Data Processing Addendum

How Virtus Professional Services LLC handles Personal Data for a business customer of Virtus that is subject to United States state privacy laws.

Effective October 3, 2026

  • This addendum is part of the Master Services Agreement or Terms of Use. It applies automatically when Virtus processes Personal Data for a business customer that is subject to U.S. state privacy laws. No separate signature is needed.
  • Virtus acts as a service provider, contractor, or processor. It processes Personal Data only on documented instructions from the customer, does not sell or share it, and does not combine it with other data except as the law permits.
  • The service is offered in the United States. It must not be used to process Personal Data of people in the EEA or the UK, and customers must not submit restricted data such as Social Security numbers, health information, or tax return data.
  • Subprocessors are listed by category. A named list is available on request, and a customer has 15 days to object to a new one.
  • Virtus does not use Personal Data to train AI models and prohibits its subprocessors from doing so. After the agreement ends, a customer can request an export for 30 days, and data is then deleted on the stated schedule.

This summary is for convenience. The full text below controls.

Scope and effect

This Data Processing Addendum (including its annexes, this “DPA”) is a standard form published by Virtus Professional Services LLC (“Provider”). It is part of the Master Services Agreement between Provider and the customer (“Customer”) or, where Customer uses Virtus under the Terms of Use without a Master Services Agreement, those terms (as amended, the “Agreement”). Provider and Customer are each a “Party” and together the “Parties.”

This DPA applies automatically when Provider Processes Personal Data for a Customer that is a business subject to State Privacy Laws. No separate signature is needed. It is incorporated into the Agreement and takes effect when the Agreement does.

Definitions

These terms have the meanings below for purposes of this DPA. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” means the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract, or otherwise.

Applicable Data Protection Laws means the privacy, data protection, and data security laws and regulations of any jurisdiction within the United States that apply to Provider’s Processing of Personal Data under the Agreement, including, as and to the extent applicable, the State Privacy Laws.

Customer Data means information provided or otherwise made available by or on behalf of Customer to Provider for Processing on Customer’s behalf to perform the Services.

Data Subject means the identified or identifiable natural person to whom Personal Data relates.

Information Security Incident means a breach of Provider’s security resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data in Provider’s possession, custody, or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.

Personal Data means Customer Data that constitutes “personal data,” “personal information,” or “personally identifiable information” as defined in Applicable Data Protection Laws, or information of a similar character regulated by them. Personal Data does not include information that Provider receives, collects, or generates independently of the Services and not from or on behalf of Customer.

Process or Processing means any operation or set of operations performed by Provider (or on Provider’s behalf) for Customer under the Agreement on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Security Measures has the meaning given in section 5 (Security).

Services means the Virtus hosted research service and any related services that Provider supplies to Customer under the Agreement (called the Service in the Master Services Agreement).

State Privacy Laws means, collectively, the comprehensive state-specific data privacy laws (and any implementing regulations) currently in effect and applicable to Provider’s Processing of Personal Data under the Agreement.

Subprocessors means Provider’s Affiliates and third parties that Provider engages to Process Personal Data in relation to the Services.

Duration and scope

This DPA remains in effect for as long as Provider Processes Personal Data, even after the Agreement expires or ends.

Processing of Personal Data that is subject to the State Privacy Laws, and for which Customer is a business, controller, processor, or service provider (as those terms are defined in the State Privacy Laws), is also subject to Annex 2 (State privacy laws) to this DPA.

United States only. The Services are offered to customers in the United States. Customer will not use the Services to Process Personal Data of individuals in the European Economic Area or the United Kingdom unless the Parties first agree to a written amendment that addresses it.

Customer instructions

Provider will Process Personal Data only in accordance with Customer’s documented instructions, including as set out in this DPA, the Agreement, any applicable Order Form, and any other written instructions Customer provides from time to time that are consistent with the Agreement and this DPA. If Customer gives instructions that are outside the scope of the Services, or that would require Provider to materially change the Services or do additional work the Agreement does not contemplate, the Parties will agree to them in a written amendment to this DPA or another written agreement.

