This page summarizes the data processing addendum ("DPA") that governs how CB Platforms LLC ("CB Platforms", "we", "us") processes personal data on behalf of a Customer using Verbial. The DPA is incorporated into the terms of service at /legal/terms and applies automatically to every Customer whose use of the service involves personal data subject to the GDPR, UK GDPR, Swiss FADP, CCPA/CPRA or another law that requires a written processing agreement. Customers that need a countersigned copy, including the EU Standard Contractual Clauses, can request one at privacy@verbial.io.
1. Roles of the parties
The Customer is the controller (or "business" under US state law) of the personal data it stores in its workspace, including data about its clients, its clients' staff, its leads and contacts, and its own team. CB Platforms is the processor (or "service provider") of that data.
For account, billing, support and usage data about the Customer's own users, CB Platforms is an independent controller, and the privacy policy at /legal/privacy applies.
| Data | Customer's role | Our role |
|---|---|---|
| Contacts, companies, deals, notes, email content | Controller | Processor |
| Client users of portals, shared links and e-signature | Controller | Processor |
| Time entries, cost, salary and margin data about the Customer's team | Controller | Processor |
| Invoices, payment records, wallet addresses | Controller | Processor |
| Integration data pulled from third-party services at the Customer's instruction | Controller | Processor |
| Account, billing and usage data about the Customer's users | Independent controller | Independent controller |
2. Scope and details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the service to the Customer under the terms of service |
| Duration | The subscription term plus the 30-day grace period, and any longer period required to delete data from backups |
| Nature and purpose | Hosting, storing, backing up, transmitting, displaying, analyzing and otherwise processing Customer data to provide CRM, time tracking, proposals, e-signature, invoicing, payment collection tooling, client reporting, profitability and AI features |
| Categories of data subjects | The Customer's clients and prospective clients and their staff; the Customer's employees and contractors; other contacts the Customer stores |
| Categories of personal data | Name, email address, phone number, job title, employer, postal address, communications content and metadata, meeting records, signatures and signing metadata (IP address, timestamp), payment references, wallet addresses, time entries, compensation data for the Customer's own team where the Customer enables it |
| Special categories | None intended. The Customer must not submit special categories of data, health data, or data about children under 16 |
3. Our obligations as processor
We will:
- process personal data only on the Customer's documented instructions, which include the terms of service, the Customer's configuration of the service, and its use of the features, unless required by law to do otherwise, in which case we will inform the Customer before processing where the law permits;
- inform the Customer if we believe an instruction violates applicable data protection law;
- ensure that people authorized to process personal data are bound by confidentiality obligations;
- implement the technical and organizational measures in section 5;
- engage sub-processors only under section 4;
- assist the Customer, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations for security, breach notification, impact assessments and consultation with supervisory authorities;
- delete or return personal data at the end of the service under section 7;
- make available the information necessary to demonstrate compliance under section 8.
4. Sub-processors
The Customer authorizes us to engage the sub-processors listed below. We impose on each sub-processor data protection obligations no less protective than those in the DPA, and we remain responsible for their performance.
| Sub-processor | Purpose | Location | Engaged |
|---|---|---|---|
| Vercel, Inc. | Application hosting, edge network, website analytics | United States | Always |
| Neon, Inc. | Dedicated Postgres database per workspace, snapshots and backups | United States | Always |
| Stripe, Inc. | Subscription billing; card payment processing for the Customer's invoices | United States | Always for billing; connected account at Customer's option |
| Postmark (ActiveCampaign, LLC) | Transactional and CRM email delivery | United States | Always |
| Google LLC | Sign-in; Gmail, Calendar and Drive integrations; YouTube Data API | United States | Sign-in always; integrations at Customer's option |
| Anthropic, PBC | AI features (Claude) and MCP integration | United States | At Customer's option |
| Slack Technologies, LLC | Notifications | United States | At Customer's option |
| Airtable, Inc. | Intermediary for QuickBooks accounting sync | United States | At Customer's option |
| Intuit Inc. (QuickBooks) | Accounting sync via Airtable | United States | At Customer's option |
| Gusto, Inc. | Payroll and compensation data for cost calculations | United States | At Customer's option |
| Ahrefs Pte. Ltd. | SEO metrics for client reporting | Singapore | At Customer's option |
We will give the Customer at least 30 days notice before adding or replacing a sub-processor, by updating this page and emailing the account owner. If the Customer objects on reasonable data protection grounds and we cannot resolve the objection, the Customer may terminate the affected subscription and receive a refund of prepaid fees for the remaining term.
