Data Processing Addendum

This is a plain-language template describing how Velsano processes personal data on your behalf — a starting point for legal and procurement review, not executed contract language and not legal advice. To put a signed DPA in place, email legal@velsano.ai.

Roles of the parties

For personal data in the data you put into the Service, you are the controller and Velsano is the processor, acting only on your documented instructions and as required by law.

Security

Velsano maintains tenant isolation, role-based access control, encryption in transit, application-layer encryption of sensitive fields, audit logging, and encrypted backups — described on our Security page, which forms part of this DPA. We claim no third-party security certification and state plainly what is in place today.

Subprocessors

The authoritative, up-to-date list of subprocessors — who they are and what data they process — is on our Security page.

International transfers, assistance, breaches, deletion

Cross-border transfers rely on an appropriate mechanism such as the Standard Contractual Clauses. Velsano assists with data-subject requests, notifies you of personal data breaches without undue delay, and returns or deletes Customer Data on termination except where the law requires retention.

Read the Security page · Privacy Policy · Terms of Service