Data Processing Agreement

Summary of the processing terms that apply when Vorentus processes personal data on behalf of a client. The operating entity is currently in the process of incorporation; the signable contractual version, including the entity's full identification and agreed contractual timeframes, will be provided during contracting after incorporation.

Roles

The client is the controller of personal data it enters or authorises in the platform. Vorentus acts as processor for that data, and as controller for commercial contact and account data.

Instructions and purposes

Vorentus processes data only on documented client instructions, to deliver the contracted service: establishing verified facts, observing AI environments, comparing answers, generating alerts and supporting decisions.

Minimisation

Clients must not enter special categories of data, children's data, identification documents or personal financial information. Content sent to AI providers is limited to what the test requires.

Security and isolation

Encryption in transit and at rest, authentication, per-organisation access control and least privilege. See the Security page.

Subprocessors

Subprocessor list. Changes are announced with reasonable notice, with a right to reasoned objection.

Rights, breaches and deletion

Vorentus assists the client with data subject requests, notifies data breaches without undue delay after becoming aware, and on termination returns or deletes data as instructed, subject to legal retention obligations.

Specific contractual timeframes will be defined in the signable DPA applicable to each contractual relationship; this public summary does not state timeframes that have not yet been formally agreed.