Legal

Data Processing Agreement

Last updated: 23 June 2026

Standard Data Processing Agreement — VERDIX Platform

1. Parties and scope

This Data Processing Agreement ("DPA") is entered into between:

Controller: The customer organisation that has entered into a subscription agreement with Insaights B.V. for access to the VERDIX platform ("Customer", "Controller").

Processor: Insaights B.V., incorporated in Amsterdam, the Netherlands ("Insaights", "Processor").

This DPA forms part of the VERDIX subscription agreement and governs the processing of personal data by Insaights on behalf of the Customer in connection with the VERDIX AI governance platform.

2. Definitions

  • GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council.
  • Personal data: Any information relating to an identified or identifiable natural person as defined in Article 4(1) GDPR.
  • Processing: Any operation performed on personal data as defined in Article 4(2) GDPR.
  • Data subject: The natural person to whom personal data relates.
  • Sub-processor: Any third party engaged by Insaights to process personal data on behalf of the Customer.
  • Services: The VERDIX AI governance platform and related services provided under the subscription agreement.

3. Nature of processing

Subject matter: Processing of personal data in connection with the VERDIX AI governance platform.

Duration: The term of the subscription agreement and any applicable retention period thereafter.

Purpose: Provision of AI governance software services to the Customer, including initiative management, council governance workflows, evidence management, and financial modelling.

Categories of data subjects: Employees and contractors of the Customer who interact with the VERDIX platform; individuals referenced in AI initiative documentation.

Categories of personal data: Names, business email addresses, job titles, and activity records of users of the platform; personal data included in AI initiative documentation uploaded by the Customer.

4. Processor obligations

Insaights shall:

  1. Process personal data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law.
  2. Ensure that persons authorised to process personal data are bound by an appropriate duty of confidentiality.
  3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
  4. Respect the conditions referred to in Article 28(2) and (4) GDPR for engaging sub-processors.
  5. Assist the Customer in fulfilling its obligations to respond to data subject requests.
  6. Assist the Customer in ensuring compliance with Articles 32–36 GDPR.
  7. At the Customer's choice, delete or return all personal data upon termination of the agreement.
  8. Make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR.

5. Security measures

Insaights implements the following technical and organisational measures, at minimum:

  • Encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Access controls and role-based permissions limiting data access to authorised personnel
  • Multi-factor authentication for administrative access
  • Regular security testing and vulnerability assessments
  • Incident detection and response procedures
  • Employee security training and confidentiality obligations
  • Logical separation of Customer data

6. Sub-processors

The Customer grants Insaights general authorisation to engage sub-processors, subject to the conditions in this section.

Insaights shall inform the Customer of any intended changes to sub-processors — including additions or replacements — giving the Customer the opportunity to object. Insaights will provide at least 30 days' notice of such changes.

Insaights imposes data protection obligations on sub-processors that are equivalent to those in this DPA. Insaights remains fully liable to the Customer for sub-processor performance.

A current list of sub-processors is available upon request from privacy@insaights.co. All sub-processors are located within the EEA or operate under appropriate transfer mechanisms.

7. International transfers

Insaights does not transfer personal data outside the European Economic Area (EEA) without appropriate safeguards in place. Where transfers to third countries are necessary (for example, via sub-processors), Insaights ensures that Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms are in place.

8. Data subject rights

Insaights shall assist the Customer in fulfilling requests from data subjects exercising rights under Chapter III GDPR (including access, rectification, erasure, restriction, portability, and objection) by providing technically feasible assistance within 5 business days of a Customer request.

9. Personal data breach

Insaights shall notify the Customer without undue delay — and where feasible, within 48 hours — after becoming aware of a personal data breach affecting Customer data. The notification shall include, where available:

  • A description of the nature of the breach
  • Categories and approximate number of data subjects and records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

10. Audit rights

Insaights shall make available to the Customer all information necessary to demonstrate compliance with the obligations in Article 28 GDPR and shall allow for and contribute to audits and inspections conducted by the Customer or an auditor mandated by the Customer, on reasonable notice and no more than once per calendar year.

11. Termination

Upon termination of the subscription agreement, Insaights shall, at the Customer's choice, delete or return all personal data processed on behalf of the Customer, and delete existing copies, unless EU or Member State law requires storage of the personal data.

12. Governing law

This DPA is governed by the laws of the Netherlands. Any disputes shall be submitted to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands.

13. Contact

Data protection enquiries:
privacy@insaights.co

Insaights B.V.
Amsterdam, the Netherlands