Skip to content
Vestrum

Data Processing Addendum

Vestrum LLC · Effective September 14, 2026

This Data Processing Addendum (“DPA”) applies where Vestrum processes Personal Data on Customer's behalf and forms part of the Terms of Service between Vestrum and Customer. Capitalized terms not defined here have the meaning given in the Terms of Service or, where applicable, in the GDPR or CCPA.

1. Roles

Customer is the controller/business (or equivalent role) for Customer Personal Data unless applicable law provides otherwise. Vestrum acts as processor/service provider to the extent applicable. Vestrum may process limited account, billing, security, and relationship information as an independent controller where necessary for its own legitimate business, security, legal, and administrative purposes.

2. Instructions

Vestrum will process Customer Personal Data only to provide, secure, maintain, support, and improve the Services as permitted by the Terms and applicable law, and on Customer's documented instructions, including with respect to transfers to a third country, unless required to do otherwise by law binding on Vestrum, in which case Vestrum will inform Customer of that legal requirement before processing, unless the law prohibits this.

3. Confidentiality

Vestrum will require personnel with access to Customer Personal Data to be subject to confidentiality obligations appropriate to their role.

4. Security Measures

  • Encryption in transit and at rest.
  • Multi-factor authentication for supported accounts.
  • Access controls and role-based permissions where available.
  • Reasonable measures to detect and respond to security incidents.
  • Vendor and infrastructure controls appropriate to the Service.

5. Subprocessors

Customer authorizes Vestrum to use the subprocessors listed in the Subprocessor List. Vestrum will provide at least ten (10) days' notice before adding a new subprocessor with access to Customer Personal Data, by updating the Subprocessor List and, where Customer has subscribed to notifications, by email. Customer may object on reasonable data-protection grounds within ten (10) days of notice by contacting owners@vestrumllc.com; if the parties cannot resolve the objection, Customer's sole remedy is to terminate the affected Service without penalty.

Vestrum will impose data protection obligations on each subprocessor that are substantially similar to those in this DPA, and will remain liable to Customer for a subprocessor's acts and omissions in performing those obligations to the same extent Vestrum would be liable if performing the subprocessor's services directly, except as otherwise limited under Section 22 of the Terms of Service.

6. Data Subject and Consumer Requests

Taking into account the nature of processing, Vestrum will provide reasonable assistance to Customer for applicable access, deletion, correction, portability, restriction, objection, or opt-out requests under GDPR, CCPA/CPRA, or comparable law. Customer remains responsible for responding to requests as controller/business where required. Where an individual submits a request directly to Vestrum concerning Customer Personal Data, Vestrum will promptly refer the individual to Customer without responding substantively, unless applicable law requires otherwise.

7. Security Incidents

Vestrum will notify Customer without undue delay, and in any case no later than seventy-two (72) hours after confirming a security incident involving Customer Personal Data that is likely to result in a risk to the rights of affected individuals, and will provide information reasonably available to Vestrum to assist Customer in meeting its own notification obligations.

8. Deletion

At Customer's request following termination, and in any case at the expiry of the retention periods described in the Terms of Service and Privacy Policy, Vestrum will delete or anonymize Customer Personal Data subject to applicable law, legitimate retention requirements, and backup-cycle limitations.

9. International Transfers

Where Vestrum processes Customer Personal Data originating from the European Economic Area or Switzerland, and transfers that data to the United States or another country not deemed to provide an adequate level of protection, the parties incorporate by reference:

  • the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor), as approved by Implementing Decision (EU) 2021/914, with Customer as “data exporter” and Vestrum as “data importer”; the governing law and forum for Clause 17/18 purposes will be Ireland unless the parties agree otherwise in writing;
  • where applicable, the Swiss Federal Data Protection Act's requirements for transfers originating in Switzerland, applying the SCCs as adapted for Swiss law.

The parties will complete the annexes to the above (description of processing, technical and organizational measures, and subprocessor list) using the information in this DPA and the Subprocessor List. If a future transfer mechanism supersedes the above under applicable law, the parties will use that mechanism instead.

This DPA does not address transfers of personal data originating from the United Kingdom. The Service is not currently offered to businesses located in the United Kingdom, and Customer must not use the Service to process personal data of individuals located in the United Kingdom, consistent with Terms of Service Section 2.

10. CCPA/CPRA Service Provider Terms

This Section 10 applies where Vestrum processes personal information that is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), on Customer's behalf. The parties intend for Vestrum to qualify as a “service provider” as defined in Cal. Civ. Code § 1798.140(ag), and for disclosures of personal information from Customer to Vestrum not to constitute a “sale” or “sharing” under the CCPA.

  • Vestrum certifies that it understands the restrictions in this Section 10 and will comply with them.
  • Vestrum will not sell or share personal information received from Customer.
  • Vestrum will not retain, use, or disclose personal information received from Customer for any purpose other than the specific business purpose(s) of performing the Services described in the Terms of Service, outside of the direct business relationship between Vestrum and Customer, or as otherwise permitted by the CCPA.
  • Vestrum will not combine personal information received from Customer with personal information received from another source, except as permitted by the CCPA (including to detect security incidents or perform internal business functions common to service providers).
  • Vestrum will notify Customer if it determines it can no longer meet its obligations as a service provider under the CCPA.

11. Audit

Vestrum may satisfy audit obligations through security documentation, questionnaires, summaries, certifications, or similar materials, and may permit reasonable additional review no more than once per year (or following a confirmed security incident) where legally required, subject to confidentiality and security restrictions and at Customer's expense for any on-site component.