated differently under the EU AI Act from remote biometric identification, and that pure one-to-one verification scenarios may fall outside the "remote biometric identification" category referenced in Annex III. This is a statement of VeryAI's current understanding only and may change as guidance evolves.
Customer deployment risks. Customer acknowledges that deployments in contexts such as critical infrastructure, essential public or private services, financial onboarding, law enforcement, migration / border / asylum, employment, education, credit, housing or one-to-many identification scenarios may trigger additional provider or deployer obligations under the EU AI Act and/or other Applicable Law. Customer is solely responsible for assessing those obligations in respect of its deployment.
Customer covenants. Customer must not deploy the Service in a manner that: (i) changes its intended purpose as described in the Agreement and the Terms of Use; (ii) creates a prohibited use case under the EU AI Act or other Applicable Law; or (iii) materially changes the risk classification of the Service, in each case without VeryAI's prior written consent. Customer will use the Service in accordance with VeryAI's instructions for use and will not modify the Service in a manner that would alter its intended purpose without VeryAI's prior written consent.
Role allocation. Any allocation of "provider" and "deployer" obligations under the EU AI Act between VeryAI and Customer will be addressed in the Agreement or in a separate AI Act Schedule, and not in this Annex 5. To the extent VeryAI is determined to be the provider of a high-risk AI system in respect of the Service, VeryAI will provide instructions for use, technical documentation extracts and information reasonably necessary to enable Customer's deployer obligations under Article 26 of the EU AI Act, to the extent and at the time those obligations apply.