Data Processing Addendum

This DPA governs how Vernacia processes Personal Data on behalf of our Customers in accordance with the EU General Data Protection Regulation (GDPR) and the UK GDPR.

Last updated: 2026-04-19

1. Parties & roles

In plain terms: if you use Vernacia to translate documents containing your customers' or employees' personal data, this is the GDPR Article 28 contract that covers it.

This Data Processing Addendum ("DPA") forms part of the Vernacia Terms of Service between RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED (CIN: U62091KA2025PTC210162), operating the Vernacia service ("Processor"), and the Customer ("Controller").

Vernacia acts as a data processor on behalf of the Customer when processing Personal Data uploaded to the service for the purpose of translation.

The Customer remains the data controller and is responsible for obtaining any necessary consents from end users and data subjects.

2. Categories of data processed

Account data: name, email address, hashed password, team membership.

Content data: documents uploaded for translation and their translated outputs.

Usage data: translation job metadata (timestamps, languages, model, token counts, cost).

Technical data: IP address, browser user agent, and audit log entries.

Vernacia does not request or process special-category data (health, biometric, political) unless it is incidentally included in uploaded documents by the Customer.

3. Security measures

Encryption in transit: TLS 1.3 for all connections.

Encryption at rest: AES-256 for files and database records; encryption keys are held in a dedicated key-management service, separate from the data they protect.

Access control: short-lived JWTs, OAuth 2.0, MFA available on all accounts, role-based access control (RBAC) with least-privilege defaults.

Audit logging: every action that touches a file is written to an immutable audit log retained for 90 days by default (configurable up to 24 months for Enterprise tier).

Secrets management: all credentials stored in environment variables; no secrets in source code, logs, or error messages.

Regular vulnerability scanning and dependency updates as part of CI.

4. Sub-processors

Vernacia engages the following sub-processors to deliver the service:

• OpenAI (USA) — AI translation model inference under OpenAI Data Processing Agreement. OpenAI does not train on API-submitted data.

• Google Cloud Translation (USA) — AI translation for certain language pairs (used as a fallback for low-resource languages). Document text for those language pairs is processed by this service.

• Cloud infrastructure provider (Mumbai, India region) — compute, object storage, and database hosting.

• Resend (USA) — transactional email delivery.

• Stripe (USA) and Razorpay (India) — payment processing.

• Twilio (USA) — SMS delivery for phone-based multi-factor authentication (processes the phone number you enrol).

• Sentry (USA) — error monitoring. Personal identifiers are stripped before events are sent.

We will notify Customers of material sub-processor changes at least 30 days in advance via email.

5. Data retention & deletion

Uploaded files and translated outputs are automatically deleted 30 days after job completion.

Account deletion triggers immediate deletion of all associated Personal Data within 24 hours, except where retention is required by law (e.g. tax records for 7 years).

Audit logs are retained for 90 days by default (configurable up to 24 months for Enterprise tier), then purged.

Customers can request export or deletion of their data at any time via [email protected].

6. Breach notification

In the event of a confirmed Personal Data breach, Vernacia will notify affected Customers without undue delay and in any case within 72 hours of becoming aware of the breach.

Notifications include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

7. International data transfers

Customer data storage is planned and architected around the ap-south-1 (Mumbai, India) region.

Where data is transferred outside the EEA (e.g. to OpenAI for model inference in the USA), we rely on the EU Standard Contractual Clauses and the EU–US Data Privacy Framework where applicable.

Enterprise customers can request EU-only processing by contacting [email protected].

8. Data subject rights

Vernacia will assist the Controller in responding to data subject requests for access, rectification, erasure, restriction, portability, and objection.

Standard requests are fulfilled within 30 days. Contact [email protected] with the data subject identifier.

Need a signed DPA?

Enterprise customers can request a counter-signed copy of this DPA, our Standard Contractual Clauses, or our latest security documentation by emailing [email protected].

Vernacia is a product of CloudServe Digital, a division of CloudServe Infotech (RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED).
CIN: U62091KA2025PTC210162 · GST: 29AAPCR1639E1Z3
#36, WeWork Prestige Central, Infantry Road,
Mahatma Gandhi Road, Bengaluru – 560001, Karnataka, India
Tel: +91-9110618988