Privacy, Terms, and Data Processing
Effective October 4, 2026 · ClientConnect, Inc.
1. Privacy Policy
Effective date: October 4, 2026 · ClientConnect, Inc.
This policy explains what Verasio collects, why, and what we do and don't do with it. It covers the website at verasioapp.com and the Verasio product. Verasio is operated by ClientConnect, Inc., a Wyoming corporation ("Verasio," "we," "us"). The service is offered from the United States and directed to businesses in the United States.
The short version
- We never sell personal information, and we never share it for cross-context advertising. The website runs no advertising cookies.
- Tenant data is never used to train AI models. We don't do it, and our default AI provider's commercial terms don't allow it.
- AI proposes, people approve. Every AI action is logged with the model and the prompt that produced it.
- Signed documents are stored in the tenant's own storage path. Siglio keeps nothing past 30 days.
- If a tenant stops paying, we keep the data 90 days past suspension, then export it to the Owner and delete it.
1.1 Who this policy covers
Three kinds of people touch Verasio, and we treat them differently.
Visitors are people using verasioapp.com, including anyone who fills in the booking form.
Tenants are the businesses that hold Verasio accounts, and the people inside them (Owners, Admins, and Users). For visitor and tenant account information, we decide how and why the data is used.
Contacts are the people a tenant texts, emails, calls, or sends documents to through Verasio. We process their information on the tenant's instructions. If a business contacted you through Verasio, that business decided to contact you, and questions about why belong to them. Section 1.6 covers what you can do.
1.2 What we collect
From visitors. The booking form collects your name, email, company, and one free-text field. Submitting it sends that information to our team by email through Mailgun, and we keep it so we can reply and follow up. Our hosting and security providers (Vercel and Cloudflare) see standard web logs such as IP address, browser type, and pages requested. The site runs no advertising cookies and no ad pixels.
From tenants.
- Account details: name, email, phone, company, role (Owner, Admin, or User), and department tag.
- Billing details: handled by Stripe. We store a reference to the payment method and the billing history, not card numbers.
- Usage and audit records: sign-in events, permission changes, approvals, and the AI action log described in Section 1.4.
- Credentials a tenant gives us, such as a tenant's own LLM key or integration keys. We use them only for that tenant.
- Security signals such as IP address and device data, used for fraud prevention and account protection.
- Support messages and our replies.
From contacts, on a tenant's instructions. Whatever the tenant puts into Verasio: names, phone numbers, email addresses, text and email messages, call records, notes, custom fields the tenant defines, signed documents and signing records, and consent status. Consent changes are stored with a timestamp and a source. Tenants decide what to store. We ask tenants not to store sensitive data they don't need, and tenants in regulated fields stay responsible for their own confidentiality duties. Do not store payment card numbers or protected health information in Verasio. We do not offer a HIPAA business associate agreement.
1.3 How we use information
- To run the service: delivering messages, calls, email, and signing requests, keeping records, and operating the product.
- To bill: charging tenants through Stripe and handling non-payment as the Terms describe.
- To support you: answering questions and diagnosing problems.
- To protect the service: abuse detection, fraud prevention, and enforcing the Terms and Acceptable Use rules, including texting rules.
- To tell tenants about their accounts: service notices, billing notices, and security alerts.
- To comply with law and to establish or defend legal claims.
1.4 How AI touches your data
Verasio uses large language models (LLMs) to help tenants customize and run their CRM. The rules are fixed in the product:
- Humans approve. AI data actions run under the permissions of the user who asked. AI changes to a tenant's setup (fields, objects, workflows, templates, integrations) need Owner approval in the Verasio interface. They can never be approved through the API or MCP.
- Everything is logged. Every AI action, approved or not, is written to the contact timeline with the model and the prompt that produced it. Those entries stay with the contact record.
- LLM call logs. The prompts and responses of LLM calls are logged and kept 90 days by default. The Owner can change that period per tenant. Deletion is enforced nightly.
- Your key stays yours. A tenant's own LLM key is never replaced with the Verasio platform key. If your key fails, the call fails.
