Legal
Data Processing Addendum
This Data Processing Addendum governs Virent’s processing of personal data on behalf of a customer using the Services.
Effective July 22, 2026
Application and incorporation
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement between Virent and Customer (the “Agreement”) when Virent processes Customer Personal Data as a processor or service provider. It is effective when Customer accepts the Agreement or the parties reference it in an order form.
Capitalized terms not defined here have the meaning in the Agreement. If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA controls.
Definitions
- “Applicable Data Protection Law” means privacy and data protection law applicable to the processing, including Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, Brazil’s Lei Geral de Proteção de Dados Pessoais (Law No. 13,709/2018 or LGPD) and ANPD regulations, applicable United States state privacy laws, and implementing or successor regulations.
- “Customer Personal Data” means personal data contained in Customer Data that Virent processes on Customer’s behalf.
- “Controller,” “processor,” “controlador,” “operador,” “business,” “service provider,” “consumer,” “data subject,” “titular,” “personal data,” “process,” “processing agent,” and “supervisory authority” have the meanings given by Applicable Data Protection Law.
- “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts that do not compromise data.
- “Subprocessor” means a third party engaged by Virent to process Customer Personal Data.
Roles and processing instructions
Customer is the controller, controlador, or business and Virent is the processor, operador, or service provider, except where Customer acts as a processor or operador for another controller, in which case Virent is Customer’s subprocessor or suboperator. Customer is responsible for its instructions, lawful basis, notices, consents, data-subject choices, records of processing, and the legality of Customer Personal Data.
Virent will process Customer Personal Data only on Customer’s documented instructions, including the Agreement, Customer’s configuration and use of the Services, and other written instructions consistent with the Agreement. Virent will notify Customer if it believes an instruction violates Applicable Data Protection Law, unless prohibited from doing so.
Processing details
Subject matter and duration
Providing, securing, supporting, and improving the contracted Services for the term of the Agreement and the deletion period described below.
Nature and purpose
Hosting, collecting, organizing, classifying, querying, comparing, transmitting, securing, and deleting Customer Personal Data to provide human analytics, crawler analytics, LLM visibility, prompt and citation tracking, integrations, reporting, and support selected by Customer.
Categories of data
- Account identifiers and business contact information.
- Online identifiers, pseudonymous IDs, device or browser context, referral information, event and conversion data.
- Request URL, user-agent, response metadata, timestamps, bot classification, and derived or transient network context.
- Prompts, answers, mentions, citations, domains, competitor information, annotations, and configuration data.
- Support content and any other personal data Customer chooses to submit consistently with the Agreement.
Data subjects
- Customer’s authorized users, personnel, contractors, prospects, and contacts.
- Visitors and users of Customer-controlled websites or applications.
- Individuals referenced in Customer-submitted prompts, content, support requests, or public-source analysis.
Sensitive data
The Services are not designed for sensitive personal data. Customer will not submit special-category data, protected health information, payment-card data, government identifiers, precise location, passwords, or similar sensitive data unless the parties expressly agree in writing to additional safeguards.
Virent obligations
- Ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
- Implement and maintain technical and organizational measures appropriate to the risk.
- Assist Customer, taking into account the nature of processing and information available to Virent, with data-subject requests, security, breach notifications, impact assessments, and regulator consultations required by Applicable Data Protection Law.
- Make information reasonably necessary to demonstrate compliance with this DPA available to Customer.
- Not sell Customer Personal Data, share it for cross-context behavioral advertising, retain, use, or disclose it outside the business purposes in the Agreement, or combine it with personal data from other sources except as permitted for a service provider by applicable law.
Security measures
Virent will maintain safeguards appropriate to the Services, processing scope, and risk. Measures may evolve without materially reducing the overall level of protection during a paid subscription term.
- Access controls based on role and need, authentication protections, and protected production credentials.
- Encryption in transit using current industry-standard transport protocols and encryption at rest where supported by the applicable storage layer.
- Data minimization, pseudonymous identifiers where appropriate, separation of customer workspaces, and controls intended to prevent unauthorized access.
- Logging, monitoring, vulnerability and dependency management, backup and recovery practices, and documented incident response.
- Vendor review and contractual data-protection obligations for relevant Subprocessors.
- Secure development, change review, and testing practices proportionate to the risk of the change.
Subprocessors
Customer gives Virent general authorization to engage Subprocessors needed to provide the Services. Virent remains responsible for each Subprocessor’s performance of data protection obligations to the extent required by Applicable Data Protection Law and will impose written obligations that provide materially similar protection.
Virent will provide a current Subprocessor list on request and, for customers with a paid order form, notice of a new Subprocessor before it processes Customer Personal Data where required. Customer may object on reasonable data-protection grounds by emailing virent.app@gmail.com within 15 days of notice. The parties will work in good faith on a commercially reasonable solution; if none is available, either party may terminate the affected Service.
