Verid Data Processing Agreement
Version 2026-08-13.1 · Effective 13 August 2026 · Last updated 13 August 2026
Opens your browser print dialog (HTML). No signed PDF is generated.
This page is the complete web DPA. Accepting it in Verid (checkout, Settings, or the in-app prompt) records version, user, and timestamp. Verid does not issue a signed PDF unless separately agreed in writing. Related: Privacy Policy · Terms.
Processor identity
Oleksandr KryvtsunNIF: Z2015426X
C/ Uruguay 1, Bloque E, Escalera 2, Planta 01, Puerta 7A
Edificio Mirador (Camporrosso Village), 03509 Finestrat (Alicante), Spain
[email protected]
1. Parties and roles
This Data Processing Agreement (“DPA”) is between the merchant customer of the Verid service (“Merchant”, “you”, “Controller”) and Oleksandr Kryvtsun, trading as Verid, NIF Z2015426X, C/ Uruguay 1, Bloque E, Escalera 2, Planta 01, Puerta 7A, Edificio Mirador (Camporrosso Village), 03509 Finestrat (Alicante), Spain (“Verid”, “Processor”, “we”).
For Magento order, refund, product-cost, ad-spend, purchase-pixel, and optional profit-conversion data that you instruct Verid to process in connection with your store, you are the controller and Verid is the processor under GDPR Article 28.
Verid remains an independent controller for Verid account identity, authentication, billing/subscription records, security logs, and product analytics about use of the Verid application itself (see the Privacy Policy).
Google Ads and Meta act as independent controllers for data you instruct Verid to upload to their APIs under your ad accounts.
2. Subject matter, duration, nature and purpose
Subject matter: processing of Merchant store and related personal data to provide the Verid Magento net-profit analytics service described in the Terms of Service.
Duration: for the term of the Merchant’s Verid subscription or trial and any post-termination retention period stated in this DPA, unless earlier deletion is required by law or mutually agreed.
Nature: collection via Magento REST and optional pixel; storage; aggregation into profit metrics; display in the Verid dashboard; optional exports, scheduled reports, alerts, and conversion uploads you enable.
Purpose: compute and present net profit and related analytics (including shipping cost vs charged, COGS, fees, ads, and attribution views) solely on documented Merchant instructions via the Verid product UI/API and this DPA.
3. Documented instructions
Verid processes personal data only on documented instructions from the Merchant, including: (a) this DPA and the Terms; (b) configuration and actions in the Verid dashboard (connect Magento, sync, set costs/fees/shipping rules, connect ads, enable pixel/conversions, export, schedule reports); and (c) written instructions from the Merchant’s authorised workspace owner.
Verid will inform the Merchant if, in its opinion, an instruction infringes GDPR or other Union or Member State data-protection provisions, unless informing the Merchant is prohibited by law.
4. Categories of data subjects
Data subjects whose personal data may be processed under this DPA typically include:
- Merchant’s Magento customers and end-buyers (identifiers on orders)
- Merchant’s Verid workspace users (owners and invited members) to the extent their identifiers appear in store-processing context
- Individuals associated with connected advertising accounts where spend or conversion records identify campaigns linked to orders
5. Categories of personal data
Depending on Magento ACL, pixel configuration, and features you enable, Verid may process:
- Order and credit-memo financial fields and line items (SKU, name, qty, totals, COGS)
- Customer email and Magento customer id when present on orders (new vs returning, LTV; optional hashed email for Meta CAPI when enabled)
- Optional pixel events (order id / click identifiers such as gclid, gbraid, wbraid, fbclid, fbc, fbp)
- Ad spend by campaign and day; OAuth tokens for connected ad accounts (credentials encrypted at rest)
- Optional conversion upload records (order key, click id, profit value, conversion action)
- Store configuration you set (timezone, currency, fee and shipping rules) and custom expenses
6. Confidentiality
Verid ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Access to Merchant store data is limited to personnel who need it to operate, secure, or support the Verid service.
7. Technical and organisational measures
Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, Verid implements appropriate technical and organisational measures, including without limitation:
- TLS encryption in transit; encryption of integration credentials at rest
- Workspace isolation and role-based access (owner / viewer)
- Authentication for Verid accounts; least-privilege Magento Integration tokens recommended
- Logging, monitoring, and rate limiting on sensitive endpoints
- Backups and recovery procedures for production databases
- Vendor due diligence for subprocessors that process personal data
8. Subprocessors
The Merchant provides a general written authorisation for Verid to engage subprocessors to process personal data for the purposes of delivering the service.
