Data Processing Agreement
This agreement is between the merchant using Verilo (the Merchant) and Bailee Satie trading as Verilo, an Australian sole trader, ABN to be added (Verilo). It applies to personal information about the Merchant's customers that Verilo handles for the Merchant (Customer Data). The Merchant accepts it in the Verilo dashboard under Settings. Version 2026-10-04.
1. Roles
The Merchant decides why Customer Data is handled: to check damaged-item claims it chooses to send for verification. Verilo handles Customer Data only to provide that service, on the Merchant's instructions given through its use of Verilo, and for no other purpose.
2. Customer Data
Order details for each claim (order, items, product photos, value, shipments, the customer's name and email address); the customer's recordings, photos and phone motion during the verification; device, browser and connection details; and the results.
3. Confidentiality
Only people who need it to run the service can access Customer Data, and they are bound to keep it confidential.
4. Security
Verilo keeps the security measures described on its Security page, including encryption in transit and at rest, separation between merchants, evidence that cannot be edited, and an audit log.
5. Sub-processors
The Merchant agrees to Verilo using these service providers:
Fly.io: Application hosting (United States (Ashburn, Virginia))
Neon: Database (orders, claims, results, audit log) (United States (AWS us-east-1))
Cloudflare: Storage of recordings and photos (R2) (United States)
Shopify: Order data and billing, as the merchant's platform (Global)
Gorgias: Messages and notes in the merchant's helpdesk, when connected (Global)
Zendesk: Messages and notes in the merchant's helpdesk, when connected (Global)
Google Workspace: Email with merchants (Global)
Crisp: Live chat with merchants and website visitors (European Union (France))
Verilo will email the Merchant at least 14 days before adding or replacing a sub-processor. If the Merchant objects on reasonable privacy grounds and the parties cannot resolve it, the Merchant may stop using Verilo.
6. Overseas disclosure
Customer Data is stored and processed in the United States. Verilo requires its service providers to protect it to a standard consistent with the Australian Privacy Principles.
7. Requests from individuals
Verilo will pass any request it receives about Customer Data to the Merchant, and help the Merchant answer requests for access or correction.
8. Data breaches
Verilo will tell the Merchant without undue delay, and within 72 hours, after becoming aware of a data breach affecting Customer Data, with what is known about it. Verilo will help the Merchant assess whether it is an eligible data breach under the Notifiable Data Breaches scheme and with any notifications.
9. Retention and deletion
Recordings and photos are deleted automatically 90 days after capture, or after the longer period the Merchant sets in Settings (up to one year). Results, claim records and the audit log are kept while the Merchant uses Verilo. On the Merchant's request, Verilo deletes the Merchant's Customer Data within 30 days, except where the law requires it to be kept.
10. Information and review
Verilo will answer the Merchant's reasonable written questions about how it protects Customer Data.
11. Term and law
This agreement forms part of the Verilo Terms of Service (verilo.app/terms). It applies while Verilo handles Customer Data for the Merchant, and its confidentiality and deletion terms continue after that. It is governed by the laws of Western Australia.
Bailee Satie trading as Verilo · ABN to be added · bailee@verilo.app