By using the Services, Customer instructs Provider to Process Personal Data to provide the Services and to perform its other obligations and exercise its rights under the Agreement. The Parties agree that the details of Provider’s Processing of Personal Data, including the Parties’ respective roles, are as described in Annex 1 (Data processing details) to this DPA.

Security

Provider Security Measures. Provider will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data, as described in Annex 3 (the “Security Measures”), taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risks to Data Subjects. Provider may update the Security Measures from time to time, including to maintain or improve security or address changes in Applicable Data Protection Laws, if the updated measures do not materially decrease the overall protection of Personal Data.

Security compliance by Provider staff. Provider will require that its personnel who are authorized to access Personal Data are subject to appropriate confidentiality obligations.

Information Security Incidents. Provider will notify Customer without undue delay of any Information Security Incident of which Provider becomes aware. The notice will describe, to the extent then known, the available details of the Information Security Incident, including steps taken to mitigate the potential risks and steps Provider recommends Customer take to address it. Provider’s notice of or response to an Information Security Incident is not an acknowledgement of fault or liability. Provider will reasonably cooperate with Customer and take commercially reasonable steps, to the extent within Provider’s control, that Customer reasonably requests and the Parties agree in good faith, to help investigate the Information Security Incident.

Customer is solely responsible for complying with notification laws that apply to Customer and for any third-party notification obligations related to an Information Security Incident. If Customer determines that an Information Security Incident must be notified to any regulatory authority, Data Subject, the public, or others under Applicable Data Protection Laws, and the notice refers to or identifies Provider, then, where the law permits, Customer will (i) notify Provider in advance, and (ii) in good faith consult with Provider and consider any clarifications or corrections that Provider reasonably recommends or requests that (a) relate to Provider’s involvement in or relevance to the Information Security Incident and (b) are consistent with applicable law.

Customer security responsibilities and assessment

Customer’s security responsibilities. Without limiting Provider’s obligations under section 5 (Security), Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (b) securing the account authentication credentials, systems, and devices Customer uses to access the Services; and (c) exporting and keeping any copies of Personal Data that Customer needs to retain, as applicable.

Customer’s security assessment. Customer acknowledges that it has evaluated the Services, the Security Measures, and Provider’s commitments under this DPA and, based on the information Provider has made available, determines that they are adequate to meet Customer’s needs, including any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.

Data subject rights

Provider’s assistance. Taking into account the nature of the Processing of Personal Data, Provider will give Customer the assistance that is reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights under those laws (“Data Subject Requests”) with respect to Personal Data in Provider’s possession or control. To the extent the assistance requires work beyond the Services, Customer will compensate Provider at Provider’s then-current professional services rates, which Provider will make available on request, and Provider will give a good-faith estimate of the fees on request.

Customer’s responsibility for requests. If Provider receives a Data Subject Request, Provider will (i) promptly notify Customer, unless the law prohibits it, and (ii) advise the Data Subject to submit the request to Customer. Customer is solely responsible for responding to the request, unless applicable law requires otherwise.

Customer responsibilities

Customer will ensure, and is solely responsible for ensuring, that it has given all notices to, and obtained all consents and permissions from, third parties (including Data Subjects), and has reserved all necessary rights, in each case as Applicable Data Protection Laws require for Provider to Process Personal Data as the Agreement contemplates.

Customer represents and warrants to Provider that Customer Data does not and will not contain any Social Security numbers or other government-issued identification numbers; protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information about an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; health insurance information; biometric information; passwords or other credentials for third-party online accounts (other than credentials created for and used solely to access the Services); credentials to any financial accounts; tax return data; any payment card information subject to the Payment Card Industry Data Security Standard; personal data of children under 16 years of age; or any other information that falls within a special category of data as defined in Applicable Data Protection Laws (“Restricted Data”).

Subprocessors

Consent to Subprocessor engagement. Customer specifically authorizes Provider’s engagement of its Affiliates as Subprocessors and generally authorizes Provider to engage third parties as Subprocessors in accordance with this section.