- No training. Tenant data is never used to train models.
- Providers. Anthropic is the default LLM provider. A tenant can bring a different provider. The current list is in our subprocessor list. Each provider handles data under its own terms, which can include short-term retention for abuse monitoring.
1.5 How long we keep it
| Record | How long |
|---|---|
| LLM call logs (prompts and responses) | 90 days by default, Owner-configurable per tenant, enforced nightly |
| AI action entries on the contact timeline | As long as the contact record exists |
| Contact records | Soft-deleted when a tenant deletes them. Kept until hard-deleted on a privacy-erasure request, or deleted with the tenant's data under Section 2.6. |
| Signed PDFs and certificates | In the tenant's own storage path until the tenant deletes them or the tenant's data is deleted. Siglio keeps its copies 30 days after an envelope closes. |
| Tenant data after non-payment | Kept 90 days past suspension, then exported to the Owner and deleted. See Section 2.6. |
| Billing and tax records | 7 years |
| Website booking inquiries | 24 months from the inquiry |
Deleted data can remain in backups until they expire. We may keep records longer where the law requires it or to resolve a dispute.
1.6 If a business contacted you through Verasio
A Verasio tenant supplied your contact details so it could reach you. We process them on that business's instructions. Here is what you can do:
- Texts. Reply STOP or UNSUBSCRIBE to stop. Reply START to opt back in. We record each consent change with a timestamp and a source.
- Email. Use the unsubscribe link, or mark the message as spam. Either one stops email from that business through Verasio, and we record the source.
- Timing. Automated texts go out only between 08:00 and 20:00 in your local time.
- Questions about why you were contacted, or about the business's records, belong to that business.
- Privacy requests. You can send them to us or to the business. Where the data belongs to a tenant's records, we may refer the request to that tenant, as the law contemplates for service providers. Hard deletion is available for a verified privacy-erasure request.
1.7 Sharing
We never sell personal information, and we never share it with third parties for their marketing. We share it only in these situations:
- Service providers under contract, limited to what their job requires: hosting, database and storage, texting, voice, email, e-signature, payments, and AI. They are listed in Section 4.
- Carriers and registries. To send texts, Verasio registers each tenant as its own brand for carrier messaging (10DLC). That registration shares the tenant's business details with carriers and their registries, and messages travel over carrier networks.
- Between a tenant and its contacts. Sending a message or a document necessarily shares it with the person it is sent to.
- Legal requirements, such as a subpoena or court order, or to protect rights and safety. Where lawful and practical, we tell the affected tenant first.
- Business transfers. If Verasio is part of a merger, acquisition, or asset sale, information may transfer, subject to this policy.
- Affiliates. We don't give personal information to affiliates for their own purposes.
1.8 Cookies
The website uses no advertising cookies. Cloudflare may set cookies it needs to protect the site from abuse. Because we don't sell or share personal information, there is nothing for a Global Privacy Control signal to switch off.
1.9 Security
We use safeguards that fit the data we hold: encryption in transit, tenant separation enforced in the database, role-based access (Owner, Admin, User), audit logging, and human approval for AI changes. No service can promise perfect security. Verasio does not currently hold a SOC 2 report or similar certification, and nothing here should be read as claiming one. If a breach affects your information, we will notify you as the law requires.
1.10 Your rights and choices
US state privacy rights (including California). Depending on where you live, you may have the right to know what we hold about you, to get a copy, to correct it, and to delete it, and to opt out of the sale or sharing of personal information. We don't sell or share personal information for advertising, so there is nothing to opt out of. We will verify your identity before acting, respond within the time the law allows, and won't treat you worse for asking. Records we must keep by law may be exempt from deletion, and we will tell you when one applies. For contacts, see Section 1.6. We extend these rights to all US residents, whether or not a particular state law applies to us. In the past 12 months, we have not sold or shared personal information.
