Data Processing Agreement

Effective 8 September 2026 · Last edited 25 August 2026

Vern — Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Use between Vern AI Pty Ltd ("Vern", "we", "us") and the customer agreeing to those Terms ("you", "Customer"). It applies where Vern processes personal information on your behalf in providing the Service.

Capitalised terms not defined here have the meaning given in the Terms of Use. Where this DPA conflicts with the Terms of Use, this DPA prevails in respect of the processing of personal data.

For questions about this DPA, or to request a countersigned copy, contact:

Vern AI Pty Ltd P/24 Campbell Street, Haymarket, NSW 2000, Australia Email: roupen@vern.so Trust Center: trust.vern.so

1. Roles and scope

You are the controller (or, where applicable, the processor acting on behalf of another controller) in respect of Customer Data. Vern is the processor (or sub-processor) and processes Customer Data only on your behalf.

Where you are yourself a processor for a third-party controller, you confirm that you have the authority to appoint Vern as a sub-processor on that controller's behalf, and that this DPA reflects instructions consistent with that controller's requirements.

"Data Protection Laws" means all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as incorporated into United Kingdom law ("UK GDPR"), and the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.

2. Subject matter, duration, nature and purpose

Subject matter. Vern's provision of the Service: extracting Customer Data from source systems and files, mapping and transforming it to your schema, validating it, and making it available to or importing it into your systems.

Duration. For the term of your subscription, plus the retention period described in Section 9.

Nature and purpose. Processing is automated and performed on your documented instructions for the purpose of migrating and onboarding your End Customers' data into your product.

The categories of data subjects and personal data are set out in Annex I.

3. Your instructions

Vern will process Customer Data only on your documented instructions, including those you give through your configured use of the Service, except where required to process otherwise by a law to which Vern is subject — in which case Vern will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.

You are responsible for ensuring that your instructions, and your collection and use of Customer Data, comply with Data Protection Laws, and that you have a lawful basis for the processing you instruct.

Vern will inform you if, in its opinion, an instruction infringes Data Protection Laws.

No training on Customer Data. Vern does not use Customer Data to train foundation models or any general-purpose AI models. Vern may use aggregated, de-identified operational data (such as schema patterns and migration metadata) to improve the Service.

4. Confidentiality of personnel

Vern ensures that personnel authorised to process Customer Data are subject to binding confidentiality obligations, are informed of the confidential nature of the data, and access it only as necessary to perform their duties.

5. Security

Vern implements and maintains the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects.

Vern may update these measures over time, provided it does not materially reduce the overall level of protection.

6. Sub-processors

You give Vern general authorisation to engage sub-processors to process Customer Data.

Vern maintains a current list of sub-processors in its Trust Center at trust.vern.so, described in Annex III. Vern will give reasonable advance notice of the addition or replacement of a sub-processor. You may object on reasonable data-protection grounds within fourteen (14) days of that notice; if the objection cannot be resolved, you may terminate the affected part of the Service and receive a refund of prepaid fees covering the unused remainder of the term.

Vern imposes on each sub-processor data protection obligations substantially equivalent to those in this DPA, and remains liable to you for a sub-processor's performance of those obligations.

7. Assistance to you

Taking into account the nature of the processing and the information available to it, Vern will assist you:

Data subject requests. By providing the functionality of the Service and, where that is not sufficient, by reasonable cooperation, so that you can respond to requests from data subjects exercising their rights. If Vern receives such a request directly, it will not respond substantively and will refer the individual to you, except where required to respond by law.

Security, breach, and impact assessments. With your obligations relating to security of processing, notification of personal data breaches, communication to data subjects, data protection impact assessments, and prior consultation with supervisory authorities.

Breach notification. Vern will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably available to it to support your own notification obligations.

8. Audit and information rights

Vern will make available to you the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, and will allow for and contribute to audits, as follows:

Documentation. On request, Vern will provide its current ISO/IEC 27001 certificate and the security documentation available in its Trust Center.

Questionnaires. Vern will respond to a reasonable security or privacy questionnaire no more than once in any twelve (12) month period, unless a personal data breach has occurred or a supervisory authority requires otherwise.