Information about Subprocessors. Information about Subprocessors, including their functions and locations, is in Annex 4 of this DPA. Provider may keep using the Subprocessors it has already engaged as of the effective date of this DPA.

Requirements for engagement. When engaging a Subprocessor, Provider will enter into a written contract with it containing data protection obligations not less protective than those in this DPA, to the extent applicable to the nature of the services the Subprocessor provides. Provider remains responsible for performing all obligations subcontracted to the Subprocessor and is liable for the Subprocessor’s acts and omissions to the same extent as if Provider had performed the Processing itself.

Opportunity to object to changes. When Provider engages a new Subprocessor after the effective date of this DPA, it will notify Customer of the engagement, including the name and location of the Subprocessor and the activities it will perform, by written notice (including by email) to Customer’s designated contact for Services-related communications, or by other written means. If a new Subprocessor introduces a new functional category, Provider will also update Annex 4. If Customer objects in a written notice to Provider within 15 days after receiving the notice, on reasonable grounds relating to the protection of Personal Data, Customer and Provider will work together in good faith to find a mutually acceptable resolution. If the Parties cannot reach one within a reasonable time, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by written notice to Provider. Customer will pay Provider all amounts due and owing under the Agreement as of the date of termination, and Provider will refund any prepaid fees for the period after termination.

Audits

Reviews and audits of compliance. Customer may audit Provider’s compliance with its obligations under this DPA up to once per year, and on other occasions only to the extent Applicable Data Protection Laws require Customer to conduct an additional audit or a competent regulatory authority with jurisdiction over Customer requires it, in each case on Customer’s written request giving reasonable detail and, where available, supporting documentation of the applicable requirement. Provider will contribute to the audit by giving Customer the information and assistance reasonably necessary to conduct it.

If a third party is to conduct the audit, Provider may object to the auditor if the auditor is, in Provider’s reasonable opinion, not independent, a competitor of Provider, or otherwise manifestly unsuitable. If Provider objects, Customer must appoint another auditor or conduct the audit itself. To request an audit, Customer must submit a proposed audit plan to Provider at least two weeks before the proposed audit date, and any third-party auditor must sign a customary non-disclosure agreement that is mutually acceptable to the Parties (acceptance not to be unreasonably withheld) and provides for confidential treatment of all information exchanged in connection with the audit and any reports of its results or findings. The proposed plan must describe the scope, duration, and start date of the audit. Provider will review it and give Customer any concerns or questions, for example about a request for information that could compromise Provider security, privacy, employment, or other relevant policies, and will work cooperatively with Customer to agree on a final audit plan. Nothing in this section requires Provider to breach any duty of confidentiality.

If the controls or measures to be assessed in the requested audit are addressed in a SOC 2 Type 2, ISO, NIST, or similar audit report performed by a qualified third-party auditor within 12 months before Customer’s audit request, and Provider confirms there have been no known material changes in the audited controls since the date of the report, Customer agrees to accept that report instead of requesting an audit of those controls or measures.

An audit must be conducted during regular business hours, subject to the agreed final audit plan and Provider’s safety, security, and other relevant policies, and may not unreasonably interfere with Provider’s business activities. It is conducted remotely where practicable. It does not include access to the data of other customers, or physical access to facilities operated by Provider’s infrastructure hosting providers. Customer will promptly notify Provider of any non-compliance it discovers during an audit and give Provider any audit reports generated in connection with it, unless Applicable Data Protection Laws prohibit it. Customer may use audit reports only to meet its regulatory audit requirements or to confirm compliance with this DPA.

Audits are at Customer’s sole expense. Customer will reimburse Provider for its reasonable, documented costs in connection with any audit or inspection under this section, including reasonable internal time at Provider’s then-current professional services rates, which Provider will make available on request. Customer is responsible for any fees charged by the auditor it appoints.

Return and deletion

Cessation. Subject to this section, when any Services involving Processing of Personal Data stop (the “Cessation Date”), Provider will promptly stop all Processing of Personal Data for any purpose other than storage and Processing necessary to return, delete, or anonymize it, or as this DPA or applicable law otherwise permits or requires.

