Verdict Labs, Inc. · Version 2.0
Data Processing Addendum
Effective 16 August 2026 for Accounts created on or after that date. For an Account created before it, this version takes effect thirty (30) days after Verdict gives notice of it, and until then the version in force when the Account was created continues to apply. That version is at useverdict.io/legal/dpa/v1.
This Data Processing Addendum (the “Addendum”) forms part of the Terms of Service between Verdict Labs, Inc., a Delaware corporation (“Verdict”), and the customer that accesses or uses the Service (“Customer”). It governs the processing of personal data in connection with the Service. Capitalized terms not defined here have the meanings given in the Terms of Service. Where this Addendum conflicts with the Terms of Service in respect of the processing of personal data, this Addendum prevails.
Requests for an executed counterpart, a customer-specific addendum, or transfer documentation may be sent to legal@useverdict.io.
Roles of the Parties
1.1 Customer as controller. In respect of personal data contained in Customer Content, including personal data relating to founders, portfolio contacts, and other individuals identified in documents Customer submits, Customer is the controller and Verdict is the processor. Verdict processes that personal data only on Customer’s documented instructions, which comprise the Terms of Service, this Addendum, and Customer’s use of the features of the Service.
1.2 Verdict as controller. In respect of account registration data, billing data, and operational telemetry generated by Customer’s use of the Service, Verdict is a controller in its own right. That processing is described in the Privacy Policy.
1.3 Unlawful instructions. Verdict will inform Customer if, in Verdict’s opinion, an instruction infringes applicable data protection law. Verdict is not obliged to conduct a legal review of the lawfulness of Customer’s instructions.
1.4 Customer responsibilities. Customer is responsible for establishing a lawful basis for submitting Customer Content to the Service, for providing any notice required to the individuals whose personal data it contains, and for the accuracy of the personal data it submits.
Subject Matter, Duration, Nature, and Purpose
2.1 Subject matter. The processing consists of the hosting, storage, and automated analysis of documents and profile information submitted by Customer, and the generation, storage, and delivery of the resulting written analysis.
2.2 Duration. Processing continues for the term of the Terms of Service and for the retention periods stated in section 4 of this Addendum.
2.3 Nature and purpose. Personal data is processed for the sole purpose of providing, securing, and operating the Service for Customer. Verdict does not process Customer Content for its own commercial purposes, for advertising, or for profiling unrelated to the Service.
Categories of Data and Data Subjects
3.1 Categories of personal data. The personal data processed under this Addendum is determined by what Customer chooses to submit. It typically includes:
- identifiers and professional information appearing in uploaded documents, such as names, roles, biographies, and contact details of company founders and team members;
- publicly available professional information retrieved from public sources during research, where Customer enables that feature;
- names and links relating to investment professionals that Customer enters for research purposes; and
- any additional personal data Customer includes in written context, profile fields, or submitted corrections.
3.2 Categories of data subjects. Company founders and employees, investment professionals, and other individuals identified in the material Customer submits.
3.3 Special categories. The Service is not designed for, and Customer must not submit, special categories of personal data within the meaning of Article 9 of the GDPR, personal data relating to criminal convictions, government identification numbers, financial account numbers, or health information.
Retention, Deletion, and Return
4.1 Deletion by Customer. Customer may delete an individual report at any time from the report list in the dashboard. The report record is deleted immediately and the associated deck file is removed from storage as part of the same operation. Removal of the stored file is attempted immediately after the record is deleted. Where the storage provider does not confirm removal, the record is deleted regardless and the file remains in storage with no reference to it. Verdict does not presently operate a process that identifies such files. Verdict removes them on becoming aware of them. A financial model uploaded alongside a deck is not removed by this operation. It is removed by the scheduled deletion described in sections 4.2 and 4.3, which reaches it on its own account; Customer requiring a financial model to be deleted before that point should request it under section 4.10.
4.2 Standard retention. A report, its associated deck file, and any financial model uploaded with it are retained for ninety (90) days from creation and are then deleted by a scheduled job that runs every hour. Operational telemetry and any generated coaching material associated with the report are deleted at the same time. The job processes a bounded number of records per run, so where a large volume becomes eligible at once, deletion of the remainder completes over subsequent hourly runs. Ninety days is therefore the minimum retention period rather than a guaranteed deletion date.