If you are in the EEA, UK, or Switzerland. Verasio is directed to US businesses. We don't claim to be set up for GDPR compliance in every respect. Where those laws apply to data we handle, you may have the right to access, correct, erase, restrict, object to, or move your data, and to complain to your local authority. For visitor and tenant data, our legal bases are performing our contract, our legitimate interests in running and securing the service, legal obligations, and consent where we ask for it. For contacts, the tenant is the controller and we act as its processor under the DPA in Section 5. Verasio is offered only to businesses established in the United States, and we have not appointed an EU or UK representative. If the law requires a transfer mechanism for data we process, we will sign standard contractual clauses on request.
1.11 Children
Verasio is a business service for adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from children under 13. If you think a child has given us information, contact us and we will delete it.
1.12 Where data is processed
We process data in the United States. If you use Verasio from elsewhere, your information is still processed in the United States.
1.13 Changes and contact
If we make a material change, we will tell account holders by email or in the product before it takes effect. The current version is always at verasioapp.com/privacy.
Questions and privacy requests: use the form on verasioapp.com. By mail: ClientConnect, Inc., 5201 W Kennedy Blvd, Suite 925, Tampa, FL 33609. By phone: 800-800-4045.
2. Terms of Service
Effective date: October 4, 2026 · ClientConnect, Inc.
These Terms govern your use of Verasio, a CRM operated by ClientConnect, Inc., a Wyoming corporation ("Verasio," "we," "us"). The Verasio software is owned by Logistic Investments, Inc. and licensed to ClientConnect. By creating an account or using the service, you agree to these Terms, the Privacy Policy, the Acceptable Use rules in Section 3, and, for personal data you put in Verasio about your own customers, the Data Processing Addendum in Section 5. If the DPA and these Terms conflict on how personal data is processed, the DPA controls. On everything else, these Terms control.
2.1 The service
Verasio is a CRM that shapes itself to how your business runs. It holds your contacts and conversations, sends and receives texts, email, and calls, sends documents for signature, and lets you work with AI agents in chat. Each customer gets its own workspace (a "tenant"). Verasio is a business tool for use in your own operations. It is not a consumer service.
2.2 Eligibility, accounts, and roles
You must be at least 18 and able to form a binding contract. If you sign up for a company, you confirm you can bind it, and "you" means that company. Verasio is offered only to businesses established in the United States.
Every tenant has an Owner. The Owner has final say over the tenant: billing, who gets access, approval of AI changes to the tenant's setup, LLM log retention, and receipt of the data export described in Section 2.6. Admins and Users act within the permissions the Owner gives them. You are responsible for your credentials, your API keys, and everything done under them, including by people you give access to.
Verasio staff with platform administrator access can reach tenant data only to give support, investigate abuse, or keep the service running.
2.3 Electronic transactions
You agree to deal with us electronically. Agreements, notices, and invoices we send electronically count as written. Keep a current email address on your account.
2.4 Fees and billing
Fees are the ones shown when you sign up or in your order. Billing runs through Stripe. Usage charges, such as carrier fees for texts and calls, signing envelopes, and AI use on the platform key, are billed as your plan states. We may change prices on 30 days' notice, and the new price applies from the next billing period.
You authorize us to charge the payment method on file. If a charge fails, the account becomes past due and Section 2.6 applies.
2.5 Taxes and refunds
Fees exclude taxes, which you are responsible for. We collect them where the law requires. Fees are non-refundable except where the law requires a refund.
2.6 Non-payment
We tell you plainly what happens if payment stops. The day counts run from the day the account became past due.
| Stage | When | What happens |
|---|---|---|
| Grace period | Day 0 to day 7 | The account keeps working. The Owner sees a banner in the product and gets a daily email. |
| Read-only | Day 7 | No sends and no new signing envelopes. Inbound messages still log. |
| Suspended | Day 30 | Login shows only the billing page. |
| Deletion | 90 days after suspension | We export the data to the Owner, then delete it. |
Paying the outstanding balance before deletion restores the account. While an account is read-only or suspended, opt-out requests from contacts are still honored. We make the export available to the Owner in a standard, readable file format. Deleted data can remain in backups until they expire. We email the Owner at the account email at least 7 days before deletion.