Return or deletion on request. To the extent technically possible, on Customer’s written request made no later than 30 days after the Cessation Date (the “Post-cessation Storage Period”), Provider will, within a commercially reasonable period after receiving the request, (i) return a complete copy of all Personal Data in Provider’s possession to Customer by export or another commercially reasonable secure method, and promptly afterward delete or anonymize all other copies, or (ii) at its option, delete or anonymize all Personal Data in its possession.

No instruction. If Customer gives no written instruction to delete or return Personal Data during the Post-cessation Storage Period, Provider will, within a commercially reasonable time after it ends, delete or render anonymous all Personal Data then in its possession, custody, or control to the fullest extent technically feasible, following the retention periods in Annex 1 (Data processing details). Copies in rolling encrypted backups are deleted as the backups expire, within the backup period stated in Annex 1.

Retention required by law. Provider may keep Personal Data to the extent applicable law permits or requires, and for no longer than that law requires, if Provider (i) maintains the confidentiality of that Personal Data and protects it in accordance with the Security Measures, (ii) Processes it only as necessary for the purposes specified in the law permitting or requiring the retention, and (iii) deletes or anonymizes it once the law no longer permits or requires its retention.

Artificial intelligence and automated processing

  • Provider will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether Provider’s own or a third party’s, unless Customer expressly authorizes it in writing.
  • Provider will prohibit its Subprocessors, including any AI model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement purposes, except as Customer expressly authorizes in writing.
  • The Services are not designed to make decisions that produce legal or similarly significant effects on Data Subjects. If the Services involve automated decision-making that produces such effects, Provider will (a) disclose the existence of that processing to Customer; (b) to the extent reasonably available to Provider, provide meaningful information about the logic involved, without requiring disclosure of Provider’s trade secrets or confidential information; and (c) reasonably cooperate with Customer, as Applicable Data Protection Laws require, so that Data Subjects can exercise their rights under those laws relating to automated decision-making.

Miscellaneous

Except as this DPA expressly modifies it, the Agreement remains in full force and effect. If this DPA conflicts with the other terms of the Agreement, this DPA controls on the protection of Personal Data. Despite anything to the contrary in the Agreement or any Order Form, the Parties acknowledge and agree that Provider’s access to Personal Data is not part of the consideration the Parties exchange under the Agreement.

Despite anything to the contrary in the Agreement, Provider may give any notice this DPA requires or permits to Customer (a) in accordance with any notice clause of the Agreement; (b) to Customer’s contact details for data protection in Annex 1; (c) to Provider’s primary points of contact with Customer; or (d) to any email address Customer designates in writing to receive Services-related communications or alerts. Customer is solely responsible for ensuring that those email addresses are valid.

Provider will cooperate in good faith with Customer to consider any amendments reasonably necessary to address compliance with Applicable Data Protection Laws. Provider may, on written notice, vary this DPA only to the extent necessary to maintain compliance with Applicable Data Protection Laws from time to time, if the variation does not materially reduce the protections afforded to Personal Data or materially increase Customer’s obligations under this DPA without Customer’s written agreement.

The total aggregate liability of either Party to the other, however arising, under or in connection with this DPA will under no circumstances exceed any limitations or caps on, and is subject to any exclusions of, liability and loss that the Parties agreed in the Agreement.