On-site audit. Where the above is insufficient to demonstrate compliance, or where required by a supervisory authority or Data Protection Laws, you (or an independent auditor appointed by you and reasonably acceptable to Vern, who is not a competitor of Vern and who is bound by confidentiality) may audit Vern's processing on at least thirty (30) days' written notice, no more than once in any twelve (12) month period, during business hours, and in a manner that does not unreasonably disrupt Vern's operations or compromise the confidentiality of other customers' data.

You bear the costs of an audit under this section, except where the audit reveals a material breach of this DPA by Vern.

9. Deletion and return

On termination or expiry of your subscription, Vern will make Customer Data available for export on your written request made within thirty (30) days of termination, in accordance with the Terms of Use. After that period, Vern will delete Customer Data, except to the extent that retention is required by a law to which Vern is subject — in which case Vern will continue to protect it in accordance with this DPA for as long as it is retained.

Routine backups are overwritten on their ordinary cycle and remain subject to this DPA until they are.

10. International transfers

Customer Data is stored in the United States or Australia, depending on the data region configured for your account. Some processing occurs in other jurisdictions where Vern's sub-processors operate, as described in the Trust Center.

Where Vern's processing involves a transfer of personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country that is not the subject of an adequacy decision, that transfer is governed by the transfer mechanism set out in Annex IV.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Use.

12. Term

This DPA takes effect when you accept the Terms of Use and continues for as long as Vern processes Customer Data on your behalf. Sections 4, 8, 9, and 11 survive termination.


Annex I — Description of the processing

Categories of data subjects

The personal data transferred concerns individuals whose records exist in the source systems you migrate. Because the Service moves whatever a source system holds, the categories depend on your product and your End Customers, and typically include:

Your End Customers' own customers, clients, members, patients, residents, tenants, or employees, as applicable to your industry.

Contacts, account holders, and authorised representatives recorded in the source system.

Personnel of your End Customers whose details appear in the source system (for example, as record owners, authors, or approvers).

Categories of personal data

Determined by the contents of the source systems and files you instruct Vern to process. Typically includes identifiers and contact details (names, email addresses, postal addresses, telephone numbers), account and relationship records, transactional and financial records (invoices, payments, balances), scheduling and activity history, free-text notes, and documents and attachments submitted for extraction.

Sensitive data

The Service is not designed for, and you should not instruct the processing of, special categories of personal data as defined in Article 9 of the GDPR, unless separately agreed in writing in an order form. Where your industry means such data may be present in a source export, you are responsible for identifying it and for the additional safeguards required.

Frequency of transfer

On a one-off or recurring basis, as determined by the migrations you run.

Retention

As set out in Section 9 of this DPA and the retention section of the Privacy Policy.

Annex II — Technical and organisational measures

Vern operates an information security program certified to ISO/IEC 27001. Measures include:

Encryption of personal data in transit (TLS) and at rest.

Role-based access control and multi-factor authentication for personnel, with access granted on a least-privilege basis.

Logical separation of customer data, with tenant scoping enforced at the database layer.

Regional data residency, so that Customer Data is stored in the region configured for your account.

Credentials for source systems held in a dedicated secrets vault, encrypted, and excluded from application and agent logs.

Logging, monitoring, and anomaly detection.

Vendor risk management and sub-processor review.

Incident response and business continuity procedures, including breach notification.

Regular internal and independent audits.

Configurable data retention, allowing you to set automatic deletion of migration workspaces.

Current detail is maintained in the Trust Center at trust.vern.so.

Annex III — Sub-processors

The current list of sub-processors — including the purpose of each and the regions in which it processes data — is maintained in the Trust Center at trust.vern.so and forms part of this Annex.

Vern will give reasonable advance notice of changes, and you may object in accordance with Section 6.

Annex IV — Transfer mechanism

To be completed. See Section 10.

Where required, the parties will enter into the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 and, for transfers subject to UK law, the International Data Transfer Addendum issued by the Information Commissioner's Office, with the annexes to those instruments completed using Annexes I to III of this DPA.

Contact roupen@vern.so to request the executed clauses.

    Data Processing Agreement | Vern