2.7 Your data and records
You own your data. We host it and process it for you to provide the service. You give us the limited rights we need to do that: to store, process, transmit, and display your data and your contacts' data so the features you use work.
- Signed PDFs and certificates are stored in your tenant's own storage path. Siglio keeps its copies for 30 days after an envelope closes and nothing past that.
- Contacts are soft-deleted when you delete them in normal use. Hard deletion exists for privacy-erasure requests.
- You are responsible for knowing how long the law requires you to keep your own records, and for keeping them.
- We never use your data to train AI models.
2.8 AI features
Verasio uses AI models to help you set up and run your CRM. AI can be wrong. So:
- AI data actions run under the permissions of the person who asked.
- AI changes to your setup (fields, objects, workflows, templates, integrations) need Owner approval in the Verasio interface. They can never be approved through the API or MCP.
- Every AI action, approved or not, is written to the contact timeline with the model and the prompt that produced it.
- LLM call logs (prompts and responses) are kept 90 days by default. The Owner can change that per tenant.
- If you bring your own LLM key, we never swap in the platform key. You are responsible for that provider's terms and charges.
- You are responsible for what you approve and what you send. Review AI-written messages before they go to a contact.
- Using AI features is subject to Section 3.
AI use on the platform key may have limits or charges, as your plan states.
2.9 Your e-signature responsibilities
Signing runs through Siglio. Electronic signatures are broadly enforceable in the United States under the federal ESIGN Act and state law, but enforceability depends on facts we don't control: what is being signed, who signs, and how you got their agreement to sign electronically. So:
- Consumer determinations are yours. You decide whether a consumer is involved and, if so, you handle the consumer disclosures and consents the law requires. Verasio doesn't do that for you.
- Excluded documents. Don't use signing for documents the law excludes from electronic signature or that need a handwritten signature, notarization, or witnessing, including wills and the other categories in 15 U.S.C. § 7003.
- No legal advice, no enforceability promise. Verasio doesn't give legal advice and doesn't promise that any signature will be held valid.
You don't need to accept Siglio's own terms. These Terms apply to your use of signing through Verasio.
2.10 Contacts, texting, and email
You represent that, for every contact you load or message through Verasio, you have a lawful basis to contact them and the consent the law requires for the channel you use, including consent under the Telephone Consumer Protection Act and similar state laws for texts and calls. Section 3 sets the rules in detail.
To send texts, Verasio registers each tenant as its own brand for carrier messaging (10DLC), under carrier accounts that Verasio holds. You must give us accurate business information for that registration. False or incomplete information can get your messaging blocked or your account suspended. Carriers set their own rules and can block or filter traffic. We are not responsible for carrier decisions.
2.11 Acceptable use
Section 3 is part of these Terms. Breaking it can lead to suspension under Section 2.14.
2.12 API keys, MCP, and integrations
API keys and MCP connections are credentials. Keep them secret and rotate them if you think they leaked. An AI agent or tool you connect through the API or MCP acts with the permissions of the user or key you connected it with, and you are responsible for what it does. Connections can't approve AI changes to your setup. We may apply rate limits and technical controls to protect the service.
You may not reverse engineer the service, resell raw access to it, or use it to build a competing service.
2.13 Support and service levels
Support comes through the form on verasioapp.com. We work to answer quickly, but we don't offer a service level agreement, an uptime commitment, or a guaranteed response time. The service may be unavailable from time to time, including for maintenance and carrier outages. Verasio does not currently hold a SOC 2 report.
2.14 Suspension and termination
The Owner can close the account at any time by asking us through the form on verasioapp.com. Download what you need first. We may suspend or end an account for non-payment (Section 2.6), for breaking Section 3, for risk or verification problems, or where carriers or the law require it. For serious abuse, such as spam, fraud, or carrier violations, we may suspend immediately without notice.
If you close your account yourself, we apply the same 90-day period before export and deletion.
Sections 2.4 (for fees owed), 2.7, 2.9, 2.10, 2.15 to 2.19, and 2.21 survive termination.
