Data Processing Addendum
Last updated 2026-09-24
Version 1.0. Complete the bracketed fields, sign Annex 1 and send a copy to info@vendorvett.com; we countersign and return it.
1. Parties and scope
This Data Processing Addendum ("DPA") forms part of the agreement ("Agreement") between [Customer legal name], [address] ("Customer"), and VendorVett ("VendorVett", "Processor") for the VendorVett service ("Service").
It applies where VendorVett processes Personal Data on Customer's behalf in providing the Service, including Personal Data subject to the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other US state privacy laws.
If this DPA conflicts with the Agreement, this DPA governs as to the processing of Personal Data.
2. Roles
Customer is the controller (or "business") and VendorVett is the processor (or "service provider" / "contractor") of Customer Personal Data.
VendorVett will process Customer Personal Data only on Customer's documented instructions, which are the Agreement, this DPA, and Customer's use and configuration of the Service. VendorVett will inform Customer if it believes an instruction infringes applicable law.
3. Details of processing
Subject matter and purpose: providing third-party / vendor due-diligence software, including inventory, questionnaires, evidence storage, scoring, reporting, audit logging, sanctions screening and, where enabled, AI-assisted document analysis.
Duration: the term of the Agreement plus the deletion period in section 10.
Categories of data subjects: Customer's authorised users; Customer's vendors' contacts and personnel named in questionnaires or evidence.
Categories of Personal Data: names, business email addresses, job titles, business phone numbers, IP addresses of users, and any Personal Data Customer or its vendors choose to include in questionnaire answers or uploaded documents.
Special categories: none are required by the Service. Customer should not upload special-category data unless necessary and lawful.
4. CCPA / US state law terms
VendorVett will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes specified in the Agreement, or combine it with personal information received from other sources except as permitted by law.
VendorVett will comply with applicable obligations under the CCPA and other US state privacy laws, provide the same level of privacy protection they require, and notify Customer if it can no longer meet them. Customer may take reasonable steps to stop and remediate unauthorised use.
5. Confidentiality and personnel
VendorVett ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and receive access only where needed to operate or support the Service.
6. Security
VendorVett implements the technical and organisational measures described in Annex 2 and on its published Security page, appropriate to the risk. VendorVett may update these measures provided the overall level of protection is not reduced.
7. Subprocessors
Customer gives general authorisation for VendorVett to engage the subprocessors listed in Annex 3 and on VendorVett's published subprocessor page.
VendorVett will give at least 30 days' notice (by email to Customer's owners and by updating the published list) before a new subprocessor processes Customer Personal Data. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees.
VendorVett imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for its subprocessors' performance.
8. Data subject requests and assistance
The Service lets Customer access, correct, export (Settings > Data & privacy) and delete Personal Data. Where Customer cannot do so itself, VendorVett will provide reasonable assistance in responding to data subject requests, and with data protection impact assessments and prior consultations, taking into account the nature of processing.
VendorVett will promptly forward to Customer any request it receives directly from a data subject about Customer Personal Data and will not respond except to direct the requester to Customer.
9. Personal data breach
VendorVett will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to help Customer meet its own notification obligations, and will take reasonable steps to contain and remediate it.
10. Return and deletion
Customer may export its data at any time. On Customer's instruction to delete its organization, VendorVett deletes Customer Personal Data, including stored documents, after a grace period of [30] days during which the instruction can be cancelled. Deleted data rolls out of encrypted backups within [35] days.
VendorVett retains a minimal deletion record (organization identifier and name, who requested deletion and when, record counts, and a cryptographic digest of the deleted audit log) as evidence that the instruction was carried out.
11. Audits
VendorVett will make available information reasonably necessary to demonstrate compliance with this DPA, including completing Customer's reasonable security questionnaires once per year. Where that is insufficient, Customer may conduct an audit on 30 days' notice, at its own cost, during business hours, subject to confidentiality, no more than once per year unless required by a regulator or following a personal data breach.
12. International transfers
VendorVett and its subprocessors process data in the United States. For transfers of Personal Data from the EEA, Switzerland or the UK to a country without an adequacy decision, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), and the UK International Data Transfer Addendum, with Annexes 1 to 3 of this DPA completing their appendices. Where VendorVett is certified under the EU-US Data Privacy Framework, transfers may rely on that certification instead.
13. Liability and term
Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where applicable law does not permit it. This DPA remains in effect while VendorVett processes Customer Personal Data.
Annex 1 — Parties
Data exporter (controller): [Customer legal name, address, contact person, email]. Signature: ________ Date: ________
Data importer (processor): VendorVett, [registered address], privacy contact info@vendorvett.com. Signature: ________ Date: ________
Annex 2 — Technical and organisational measures
Encryption of data in transit (TLS) and of stored documents at rest (server-side AES-256); documents are private objects reachable only via short-lived signed links.
Logical tenant isolation enforced server-side on every request, with automated cross-tenant isolation tests; role-based access control (owner, analyst, viewer).
Append-only, hash-chained audit log per organization, verifiable by the customer.
Antivirus scanning of uploads, fail-closed: an unscanned file cannot be downloaded.
Rate limiting on authentication and public endpoints; password reset tokens single-use and short-lived; server-side session revocation.
Error monitoring configured to exclude request bodies and personal data.
Automated tests and code review for every change; production deploys only from a protected branch.
Annex 3 — Subprocessors
Railway Corporation (United States): Application hosting: web servers, background workers, PostgreSQL database and Redis queue.
DigitalOcean, LLC (United States): Object storage (Spaces) for uploaded evidence documents and data-export archives.
Resend, Inc. (United States): Transactional email: sign-in, invitations, questionnaire links, reminders, notices.
Anthropic, PBC (United States): AI analysis of uploaded evidence and drafting of assessment narratives. Only for organizations on a plan with AI analysis, when an analysis is requested.
Stripe, Inc. (United States): Subscription billing and payment processing. Only for organizations on a paid plan.
Functional Software, Inc. (Sentry) (United States): Error monitoring for the application.
Template text, not legal advice. It has not yet been reviewed by counsel.