
Data Processing Addendum
- Company
- VERSPECIFY, LLC
- Effective date
- August 21, 2026
- Version
- dpa-v1
- Website
- https://verspecify.com
- Contact
- support@verspecify.com
- Address
- 29350 Lisa Lynn Drive, Livingston, LA 70754
This Data Processing Addendum ("DPA") forms part of the agreement between Customer and VERSPECIFY, LLC. It applies when VerSpecify processes Personal Data on Customer's behalf in providing the Service. "Personal Data," "process," "controller," "processor," and similar terms have the meanings under applicable data-protection law.
1. Roles and instructions
Customer is the controller or business and VerSpecify is the processor or service provider for Customer Personal Data. VerSpecify will process Personal Data only to provide, secure, and support the Service; on documented Customer instructions; and as required by law. The agreement and Customer's authorized use constitute documented instructions.
2. Processing details
| Item | Description |
|---|---|
| Subject matter | Operation of AI-assisted document comparison and collaboration. |
| Duration | Subscription term plus the documented deletion and backup period. |
| Nature and purpose | Hosting, extraction, comparison, report generation, collaboration, support, security, and deletion. |
| Data subjects | Customer personnel, project participants, contacts, and persons referenced in Customer documents. |
| Data categories | Identity and contact data, account and usage data, document contents and metadata, project communications, and other data Customer elects to submit. |
| Sensitive data | Not intended unless expressly agreed in writing; Customer must avoid unnecessary sensitive data. |
3. Confidentiality and security
VerSpecify will ensure personnel authorized to process Personal Data are bound by confidentiality and will maintain safeguards appropriate to risk. Current controls are described in the Security Overview and applicable agreement. Customer is responsible for secure configuration and authorized-user management.
4. Subprocessors
Customer provides general authorization for subprocessors on the published Subprocessor List. VerSpecify will impose data-protection obligations appropriate to the services performed and remain responsible for subprocessor performance to the extent required by applicable law and contract. VerSpecify will provide at least 30 days' advance notice of material new subprocessors. Customer may object on reasonable data-protection grounds within 30 days after notice, after which the parties will seek a practical resolution. If advance notice is not reasonably possible because of an urgent security or legal need, VerSpecify will notify affected workspace administrators as soon as reasonably practicable afterward.
5. Security incidents
VerSpecify will notify Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, and will provide information reasonably available to assist Customer. Notification is not an admission of fault. Customer is responsible for notices it is legally required to issue unless law assigns that duty to VerSpecify.
6. Individual requests and compliance assistance
Taking into account the nature of processing, VerSpecify will provide reasonable assistance for verified data-subject requests, security assessments, breach obligations, and required impact assessments. Customer will first use available self-service tools. Fees may apply for extraordinary assistance where legally permitted.
7. Return and deletion
At termination or Customer request, VerSpecify will delete or return Customer Personal Data as stated in the agreement, unless retention is required by law. Deleted information may remain in protected backups until overwritten under the documented backup cycle and will not be restored except for disaster recovery or legal necessity.
8. Audits
VerSpecify will provide information reasonably necessary to demonstrate compliance, such as current third-party reports or questionnaires when available. On-site audits are limited to circumstances required by law or where supplied evidence is insufficient, subject to confidentiality, security, scheduling, scope, and cost protections.
9. International transfers and state-law terms
Before processing regulated data outside its originating jurisdiction, the parties will implement any required transfer mechanism. For U.S. state privacy laws, VerSpecify will not sell or share Customer Personal Data, retain/use/disclose it outside the permitted business purposes, or combine it with unrelated personal data except as permitted by applicable law and the agreement.
10. Order of precedence
If this DPA conflicts with the agreement on Personal Data processing, this DPA controls. More protective mandatory law controls over both.