VeridexCore Data Processing Addendum

Effective Date: March 8, 2026 Version: 1.0 Entity: VeridexCore (operated by VeridexCore Inc.)

This Data Processing Addendum ("DPA") supplements the VeridexCore Terms of Service and governs the processing of personal data by VeridexCore on behalf of the Customer.


1. Definitions


2. Scope of Processing

VeridexCore processes data solely as necessary to provide the Service:

Data CategoryProcessing PurposeStorage Location
SOP text contentCapability generationGoogle Cloud Firestore (us-central1)
GitHub usernameAuthenticationIn-memory (session only)
IP addressRate limiting, abuse preventionIn-memory (not persisted)
Capability artifactsService delivery, verificationGoogle Cloud Firestore (us-central1)
Receipt eventsTruth ledger emissionVeridexCore Firestore
Payment identifiersTransaction processingStripe (no card data stored by VeridexCore)

3. Customer Obligations

Customer shall:


4. VeridexCore Obligations

VeridexCore shall:


5. Sub-processors

VeridexCore uses the following Sub-processors:

Sub-processorPurposeLocation
Google Cloud PlatformInfrastructure, FirestoreUnited States (us-central1)
Stripe, Inc.Payment processingUnited States
VeridexCore Inc.Truth ledger, receipt persistenceUnited States (us-central1)
Vercel, Inc.Landing page hostingUnited States

Changes to Sub-processors will be communicated to the Customer with reasonable advance notice.


6. Data Transfers

Personal Data is processed in the United States (Google Cloud us-central1 region). If Customer is located outside the United States, Customer consents to the transfer of data to the United States for processing.

Where required by applicable law (e.g., GDPR), VeridexCore will implement appropriate transfer mechanisms such as Standard Contractual Clauses.


7. Security Measures

VeridexCore implements the following security measures:


8. Data Breach Notification

In the event of a Personal Data breach, VeridexCore will:


9. Data Retention and Deletion


10. Audit Rights

Customer may request documentation of VeridexCore's compliance with this DPA. VeridexCore will provide reasonable cooperation, including responses to written audit questionnaires. On-site audits require 30 days advance notice and are subject to confidentiality obligations.


11. Term

This DPA is effective for the duration of the Customer's use of the Service and survives termination to the extent necessary to complete processing obligations.


Document Control

VersionDateStatus
1.02026-03-08Active