2.15 Intellectual property
The Verasio software, API, documentation, and brand are owned by Logistic Investments, Inc. and licensed to ClientConnect. We give you a limited, non-exclusive, non-transferable license to use them while your account is in good standing. You keep ownership of your data. If you send us feedback, we may use it without obligation. You own the setup built for your tenant, such as custom fields, workflows, and templates created for you. We keep ownership of the platform and our pre-built templates.
2.16 Disclaimers
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE. WE DO NOT WARRANT THAT AI OUTPUT WILL BE ACCURATE, THAT ANY MESSAGE WILL BE DELIVERED, OR THAT ANY SIGNATURE WILL BE VALID OR ENFORCEABLE.
2.17 Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW: (A) NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, OR GOODWILL; AND (B) OUR TOTAL LIABILITY ARISING OUT OF OR RELATING TO THE SERVICE IS LIMITED TO THE FEES YOU PAID US IN THE TWELVE MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM. These limits do not apply to your payment obligations, your indemnification obligations, or liability that cannot be limited by law. One cap applies to all claims combined, including claims under the Data Processing Addendum.
2.18 Indemnification
You will defend and indemnify ClientConnect, Inc., Logistic Investments, Inc., and their officers, directors, and personnel against third-party claims, and resulting damages, penalties, and reasonable attorneys' fees, arising from: (a) your data and content; (b) claims by contacts about contact information or consent you supplied or failed to obtain, including claims under the TCPA and similar state laws; (c) your breach of Section 2.9, 2.10, or 3; or (d) your products and services, and messages you approve or send, including AI-written ones. We will give you prompt notice of a claim and reasonable cooperation at your expense.
2.19 Governing law and venue
These Terms are governed by the laws of the State of Wyoming and applicable federal law, without regard to conflict-of-laws rules. The exclusive venue for any dispute is the state or federal courts located in Wyoming, and each party consents to personal jurisdiction there.
2.20 Changes to these Terms
We may update these Terms. For material changes we will give notice through the product or your account email before the change takes effect. Using the service after the effective date means you accept the change. The current version is always at verasioapp.com/privacy#terms.
2.21 Notices and general
Legal notices to us go to: ClientConnect, Inc., 5201 W Kennedy Blvd, Suite 925, Tampa, FL 33609. Legal process is served on our registered agent in Wyoming. Operational messages go through the form on verasioapp.com. Notices to you may go to the email on your account and are effective when sent.
These Terms, with the Privacy Policy, Section 3, and Section 5, are the whole agreement about the service. If a provision is unenforceable, the rest stands. Not enforcing a provision is not a waiver. You may not assign these Terms without our consent. We may assign them in a merger, acquisition, or asset sale. Neither party is liable for delay or failure caused by events beyond its reasonable control. The parties are independent contractors.
3. Acceptable Use
This section is part of the Terms of Service. It covers texting consent, opt-out handling, and what you can't send or do with Verasio.
The short version
- Message people who asked to hear from you, for the reason they asked.
- When someone says stop, stop. Verasio records it. You honor it.
- Don't send what carriers and the law prohibit, and don't dodge the controls that enforce that.
- AI works for you under your rules. It doesn't get to bypass them.
3.1 Who this applies to
Every tenant, everyone the tenant gives access to, and every AI agent or tool connected to the tenant through the product, the API, or MCP. You are responsible for all of them.
3.2 Texting consent
- You need consent before you text. For marketing texts, that means written consent from the person, for your business, for that kind of message. For other texts, you still need the consent the law requires for that message.
- Keep proof. Record who agreed, when, how, and to what. Verasio stores every consent change with a timestamp and a source. That does not replace your own proof of the original consent, and you must give it to us when we ask.
- No bought lists. Don't text anyone whose number you purchased, rented, scraped, or appended, or whose consent was given to someone else.
- Say who you are. Identify your business in your messages. When you collect consent, tell people what they are signing up for, how often you may text, that message and data rates may apply, and how to stop. Link your privacy policy and terms. Sample wording: "By giving us your number, you agree to receive texts from (your business name) about (what you will send). Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help. Consent is not a condition of any purchase. See our Privacy Policy and Terms."
