Data Processing
Created: September 9, 2026 · Last Updated: September 9, 2026
Article 1. Purpose and Scope of This Page
Certain engagements with Veren Digital Solutions Limited ("Veren Digital," "we," "us," or "our") involve us processing personal data that belongs to a client's own leads, customers, or other end-individuals — not data collected directly from visitors to verendigital.com, which our Privacy Policy already covers. This can arise across the range of services Veren Digital offers: an AI consulting engagement that touches a client's CRM data, a bespoke automation build, or our PCAA (Prince Charming AI Android) lead-recovery offer, cited here as one concrete, currently live example of this pattern, not as this page's subject. This page explains, in plain but precise terms, how we handle that category of data whenever an engagement calls for it.
Article 2. Definitions
- "Client" means the business that has engaged Veren Digital under a signed Service Agreement.
- "Client Data" means the personal data of a Client's own leads, customers, or other end-individuals that Veren Digital processes in the course of delivering a Service to that Client.
- "Controller" means the party that determines the purposes and means of processing Client Data. For Client Data, the Client is the Controller.
- "Processor" means the party that processes Client Data on the Controller's documented instructions. For Client Data, Veren Digital is the Processor.
- "Instructions" means the Client's documented directions regarding how their Client Data should be processed, typically set out in the applicable Service Agreement and any Data Processing Addendum within it.
- "Service" means the specific engagement — such as an AI consulting project or PCAA — under which Veren Digital processes Client Data.
- "Sub-processor" means a third-party service provider Veren Digital engages to process Client Data in order to deliver a Service.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Client Data.
Article 3. Roles: Controller and Processor
Under data-protection law (the GDPR, UK-GDPR, and, by the same underlying principles, Nigeria's NDPR), the Client remains the Controller for the personal data of its own leads and customers at all times. The Client decides why and how that data is used and is responsible for having a proper lawful basis for holding and using it in the first place. Veren Digital acts strictly as a Processor with respect to Client Data: we process it only on the Client's Instructions and only for the purpose of delivering the Service the Client engaged us for.
Article 4. Our Processing Commitments
Whenever Veren Digital processes Client Data as a Processor, we commit to the following, consistent with what a Data Processing Addendum in a Service Agreement sets out in binding form:
- We process Client Data only on the Client's documented Instructions, and never for our own independent purpose, including never for our own marketing.
- We do not use one Client's Client Data for the benefit of any other Client, and we do not aggregate or repurpose it beyond the specific Service it was provided for.
- We apply the security measures described in Article 5.
- We ensure that personnel authorized to process Client Data are subject to confidentiality obligations.
- We engage Sub-processors only as described in Article 10, and flow down equivalent data-protection obligations to them by contract.
- We notify the Client of a Personal Data Breach, and assist with data-subject rights requests, as described in Articles 6 and 7.
- At the end of an engagement, we delete or return Client Data in accordance with the Client's Instructions and the terms of the applicable Service Agreement.
Article 5. Security Measures
Veren Digital applies technical and organizational measures designed to protect Client Data appropriate to its sensitivity and the risk presented by the specific Service. These measures include: encrypting Client Data in transit between our systems and a Client's own systems; restricting access to Client Data to the personnel and Sub-processors who need it to deliver the Service, on a need-to-know basis; requiring confidentiality commitments from anyone with that access; relying on infrastructure providers who themselves maintain independent security certifications and practices; and periodically reviewing our own access controls and Sub-processor list as part of delivering each Service. These measures evolve as a Service and its underlying technology evolve, and the applicable Service Agreement's Data Processing Addendum may specify additional or more particular measures for a given engagement.
Article 6. Personal Data Breach Notification
If Veren Digital becomes aware of a Personal Data Breach affecting Client Data, we will notify the affected Client without undue delay after becoming aware of it, and in any event within the timeframe specified in the applicable Service Agreement or, absent a more specific commitment there, within 72 hours. That notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures we have taken or propose to take to address it and mitigate its effects. Because the Client remains the Controller for Client Data, the Client is responsible for deciding whether and how to notify the affected individuals and any supervisory authority, though we will provide reasonable assistance with that assessment and notification if asked.
Article 7. Assisting With Data Subject Rights Requests
If Veren Digital receives a request directly from one of a Client's leads or customers to exercise a data-subject right (such as access, correction, or deletion) concerning Client Data, we will promptly forward that request to the Client rather than responding to it ourselves, since the Client, as Controller, is best placed to verify the requester's identity and decide how to respond. Where a Client asks us for assistance in responding to such a request — for example, locating and extracting the relevant Client Data from our systems, or implementing a correction or deletion the Client has decided to make — we will provide that assistance within a reasonable time, taking into account the nature of the processing and the information reasonably available to us.
Article 8. Categories of Client Data Typically Processed
The specific categories of Client Data we process vary by engagement and are set out precisely in the applicable Service Agreement. In general, and by way of illustration through our PCAA offer, this can include a lead's or customer's name, contact details (phone number, email address, WhatsApp handle), the history and content of their prior interactions with the Client, and status or stage information the Client's own systems already hold about them. We do not require, and do not seek, categories of data beyond what a given Service actually needs to operate.
Article 9. Client Responsibilities
As the Controller, the Client remains responsible for having a lawful basis — such as the consent of its own leads and customers, or an existing customer relationship recognized under applicable law — for holding and using the Client Data it provides to Veren Digital or grants us access to. Engaging a Service such as PCAA does not, by itself, create that lawful basis; the Service operates within whatever lawful basis the Client already has, and it is the Client's obligation to ensure that basis exists and remains valid before engaging us.
Article 10. Sub-processors
In delivering a Service that involves Client Data, we may rely on the same categories of infrastructure and service providers described in our Privacy Policy — for example, Resend for email delivery and Vercel for hosting — engaged only to the extent necessary to operate the Service, and bound by contractual data-protection obligations consistent with this page. We do not add a Sub-processor with access to Client Data without a basis to do so under the applicable Service Agreement, and, where that agreement requires advance notice of a new Sub-processor, we provide it.
Article 11. International Transfers
Where delivering a Service requires transferring Client Data outside the country in which it originated — including to Nigeria, where Veren Digital is based — we rely on the same categories of safeguards described in our Privacy Policy, such as standard contractual clauses, and, where the applicable Service Agreement specifies additional transfer safeguards, we follow those as well.
Article 12. Relationship to Your Signed Service Agreement; Governing Law
This page is a plain-language summary of how Veren Digital approaches Client Data across its Services generally. It is not, itself, a Data Processing Addendum and does not create binding obligations independent of a signed Service Agreement. The legally binding terms governing our processing of a specific Client's Client Data are set out in the Data Processing Addendum within that Client's signed Service Agreement; if this page and that Addendum conflict, the Addendum governs. This page, and the Data Processing Addendum it summarizes, are governed by the laws of Nigeria, consistent with the governing-law provision in the applicable Service Agreement, unless that Service Agreement specifies otherwise.
Article 13. Changes to This Page
We may update this page if how we process Client Data changes, or if we introduce a new Service that involves processing Client Data in a new way. The "Last Updated" date at the top of this page always reflects the most recent version; where a Client has a live Service Agreement with us, a material change to how we process their Client Data is also governed by whatever notice mechanism that Agreement specifies.
Article 14. Contact Us
Questions about how Veren Digital processes Client Data, for PCAA or any other Service, can be sent to privacy@legal.verendigital.com, or by post to Veren Digital Solutions Limited, 20 Kingdom Abadi Close, Old Etegwe Road, Yenagoa, Bayelsa State, Nigeria (RC 9664851).