Data Processing Terms
Last updated: 27 July 2026
Purpose of this page
This page summarises our standard processing model. It is not a signed data-processing agreement. Customers receive contractual processing terms appropriate to their service, configured integrations, data location and controller responsibilities.
Roles
A customer organisation is normally the controller for the people, clients, sites, assets, jobs and operational records it manages in Nemeton Works. Virtus Nemeton acts as processor for that data and processes it on documented customer instructions.
Virtus Nemeton remains controller for its own contracting, account administration, security, billing and direct business communications.
Processing scope
Processing may cover user identity and contact information, organisation membership, client and site contacts, assignments, job sheets, timesheets, photographs, maintenance records, customer communications, audit events and support information. The exact scope is defined by the customer's configuration and agreement.
Customers must provide lawful instructions, manage their own notices and lawful bases, and avoid uploading special-category or criminal-offence data unless this is agreed in writing with appropriate safeguards.
Subprocessors
Only providers required by the contracted service or enabled integration are used.
| Provider | Purpose |
|---|---|
| Vercel | Application hosting and delivery |
| Supabase | Authentication, database and file storage |
| Resend | Email delivery |
| Stripe | Payment processing |
| Google or Microsoft | Optional sign-in and calendar integration |
| Twilio | Optional SMS delivery |
| Anthropic | Optional AI-assisted workflow processing |
Contractual safeguards and transfer mechanisms must be confirmed in the executed agreement and processor register before a provider handles production customer data.
Security and assistance
Our standard model includes tenant-scoped access, database Row Level Security, encrypted transport, managed encryption at rest, role-aware server authorisation, audit logging and human approval for consequential machine-proposed actions.
We support customers with data-subject requests, breach assessment, deletion or return of data, and reasonable audit information as defined in the applicable agreement.
Request contractual terms
Contact team@virtusnemeton.co.uk to request the current customer DPA, subprocessor register and security information.