4.3 Sensitive retention level. Where Customer marks an upload as “Sensitive” on the upload form, the deck file and any financial model uploaded with it are deleted from storage within twenty-four (24) hours of being uploaded. The period runs from the upload itself, and nothing that happens afterwards extends it: re-running the analysis, resuming it, and opening the report each leave the deletion time where it was. The period applies whether or not the analysis completed, so a file belonging to a failed or abandoned analysis is deleted on the same basis as one belonging to an analysis that succeeded. Each file is reached on its own account, so a financial model is deleted on this period whether or not the deck file it accompanied is still held. Deletion is carried out by the job described in section 4.2, which runs every hour and takes files more than twenty-three (23) hours old, so that removal falls inside the twenty-four hour period rather than at its edge. The generated report is retained for the period that applies to it under section 4.2.
4.3.1 Limits of the Sensitive level. Two limits apply, both concerning copies, and are stated because a Customer would otherwise plan around a shorter period than the Service delivers. First, where Customer starts a new analysis of the same company by uploading the deck again, that upload is stored as a separate copy with its own period running from its own upload, so one copy may remain in storage after another has been deleted. Second, where the restart of a failed analysis reuses the stored copy already held, that copy is removed only once every report referring to it has reached the end of its own period, which can hold the copy beyond twenty-four hours from the upload. Verdict removes a shared copy late rather than early, because removing it early would take a file away from a report that is still inside its own period. Both limits apply to a financial model on the same terms as to a deck file; a restarted analysis reuses the model already held exactly as it reuses the deck file. A Customer requiring a file to be removed at a fixed time regardless of the number of copies should delete each report directly under section 4.1.
4.4 Submitted corrections. Corrections Customer submits through the in-product feedback control, comprising the substituted conclusion, the written reason, and derived category labels, are not deleted by the periods in section 4.2, because they calibrate later analysis for Customer’s own Account. They are retained for the shorter of seven (7) years from creation or the closure of the Account. The reference linking a correction to the report that prompted it is severed when that report is deleted, so the correction is no longer associated with a specific upload. Customer may request deletion of these records at any time under section 4.10.
4.5 Derived records. Two further categories of record outlive the report that produced them, on the same basis as section 4.4 and subject to the same limits. The first is the set of findings Verdict records at the end of an analysis and reads on later analyses for the same Account, so that recurring errors are caught. The second is a store of prose drawn from reports generated for the Account, which is used to keep the wording of later reports consistent with earlier ones. Both are scoped to the Account, both have the reference to the originating report severed when that report is deleted, and both are removed when the Account is closed under section 4.7.
4.6 Longer or shorter retention. Customer requiring retention of a specific report beyond the period that applies to it under section 4.2 should export it, or contact Verdict before the period expires. Customer requiring shorter retention should use the Sensitive level or delete the report directly.
4.7 Account closure. Customer may close its Account by writing to legal@useverdict.io from the address associated with the Account. Access to the Account is revoked immediately on closure. A share link or co-investor link Customer generated before closure may remain readable, and Customer should revoke any such link before closing the Account. Verdict deletes the fund or fundraise profile, the generated reports, the uploaded deck files, any uploaded financial model, the submitted corrections, and the derived records described in sections 4.4 and 4.5, within thirty (30) days of the request, and confirms completion by reply. Deletion on closure is carried out by Verdict rather than by a scheduled process.
4.8 Records Verdict must keep. Records of payment held by Verdict’s payment processor are retained on that provider’s schedule and for the period required by applicable tax and accounting law. Deleted records may persist in routine infrastructure backups until those backups expire in the ordinary course.
4.9 Return on termination. Customer may export its reports from the Service to PDF at any time before closure, and that is the only export function the Service provides. On written request made before deletion is carried out, Verdict will provide a copy of the personal data it processes on Customer’s behalf. That copy is assembled by hand rather than produced by the Service, and Verdict does not presently commit to a structured or machine-readable format for it. Customer requiring a particular format should agree it with Verdict in writing before relying on it.
4.10 Deletion of specific items. Customer may request deletion of a specific report, deck file, financial model, submitted correction, or derived record, without closing its Account, by writing to legal@useverdict.io from the address associated with the Account. Verdict carries out the deletion within thirty (30) days of the request and confirms completion by reply. Deletion under this section is carried out by Verdict rather than by a scheduled process. A report may also be deleted directly by Customer at any time under section 4.1.
Security Measures
5.1 Technical and organizational measures. Verdict maintains the measures described in this section, which take into account the state of the art, the costs of implementation, and the nature and risk of the processing. The measures may be updated, provided the level of security is not materially reduced.
5.2 Encryption. Deck files held in object storage are encrypted at rest using AES-256. Traffic between Customer and the Service, and between the Service and its Sub-processors, is encrypted in transit using TLS 1.2 or higher. Payment card details are submitted directly to the payment processor through tokenized checkout and do not reach Verdict infrastructure.