Annex 1 — Data processing details

  • Provider. Virtus Professional Services LLC. Provider’s mailing address for data protection matters is the one stated in the Order Form or available on request.
  • Contact details for data protection (Provider). admin@virtusprofessionalservices.com.
  • Provider activities. Provider operates a hosted research workspace over public United States federal tax sources, including a research library, search, a document reader, citation and download features, and AI-assisted research features.
  • Customer. The entity or other person that is a counterparty to the Agreement. Customer’s address and contact details for data protection are those stated in the Order Form or notified to Provider in writing.
  • Customer activities. Customer’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations.
  • Categories of Data Subjects. Customer’s personnel and Authorized Users, and the business contacts they enter into the Services.
  • Categories of Personal Data. Name, work email address, role, organization membership, authentication and session records, workspace activity and audit events, and support messages.
  • Sensitive categories of data. None. As section 8 (Customer responsibilities) provides, Customer must not submit Restricted Data to the Services without the Parties’ prior written agreement. Additional safeguards for sensitive data: not applicable.
  • Frequency of Processing. Continuous while Customer’s account is active, as initiated by Customer in and through its use, or use on its behalf, of the Services.
  • Nature of the Processing. Processing operations required to provide the Services and to perform Provider’s obligations under the Agreement and this DPA.
  • Purpose of the Processing. As necessary to provide the Services as Customer initiates by using them, and to comply with Customer’s documented instructions as permitted under and in accordance with this DPA and the Agreement.
  • Duration of Processing. For the term of the Agreement, plus the period determined under section 11 (Return and deletion).
  • Transfers to Subprocessors. As, and for the purposes, described in Annex 4 (Subprocessors).

Retention periods. These follow the retention schedule in the Privacy Policy. Some of these records, such as site visit and billing records, are kept for Provider’s own purposes and are listed for completeness.

  • Account and workspace data: for the life of the account.
  • Scheduled deletion: a 30-day soft-deletion period, followed by a 7-day final hold before permanent deletion.
  • Account export artifacts: 7 days.
  • Operational logs: 30 days.
  • Site visit records, which contain no IP address: about 13 months.
  • Application, security, and administrator audit records: 24 months.
  • Transactional email outbox records: 30 days.
  • Email delivery metadata: 90 days.
  • Billing, tax, contract, and deletion receipts: 7 years.
  • Rolling encrypted backups: 35 days.
  • Raw research query text is not retained by default. If a workspace expressly approves retention, the maximum period is 30 days.

Annex 2 — State privacy laws

For purposes of this Annex 2, the terms “business,” “controller,” “processor,” “commercial purpose,” “sell,” “share,” “service provider,” and “contractor” have the meanings given to them in the applicable State Privacy Laws, and “personal information” means Personal Data to the extent it is “personal information,” “personal data,” or a similar term governed by the State Privacy Laws.

It is the Parties’ intent that, for any personal information, Provider is a service provider, contractor, or processor, as applicable under the State Privacy Laws. Provider (a) acknowledges that Customer discloses personal information only for the limited and specified purposes described in the Agreement; (b) will comply with the obligations that apply to it under the State Privacy Laws and will give the personal information the same level of privacy protection the State Privacy Laws require; (c) agrees that Customer has the right to take reasonable and appropriate steps to help ensure that Provider’s Processing of personal information is consistent with Customer’s obligations under the State Privacy Laws; (d) will notify Customer in writing of any determination it makes that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, on reasonable notice, including notice under clause (d), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.

Provider will not:

  • sell or share any personal information;
  • retain, use, or disclose any personal information for any purpose other than the specific purpose of providing the Services, including for a commercial purpose other than providing the Services, or as the State Privacy Laws otherwise permit;
  • retain, use, or disclose the personal information outside the direct business relationship between Provider and Customer; or
  • combine personal information received under the Agreement with personal information (i) received from or on behalf of another person, or (ii) collected from Provider’s own interaction with any Data Subject to whom it pertains, except as and to the extent the State Privacy Laws permit and as is necessary for Provider to provide the Services.

Provider certifies that it understands its obligations under this Annex 2 and will comply with them.

Giving Customer notice of Subprocessor engagements in accordance with section 9 (Subprocessors) satisfies Provider’s obligation under the State Privacy Laws to give notice of, and an opportunity to object to, those engagements. Customer may conduct audits in accordance with section 10 (Audits) to help ensure that Provider’s use of personal information is consistent with Provider’s obligations under the State Privacy Laws.

The Parties acknowledge that Provider’s retention, use, and disclosure of personal information as authorized by Customer’s instructions documented in the Agreement and this DPA are integral to Provider’s provision of the Services and the business relationship between the Parties.

As of the effective date of this DPA, the Parties do not identify a separate Michigan requirement for this Annex 2. They intend compliance with the State Privacy Laws and any Michigan law that applies to Provider’s Processing.