- Stay inside your registration. Each tenant is registered as its own brand for carrier messaging, with a described use. Don't send other kinds of messages than the ones you registered, and don't share your registration with another business.
- Quiet hours. Automated texts from Verasio go out only between 08:00 and 20:00 in the contact's local time. Some states set shorter windows or extra limits. Following those is your job. You are responsible for keeping each contact's time zone accurate.
- Calls. If you call contacts through Verasio, you need the consent the law requires for the way you call, including for prerecorded or AI-generated voices. Follow the National Do Not Call Registry and recording-consent laws in the places you call. Calls that use a prerecorded or AI-generated voice need prior express written consent for marketing and prior express consent otherwise.
3.3 Opt-out handling
What Verasio does
- Handles STOP, UNSUBSCRIBE, and START in the core of the product, for every tenant.
- Records every consent change with a timestamp and a source.
- Handles email opt-outs and complaints by setting stop_emails on the contact, with a source.
- Keeps logging inbound messages even when an account is read-only. Opt-outs keep working while an account is read-only or suspended.
What you must do
- Never text a contact who has opted out unless they opt back in themselves, by replying START or by giving you a new consent you can document.
- Treat any clear request to stop as an opt-out, in any form: a reply, a call, an email, or a message in your own words. The law lets people withdraw consent in any reasonable way, not only with a keyword. Record it. Verasio handles STOP, UNSUBSCRIBE, and START for you. For any other way a contact says stop, such as STOP ALL, CANCEL, or a message in their own words, you must record the opt-out in the contact's consent status.
- Treat a request to stop all contact as covering every channel.
- Put an unsubscribe link and your own valid postal address in marketing email, as the CAN-SPAM Act requires. Never email a contact flagged stop_emails.
- Don't import contact lists and flip contacts back to opted-in without proof of consent.
3.4 Prohibited content and conduct
You may not use Verasio to send, store, or do any of the following.
Content
- Anything illegal where you or the recipient are located.
- Phishing, credential theft, fraud, forgery, or deceptive requests for money or information.
- Impersonation of a person or organization, including AI-generated voices or messages that pretend to be a real person you aren't authorized to speak for.
- Threats, harassment, hate, or content that sexualizes minors.
- Content carriers restrict or prohibit: adult content, hate speech, alcohol, firearms, tobacco and vaping, and cannabis products, unless a carrier-compliant program covers it.
- Malware, malicious links, or documents meant to harm recipients.
- Debt collection that breaks federal or state law, and offers carriers treat as high risk, such as payday loans or get-rich-quick schemes. Carriers also treat as high risk: payday and short-term loans, get-rich-quick and work-from-home offers, crypto and investment promotions, gambling, and third-party lead generation.
Conduct
- Unsolicited bulk messages, spam, or messages to people who haven't agreed to hear from you.
- Ignoring or working around an opt-out, quiet hours, or a carrier block.
- Evading carrier filtering, for example by rotating numbers, splitting traffic across numbers or brands, or hiding who the sender is.
- Registering another business's traffic under your brand, or giving us false registration information.
- Interfering with or getting around security, rate limits, permissions, or metering.
- Using AI to get around the rules above. That includes prompting an agent to contact people who opted out, to bypass an approval, or to act beyond the permissions of the user it runs under.
- Trying to approve an AI change to your setup through the API or MCP. Those approvals happen only in the Verasio interface, by the Owner.
- Using Verasio's output to build or train a competing model or service.
- Putting sensitive data in Verasio that you have no need and no right to hold. Never store payment card numbers or protected health information in Verasio. Store government ID numbers only if you need them.
3.5 Restricted industries
Some industries draw extra scrutiny from carriers, for example collections, debt settlement, credit repair, and similar lending or financial services. For these, we may require approval first, ask for extra registration, limit texting, or decline to enable it.
3.6 Enforcement
We watch for abuse, carrier complaints, and consent problems. We may ask you for proof of consent and for details of how you use the service. We may block messages, pause texting, suspend the account, or end it. For serious abuse we may act immediately without notice. Carriers can also require us to share a tenant's identity with them. We may report unlawful activity to law enforcement. Our rights under Section 2.14 apply.
