Data Processing Addendum
This is a plain-language template describing how Velsano processes personal data on your behalf — a starting point for legal and procurement review, not executed contract language and not legal advice. To put a signed DPA in place, email legal@velsano.ai.
Roles of the parties
For personal data in the data you put into the Service, you are the controller and Velsano is the processor, acting only on your documented instructions and as required by law.
Security
Velsano maintains tenant isolation, role-based access control, encryption in transit, application-layer encryption of sensitive fields, audit logging, and encrypted backups — described on our Security page, which forms part of this DPA. We claim no third-party security certification and state plainly what is in place today.
Subprocessors
The authoritative, up-to-date list of subprocessors — who they are and what data they process — is on our Security page.
International transfers, assistance, breaches, deletion
Cross-border transfers rely on an appropriate mechanism such as the Standard Contractual Clauses. Velsano assists with data-subject requests, notifies you of personal data breaches without undue delay, and returns or deletes Customer Data on termination except where the law requires retention.