The current subprocessor list is published in this DPA (section “Current subprocessors”). Verid will give the Merchant advance notice of intended additions or replacements (via email to the workspace owner and/or an in-app notice) before the change takes effect, and will give the Merchant a reasonable opportunity to object on legitimate data-protection grounds.
If the Merchant objects, the parties will discuss in good faith. If Verid cannot reasonably accommodate the objection, the Merchant may terminate the affected service without penalty for the unused prepaid period attributable to that change.
Verid remains responsible for subprocessors’ performance of obligations under this DPA as for its own acts.
9. Assistance with data-subject and authority requests
Taking into account the nature of processing, Verid assists the Merchant by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Merchant’s obligations to respond to requests for exercising data-subject rights (access, rectification, erasure, restriction, portability, objection).
Verid assists the Merchant with data-protection impact assessments and prior consultations with supervisory authorities, to the extent relating to Verid’s processing of Merchant personal data and as reasonably requested.
Requests should be sent to the privacy contact below. Verid will not respond to data subjects as controller for Merchant store data except to redirect them to the Merchant where appropriate.
10. Personal-data breach notification
Verid will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting Merchant personal data processed under this DPA.
Notification will describe, to the extent known: the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.
11. Deletion or return; retention
Upon termination of the Verid service for a workspace, or upon written request of the Merchant, Verid will delete or return Merchant personal data processed as processor, at the Merchant’s choice, and delete existing copies, unless Union or Member State law requires storage.
Operational retention (unless a longer legal obligation applies):
- Active subscription/trial: Merchant store analytics data retained while the workspace remains active
- After workspace deletion request or account termination: Merchant Magento/order/pixel/ad analytics data deleted or anonymised within 30 days
- Backups: purged on the normal backup rotation cycle (typically within 35 days after primary deletion)
- Billing and tax records controlled by Verid: retained as required by applicable accounting/tax law (typically up to 6–10 years depending on jurisdiction)
- Security and abuse logs: typically up to 12 months
12. Audit and information rights
Verid makes available to the Merchant information necessary to demonstrate compliance with Article 28 obligations and this DPA, and allows for and contributes to audits, including inspections, conducted by the Merchant or an auditor mandated by the Merchant, subject to reasonable notice, confidentiality, and frequency limits that do not unreasonably disrupt Verid’s operations.
Where available, Verid may satisfy audit requests with up-to-date third-party audit reports, certifications, or detailed written answers in lieu of on-site inspection when those materials reasonably address the Merchant’s questions.
13. International transfers
Where Merchant personal data is transferred outside the EEA/UK to a country without an adequacy decision, Verid uses appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) with subprocessors, supplementary measures where required, and transfers only as needed to provide the service.
14. Liability, governing law, contact, version
Liability between the parties for this DPA follows the limitation and liability provisions of the Verid Terms of Service, except where mandatory data-protection law provides otherwise.
This DPA is governed by the laws of Spain, without prejudice to mandatory data-protection provisions. Courts of Alicante, Spain, have jurisdiction for disputes arising from this DPA, subject to any mandatory rights of data subjects or supervisory authorities.
Privacy / DPA contact: [email protected]. Operator: Oleksandr Kryvtsun, NIF Z2015426X.
Effective date: 13 August 2026. Document version: 2026-08-13.1. Last updated: 13 August 2026.
Acceptance of this DPA is recorded electronically (user, version, timestamp, source). Verid does not claim a wet-ink or generated signed PDF unless separately issued.
Current subprocessors
General authorisation list as of 13 August 2026. Changes follow the advance-notice and objection process in section 8.
| Subprocessor | Role | Region | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the Verid web app and worker; PostgreSQL and Redis run on the same VPS (not separate unnamed hosts) | EEA (Hetzner; production IP in Finland allocation) | EEA processing; no third-country transfer for this host |
| Cloudflare, Inc. | CDN / DNS / reverse-proxy (TLS) and transactional email delivery via Cloudflare Email Sending | EEA / USA | SCCs (or equivalent) as applicable for US processing |
| Stripe Payments Europe, Limited | Subscription billing and payment processing | EEA / USA | SCCs (or equivalent) as applicable for US processing |