To report abuse of Verasio, use the form on verasioapp.com.
4. Subprocessors
These are the companies that handle data for Verasio, and what each does. Last updated: October 4, 2026. Each one is bound by a contract that limits it to providing its service to us.
| Subprocessor | What it does for Verasio | Data it handles | Who it applies to |
|---|---|---|---|
| Supabase | Database, sign-in, and file storage. Signed PDFs and certificates sit in each tenant's own storage path. | All tenant and contact data, stored files | Every tenant |
| Vercel | Hosts the application and the verasioapp.com website | Web requests, logs, data passing through the app | Every tenant, website visitors |
| Cloudflare | DNS, network security, and tunnels. Sets up DNS records for tenant email domains. | Traffic data, DNS records, security signals | Every tenant, website visitors |
| Bandwidth | Text messaging and carrier connectivity, including carrier brand registration | Contact phone numbers, message content, delivery status | Tenants that send texts |
| Twilio | Voice calls and branded caller ID | Phone numbers and call data, plus recordings or transcripts if you use them | Tenants that make calls |
| Mailgun | Sends and receives email, including tenant email from the tenant's own domain, platform mail, and the website booking form | Email addresses, message content, delivery events, booking form entries | Tenants that send email, website visitors |
| Siglio | E-signature. Delivers signing requests by email or text, runs signing, and returns the signed result to Verasio. Deletes its files 30 days after an envelope closes. | Documents sent for signature, signer names and contact details, signing events | Tenants that send documents for signature |
| Stripe | Billing and payment processing. Card details go to Stripe, not to us. | Billing contact, payment method reference, billing history | Tenants that pay by card |
| Anthropic | Default LLM provider | The prompts we send, which include the tenant data the AI needs for the task, and the responses | Tenants using the default AI |
| Tenant-chosen LLM provider | Any LLM provider a tenant connects with its own key | Same as above, sent under the tenant's key and the tenant's agreement with that provider | Only tenants that connect one |
Notes
- Tenant-chosen providers are the tenant's choice. The tenant's Owner decides which provider to connect, and the tenant answers for its own agreement with that provider and its terms. We never replace a tenant's key with ours.
- Carriers that deliver texts and calls are not our subprocessors. They are networks that carry the traffic. See Privacy Policy Section 1.7.
- Our own business tools. Email and calendar tools our team uses hold booking form inquiries. They are our own business tools and are not used to process tenant data.
- Where data is processed. We process data in the United States.
- Changes. We email the tenant's Owner at least 30 days before a new subprocessor handles tenant data. The process is in the DPA, Section 5.6.
5. Data Processing Addendum
This addendum is part of the Terms of Service between a tenant ("you") and ClientConnect, Inc. ("Verasio," "we"). It applies automatically when you use Verasio and covers the personal data you put into Verasio about your own customers, leads, and other contacts. It needs no separate signature. If your own contracts need a countersigned copy, ask us through the form on verasioapp.com.
5.1 Roles and scope
You are the controller of your contacts' personal data (the "business" under California law). Verasio is your processor (your "service provider"). We process that data only to provide Verasio to you.
- Subject matter and duration: running your CRM, for as long as your account exists plus the wind-down in Section 2.6.
- What we do with it: store, display, send, receive, sign, and run AI actions on it, as you direct.
- Whose data: your contacts, leads, customers, and signers.
- What kind: contact details, messages, call data, notes, custom fields you define, signed documents and signing records, consent records, and the AI action log.
- Sensitive data: Verasio isn't built for special categories of data, and you should not store them unless you need to. If you do, you are responsible for the extra rules that apply. Do not store payment card numbers or protected health information in Verasio, and we do not offer a HIPAA business associate agreement.
5.2 Your instructions
We process your data only on your documented instructions. Those are the Terms, your settings, and what you and your users do in the product, the API, and MCP. That includes AI actions run under a user's permissions. We may also process data where the law requires it, and we'll tell you first unless the law forbids it. If we think an instruction breaks the law, we'll tell you.