5.3 Access control and account isolation. Every request to a data endpoint resolves the authenticated user on the server before any record is read or written, and each query is scoped to that user. Row-level security is enabled on every table holding customer data, and no policy admits an unauthenticated request: each requires either a service-role credential or an authenticated session, so an anonymous query returns no rows. Some policies grant scoped access to the signed-in database role. The application ships no browser-side database client, so in practice a browser does not query the database directly. Server-side access uses a service-role credential that is not subject to row-level security. Isolation between accounts is therefore enforced by server-side scoping of every query, with row-level security operating as an additional layer behind it. Verdict does not represent that row-level security would contain an application-layer scoping defect.
5.4 Access by Verdict personnel. Verdict personnel holding an administrative account can open any account’s reports through the application, and can download the deck file uploaded with a report while that file is still held, which is how Verdict answers support and debugging requests. Two people hold that access, as set out in section 5.6. It is not conditioned on a per-incident authorization from Customer, and Verdict does not record it. Opening a report leaves no record at all, so Verdict cannot report to Customer whether or when its reports were opened by Verdict personnel, and cannot do so retrospectively for any period before such recording begins. Customer requiring either a per-incident authorization or a record of access should raise it in writing before submitting confidential material.
5.5 Secret management. The service-role database credential is held only in deployment environment secrets, is not committed to source control, and is distinct from the secret used to sign internal job-trigger tokens.
5.6 Personnel. Verdict limits access to personal data to personnel who require it to operate the Service. Verdict presently has no employees. The administrative access described in section 5.4 is held by two people: Verdict’s founder, and one further person Verdict has authorized to assist in operating the Service. Between them they hold several accounts carrying that access, because the founder signs in under more than one address; the number of accounts is therefore larger than the number of people. Verdict binds each person holding such access to an obligation of confidentiality that survives the end of the engagement, and will update this section if the number of people changes.
5.7 Sharing controlled by Customer. Reports are private to the Account by default, and Verdict does not make a report readable outside the Account on its own initiative. A report becomes readable by a person who holds no Account where Customer makes it so, including where Customer generates a share link, generates a co-investor link, connects a Slack workspace, in which case Verdict delivers report content into the channel Customer selects and it is readable by that channel’s members, or exports a report and distributes the exported file. Customer may revoke a share link or a co-investor link at any time, and may disconnect the workspace.
5.8 Verdict’s public gallery. Verdict separately operates a public gallery containing analyses that Verdict itself prepares, of companies Verdict selects for demonstration and that are not Verdict customers. Publication to the gallery is performed by Verdict and is not connected to the share links described in section 5.7. Verdict does not publish Customer Content, or any analysis generated from Customer Content, to the gallery or to any other public surface without Customer’s prior written consent.
5.9 Absence of certification. Verdict holds no SOC 2, ISO 27001, or equivalent third-party attestation, has not engaged an auditor, and has not commissioned an external penetration test. Verdict publishes no target date for any of them. A summary of the controls Verdict does not have is maintained at useverdict.io/security. Customer should weigh this in deciding what material to submit, and should raise any additional requirement in writing before purchase.
Sub-processors
6.1 Authorization. Customer gives Verdict general authorization to engage Sub-processors to process personal data in connection with the Service. The complete, current list of Sub-processors, with a link to each provider’s own privacy and security documentation, is maintained in section 4 of the Privacy Policy. Verdict does not attest to any Sub-processor’s certification status; each provider publishes its own.
6.2 Principal Sub-processors. The providers below carry the core of the processing. The list in the Privacy Policy is the operative one and covers every other provider named there.
- Anthropic. Model inference. Deck contents and analysis prompts are transmitted to Anthropic for processing. Anthropic’s commercial terms prohibit training on customer data. Inputs and outputs may be retained by Anthropic for up to thirty (30) days for trust-and-safety review and are then deleted. Anthropic commercial terms.
- Supabase. Database and object storage for deck files, reports, and profile data. Encrypted at rest (AES-256) and in transit (TLS 1.2 or higher). Hosted on AWS
us-east-1. Supabase security. - Vercel. Application hosting and serverless execution. Request logs are retained on Vercel’s standard schedule. Vercel privacy.
- Clerk. Authentication and session management. Holds the Account email address and any OAuth tokens. Clerk privacy.
- Stripe. Payment and subscription processing. Receives payment details directly through tokenized checkout. Stripe privacy.
6.3 Sub-processor obligations. Verdict engages each Sub-processor under that provider’s data processing terms, which are intended to meet the requirements of Article 28(3) of the GDPR. Those terms are set by the provider, and their form and timing conventions differ from this Addendum. Verdict does not represent that each of them is identical to or more protective than this Addendum in every respect, and will identify the terms applicable to a given Sub-processor on written request. Verdict remains liable to Customer for a Sub-processor’s performance of its data protection obligations.