5. Security measures
We implement the following technical and organizational measures.
| Area | Measure |
|---|---|
| Isolation | Each workspace runs in its own dedicated Postgres database. No tables are shared between customers |
| Encryption | TLS 1.2 or higher for all data in transit. Encryption at rest for databases, backups and stored files |
| Authentication | Google sign-in only. No password storage. Session management with secure, HTTP-only cookies |
| Access control | Role-based access within workspaces, configured by the Customer. Least-privilege access to production for our staff, with multi-factor authentication and logged access |
| Backups | Daily snapshots and logical backups, retained on a 35-day rotation, with periodic restore testing |
| Logging and monitoring | Application and infrastructure logging, alerting on security events, audit log export for Scale plan customers |
| Development | Code review, dependency scanning, vulnerability management, and separation of production from development environments |
| Personnel | Confidentiality obligations for all staff and contractors with access to personal data. Access removed promptly on role change or departure |
| Vendor management | Security and data protection review of sub-processors, and contractual obligations flowed down |
| Incident response | Documented incident response procedure covering detection, containment, notification and post-incident review |
The Customer is responsible for the security of the Google accounts its users sign in with, the roles it assigns, the links it shares, the integrations it enables, and the wallets, bank accounts and third-party accounts it connects.
6. Personal data breach notification
We will notify the Customer without undue delay, and in any event within 72 hours after confirming a personal data breach affecting Customer data. The notice will go to the account owner by email and will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed to address it, and a point of contact. We will provide updates as more information becomes available.
The Customer is responsible for determining whether, and how, to notify supervisory authorities and data subjects. We will provide reasonable assistance. Our notice is not an admission of fault or liability.
7. Deletion and return of data
During the subscription term, the Customer can export all Customer data in JSON and other machine-readable formats at any time using the export features of the service.
At expiration or termination of the service, we keep the workspace in a read-only state for 30 days so the Customer can complete an export. After the 30-day grace period, we delete the workspace and its dedicated database. Copies in snapshots and backups roll off within 35 days after that deletion. We may retain personal data to the extent required by law, and we will continue to protect it under the DPA for as long as we hold it.
On written request during the grace period, we will confirm deletion in writing once it is complete.
8. Audits and compliance information
We will make available the information reasonably necessary to demonstrate compliance with the DPA. The primary mechanism is a written security questionnaire, which we will complete once per year on request, and the documentation at /security.
Where applicable law gives the Customer a right to audit and the questionnaire is not sufficient to demonstrate compliance, the Customer may request an audit no more than once per year, on at least 30 days written notice, during business hours, conducted by the Customer or an independent auditor bound by confidentiality, at the Customer's expense, and limited to what is reasonably necessary. Audits may not access other customers' data or our sub-processors' facilities. Where we hold a current third-party audit report or certification covering the relevant controls, we may provide that report in place of an on-site audit.
9. Data subject requests
If we receive a request from a data subject relating to Customer data, we will not respond except to direct the person to the Customer, unless the law requires otherwise. We will notify the Customer of the request where we can identify the Customer. The service provides tools for the Customer to access, correct, export and delete contact records so that the Customer can respond to requests itself.
10. International transfers
We host the service in the United States. For transfers of personal data from the EEA, the United Kingdom or Switzerland, the parties enter into the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), with the UK International Data Transfer Addendum for UK data and the adjustments required by the Swiss FDPIC for Swiss data. The SCCs are incorporated into the DPA and are available in the countersigned version on request. Where a sub-processor is certified under the EU-US Data Privacy Framework, we may also rely on that certification for that sub-processor.
We will assess the laws of the destination country and implement supplementary measures where needed, and we will notify the Customer if we become unable to comply with the SCCs.
11. US state privacy laws
Where the CCPA/CPRA or a similar US state law applies, we act as a service provider or processor. We will not sell or share personal information, retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than providing the service, or combine it with personal information from other sources except as permitted by law. We certify that we understand these restrictions. We will notify the Customer if we determine we can no longer meet our obligations under those laws, and the Customer may take reasonable steps to stop and remediate unauthorized use.
12. Liability and precedence
The liability of each party under the DPA is subject to the limitations and exclusions in the terms of service. In the event of conflict, the SCCs prevail over the DPA, and the DPA prevails over the terms of service for matters relating to the processing of personal data.
13. Contact
Data protection questions and requests for a countersigned DPA or the SCCs may be sent to privacy@verbial.io or by mail to CB Platforms LLC, CB Platforms LLC, United States.