Data-subject requests
Taking into account the nature of processing, Virent will provide reasonable assistance for Customer to respond to requests to confirm processing; access, correct, anonymize, block, delete, restrict, object to, or port Customer Personal Data; obtain information about sharing; withdraw consent; or exercise rights related to qualifying automated decisions. If Virent receives a request directly, it will direct the requester to Customer unless law requires another response. Customer is responsible for responding within applicable time limits and for using available Service controls before requesting additional assistance.
Security Incidents
Virent will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notice will be sent to Customer’s account contact or virent.app@gmail.com correspondence channel and will include available information reasonably needed for Customer’s obligations, such as the nature of the incident, affected data, likely consequences, and mitigation. Virent may provide information in phases as it becomes available.
Virent’s notice or response is not an admission of fault or liability. Customer is responsible for notices to individuals, regulators, or others unless law assigns that duty to Virent. This includes, where the Customer is a Brazilian controlador and the legal threshold is met, notice to the ANPD and affected data subjects within the period required by ANPD rules, currently three business days under Resolution CD/ANPD No. 15/2024.
Deletion and return
During the term, Customer may use available export and deletion controls. After termination or a valid written request, Virent will delete or return Customer Personal Data within a commercially reasonable period unless law requires retention. Data may remain temporarily in protected backups until overwritten under normal cycles and will remain subject to this DPA. Virent may retain de-identified data that cannot reasonably be linked to Customer or an individual.
Audits and compliance information
Virent will respond to reasonable written security and compliance questionnaires and provide available independent reports or summaries under confidentiality where appropriate. If that information is insufficient, Customer may request an audit no more than once per year, or after a Security Incident, by an independent auditor bound by confidentiality. Audits must be coordinated in advance, avoid disruption, protect other customers, and be at Customer’s expense unless the audit identifies a material breach by Virent. No audit may provide access to another customer’s data, penetration-test production without written approval, or compromise security.
International transfers
When Virent transfers Customer Personal Data from the EEA, United Kingdom, or Switzerland to a country without an applicable adequacy decision, the parties incorporate the legally required transfer mechanism. For EEA transfers, this includes the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914, using Module Two or Module Three as appropriate. For UK transfers, the applicable UK Addendum is incorporated. Swiss law adaptations apply where required.
The information in this DPA and the Agreement completes the relevant annexes: Customer is the exporter, Virent is the importer, the processing details appear above, the competent authority and governing law are selected as required by the applicable clauses, and the security measures are described in this DPA. If the transfer clauses conflict with this DPA, the transfer clauses control.
For a transfer of Customer Personal Data from Brazil that requires contractual safeguards, the parties will use the Brazilian standard contractual clauses in Annex II to ANPD Resolution CD/ANPD No. 19/2024 in full and without modification, or another transfer mechanism valid under the LGPD. The parties’ identities, roles, transfer description, security measures, and contact channels will be completed from this DPA and the applicable order form. The mandatory Brazilian clauses control over conflicting terms. Virent will reasonably assist Customer with the transparency information and copy of transfer clauses that the LGPD and ANPD rules require.
Jurisdiction-specific terms
EEA
Article 28 GDPR requirements apply where relevant. Virent will assist with data-subject rights, security obligations, data protection impact assessments, and prior consultations, taking into account the nature of processing and information available to Virent. The applicable EU SCC module and supervisory authority are determined by the parties’ roles and the data exporter’s establishment.
United Kingdom and Switzerland
References to GDPR obligations include the corresponding UK GDPR or Swiss requirements where applicable. Restricted UK transfers use the UK International Data Transfer Agreement or the approved UK Addendum to the EU SCCs, as appropriate. Swiss transfers use the EU SCCs with adaptations required by Swiss law where permitted.
Brazil
For LGPD-covered processing, Customer is the controlador and Virent is the operador unless the facts require another classification. Virent will follow Customer’s lawful instructions, maintain security and governance measures appropriate to risk, assist with titular requests and impact assessments, and provide information reasonably necessary for Customer’s accountability obligations. Customer remains responsible for selecting a lawful basis, meeting transparency duties, responding to titulares, and making required communications to the ANPD.
United States
Where state privacy law applies, Virent acts as a service provider, contractor, or processor for Customer Personal Data; processes it only for the limited and specified purposes in the Agreement; does not sell it or share it for cross-context behavioral advertising; and will provide the same level of privacy protection required by applicable law. Customer may take reasonable steps to verify compliant use and require remediation of unauthorized use.
Liability, term, and contact
Each party’s liability under this DPA is subject to the exclusions and limitations in the Agreement to the extent permitted by law. This DPA remains in effect while Virent processes Customer Personal Data. Changes required by law may take effect upon notice; other material changes require agreement where applicable.
Data protection questions, requests for the Subprocessor list, and DPA notices should be sent to virent.app@gmail.com.