5.3 Confidentiality and access
Everyone at Verasio who can reach your data is bound by confidentiality. Staff with platform administrator access use it only to give support, investigate abuse, or keep the service running.
5.4 Security
We protect your data with encryption in transit, tenant separation enforced in the database, role-based access (Owner, Admin, User), audit logging, and human approval of AI changes to your setup. These measures are described in Privacy Policy Section 1.9. Verasio does not currently hold a SOC 2 report or similar certification.
5.5 AI processing
- We never use your data to train models. Our default provider's commercial terms don't allow it either.
- Every AI action is logged to the contact timeline with the model and prompt.
- LLM call logs (prompts and responses) are kept 90 days by default. You can change that in your tenant settings. Deletion is enforced nightly.
- If you bring your own LLM key, we never replace it with ours.
- AI providers are on the subprocessor list. Each provider handles data under its own terms, which can include short-term retention for abuse monitoring.
5.6 Subprocessors
You allow us to use the subprocessors listed in Section 4. We have a contract with each one that limits it to what it needs to do for us, and we answer for how they handle your data. Before a new subprocessor handles your data, we'll email your Owner at least 30 days ahead. If you object in writing within that time, on reasonable data protection grounds, we'll work with you. If we can't resolve it, you may stop using the affected feature or close your account. Providers you connect yourself, such as your own LLM provider, are your choice and not covered by this section.
5.7 Requests from your contacts
If one of your contacts asks us to access, correct, delete, or move their data, we'll send them to you, unless the law says we must respond ourselves. You can handle most requests in the product. Hard deletion is available for a privacy-erasure request, and we'll help you with it. Tell us if you need help with a request, and we'll give reasonable help.
5.8 Breaches
If we confirm a personal data breach affecting your data, we'll tell your Owner without undue delay, and we aim to do it within 72 hours of confirming. We'll share what we know, what we're doing about it, and what you may need to do.
5.9 Return and deletion
- When an account is closed or goes unpaid, Section 2.6 sets the timeline: we keep the data 90 days past suspension, then export it to the Owner and delete it.
- Signed PDFs and certificates in your tenant's storage path are deleted with the rest of your data. Siglio deletes its own copies 30 days after an envelope closes.
- While you're a customer, you can delete contacts yourself. They are soft-deleted in normal use. Ask us for a hard delete if the law calls for one.
- Deleted data can remain in backups until they expire.
- We may keep data where the law requires us to, and we'll tell you when that applies.
5.10 Information and audits
On request, we'll give you the information reasonably needed to show we're meeting this addendum, such as a written answer to a security questionnaire, once a year. An on-site audit happens only if the law requires one, with reasonable notice, at your cost, and without exposing other tenants' data.
5.11 Privacy law terms
California (CCPA and CPRA). We won't sell your contacts' personal information or share it for cross-context behavioral advertising. We'll use it only for the business purposes in this addendum. We won't keep, use, or disclose it outside our direct business relationship with you, and we won't combine it with other data except as the law allows. We'll give it the level of protection the law requires, and we'll tell you if we can no longer meet that. You may take reasonable steps to stop and fix unauthorized use.
GDPR and similar laws. Verasio is directed to US businesses, and your data is processed in the United States. If GDPR, UK GDPR, or Swiss law applies to your use of Verasio, the terms of this addendum are meant to serve as the processor terms those laws require. We make no claim of GDPR certification or adequacy. We don't offer Verasio to tenants established in the EEA, UK, or Switzerland. If the law requires a transfer mechanism for personal data we process for you, we will sign standard contractual clauses on request.
5.12 What you take on
You are responsible for having a lawful basis to hold and contact your contacts, for giving them the notices the law requires, for getting and recording the consent in Section 3, for keeping your contact data accurate, and for honoring opt-outs. Your instructions to us must be lawful.
5.13 Order of precedence and liability
If this addendum conflicts with the Terms on how personal data is processed, this addendum controls. Liability under it is subject to the limits in Section 2.17 of the Terms.
Questions about this addendum: use the form on verasioapp.com.