6.4 Change notice and objection. Verdict will give at least thirty (30) days’ notice by email to Customer before a new Sub-processor begins processing personal data. Customer may object on reasonable data-protection grounds within that period. If the parties cannot agree a resolution, Customer may terminate the affected part of the Service and receive a refund of fees attributable to the unused remainder of the paid period.
6.5 No other disclosure. Verdict does not sell, lease, license, or otherwise transfer Customer Content to any party outside the Sub-processor list, except where compelled under section 9.3.
No Training on Customer Data
7.1 Commitment. Verdict does not use Customer Content, generated reports, or submitted corrections to train, fine-tune, or otherwise develop any generalized artificial-intelligence or machine-learning model. Verdict operates no training of its own, and its model provider processes each request under commercial terms that prohibit training on customer data.
7.2 Account-scoped calibration. Corrections Customer submits are used to calibrate later analysis within Customer’s own Account. They do not propagate into the analysis produced for any other account. Verdict does not operate cross-account or federated learning on Customer Content.
Assistance to Customer
8.1 Data subject requests. Taking into account the nature of the processing, Verdict will assist Customer by appropriate technical and organizational measures, so far as is reasonably possible, in responding to requests from data subjects exercising their rights. Where Verdict receives such a request directly in respect of personal data it processes on Customer’s behalf, Verdict will refer the request to Customer rather than respond to it, unless legally required to respond.
8.2 Impact assessments. Verdict will provide Customer with reasonable assistance in carrying out a data protection impact assessment or a prior consultation with a supervisory authority, to the extent the assessment relates to processing under this Addendum and Customer cannot reasonably obtain the information elsewhere.
8.3 Information rights. On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, Verdict will make available the information reasonably necessary to demonstrate compliance with this Addendum. Customer will treat that information as confidential and will bear its own costs.
Personal Data Breach
9.1 Notification. On becoming aware of a personal data breach affecting personal data processed under this Addendum, Verdict will notify Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of it. Notice is sent to the email address associated with the Account.
9.2 Content of notice. The notice will describe the nature of the breach, the categories and approximate volume of personal data concerned so far as known, the likely consequences, the measures taken or proposed to address it, and any recommended action for Customer. Where the full information is not available at the time of notice, Verdict will provide it in phases as it is established.
9.3 Compelled disclosure. Where Verdict is required by law to disclose personal data processed under this Addendum, Verdict will notify Customer before disclosing it unless legally prohibited from doing so.
International Transfers
10.1 Processing location. The Service and its primary data stores operate in the United States. Personal data submitted from outside the United States is transferred to and processed there.
10.2 Transfer mechanism. Where personal data protected by the GDPR or by United Kingdom data protection law is transferred to a country that has not received an adequacy decision, the transfer is made on the basis of the European Commission’s Standard Contractual Clauses, together with the United Kingdom International Data Transfer Addendum where applicable. Verdict will provide the relevant transfer documentation on written request to legal@useverdict.io.
General
11.1 Order of precedence and governing law. This Addendum prevails over the Terms of Service and the Privacy Policy in respect of the processing of personal data. In all other respects the Terms of Service govern. This Addendum is governed by the law designated in section 17.1 of the Terms of Service, and section 17.2 of the Terms of Service governs venue, in each case except where applicable data protection law requires otherwise. Nothing in this section deprives a data subject of a right or a forum that applicable data protection law confers on them.
11.2 Liability. The limitations of liability in the Terms of Service apply to this Addendum and to any claim arising under it, to the extent permitted by applicable law. Section 14.4 of the Terms of Service disapplies the aggregate liability cap for Verdict’s breach of section 5 or section 7 of this Addendum, of section 10 (Confidentiality) or section 12 (Data Protection) of the Terms of Service, or of applicable data protection law, including a personal data breach resulting from Verdict’s failure to maintain the security measures described in section 5 of this Addendum. The cap continues to apply to a claim arising from any other provision of this Addendum. The exclusion of indirect and consequential damages in section 14.1 of the Terms of Service continues to apply to such a claim.
11.3 Amendment. Verdict may amend this Addendum. For a material amendment, including a change to a Sub-processor, to a retention period, or to the breach notification commitment, Verdict will notify registered users by email at least thirty (30) days before the amendment takes effect and will update the version designation and effective date on this page.
11.4 Contact. Requests for an executed counterpart, a customer-specific retention schedule, a Sub-processor objection, transfer documentation, or any other data protection matter may be sent to legal@useverdict.io.