Annex 3 — Security measures

Provider’s Security Measures include the following, each designed to protect Personal Data in proportion to the risk:

  • Organization. Assignment of responsibility for developing, implementing, and maintaining Provider’s information security program to designated personnel.
  • Review. Procedures designed for periodic review and assessment of risks to Provider’s organization, for monitoring and maintaining compliance with Provider’s policies and procedures, and for reporting the condition of its information security and compliance to senior management.
  • Data security controls. Logical segregation of data between customer workspaces; restricted, role-based access; authenticated sessions; encryption in transit over public networks and at rest, using commercially available industry-standard technologies (or materially equivalent safeguards); and rolling encrypted backups.
  • Logical access controls. Controls designed to manage electronic access to data and system functionality based on authority levels and job functions, such as granting access on a need-to-know and least-privilege basis, using unique user IDs and appropriate authentication credentials for all users, and promptly revoking or changing access when employment ends or job functions change.
  • Password controls. Controls designed to manage password strength and use, including prohibiting users from sharing passwords and maintaining password controls for Provider’s staff that are consistent with generally accepted industry standards and appropriate to the risk, such as (i) minimum password length or use of multi-factor authentication as appropriate; (ii) not storing passwords in a readable format; and (iii) appropriate complexity or other compensating controls.
  • Audit logging. System audit and event logging and related monitoring procedures designed to record user access and system activity.
  • Physical and environmental security. Physical and environmental security of data centers and computing facilities is provided by Provider’s infrastructure hosting providers.
  • Operations. Operational procedures and controls designed to provide for the secure configuration, monitoring, and maintenance of technology and information systems, including secure disposal of systems and media in accordance with commercially reasonable industry standards.
  • Change management. Procedures and tracking mechanisms designed to test, approve, and monitor material changes to Provider’s technology and information assets that may affect the security of Personal Data.
  • Incident management. Procedures designed to let Provider investigate, respond to, mitigate, and give notifications under this DPA about events related to Provider’s technology and information assets.
  • Network security. Controls designed to protect systems from intrusion and limit the scope of any successful attack.
  • Vulnerability management. Vulnerability assessment and patch management procedures and scheduled monitoring designed to identify, assess, mitigate, and protect against identified security threats and malicious code.
  • Continuity. Business continuity and disaster recovery procedures designed to maintain service, or recover from foreseeable emergencies or disasters, using rolling encrypted backups.

Annex 4 — Subprocessors

Customer approves Provider’s engagement of Subprocessors in the following functional categories to provide the Services under the Agreement. Provider does not name vendors on this page. A named list of its current Subprocessors is available on request to admin@virtusprofessionalservices.com. Changes follow the notice-and-objection process in section 9 (Subprocessors), under which Customer has 15 days to object.

  • Cloud hosting and object storage. Hosts the Services and stores files. Locations vary by provider; processing is primarily in the United States.
  • Managed data storage. Stores account, workspace, and audit records. Locations vary by provider; processing is primarily in the United States.
  • Sign-in and identity provider. Authenticates users and manages sign-in methods. Locations vary by provider; processing is primarily in the United States.
  • Payment processing. Processes subscription payments. Locations vary by provider; processing is primarily in the United States.
  • Transactional email delivery. Delivers account and service emails. Locations vary by provider; processing is primarily in the United States.
  • AI-assisted search and answer generation over public source documents. Powers AI-assisted research features. Locations vary by provider; processing is primarily in the United States.

Contact

Send data protection requests, Subprocessor objections, and audit requests to admin@virtusprofessionalservices.com. Write to Virtus Professional Services LLC at the address that matches your request:

Product help and account access
support@virtusprofessionalservices.com
Legal notices, arbitration notices, privacy and data requests, and security reports
admin@virtusprofessionalservices.com
Invoices, payments, billing disputes, and seat changes
billing@virtusprofessionalservices.com
Accounts receivable and remittance
ar@virtusprofessionalservices.com

Adapted from the General Legal open-source legal templates (CC0 1.0).