Data Processing Addendum

Effective 2026-08-13. Last updated 2026-08-13.

This addendum applies where you upload personal data about your own end users into Vendeflect: you are the controller and we are your processor. It sets out the data processed, our obligations, the security measures the product actually implements today, our subprocessors, breach notification, and deletion on termination. It forms part of the Terms of Service.

1.Roles

This Data Processing Addendum applies where you upload personal data about your own end users or contacts into a workspace. For that data you are the controller and we are your processor, and we process it only on your documented instructions, which are the use of the service and our Terms of Service. For your own account data we are the controller, as set out in the Privacy Policy. This addendum forms part of the Terms of Service.

2.Subject matter and duration

The subject matter is the processing needed to provide Vendeflect to you. Processing lasts for as long as your subscription is active, and then through the deletion period described below.

3.Nature and purpose

We process your data to host and secure the service, to store your documents as extracted text, to draft questionnaire answers from those documents where AI drafting is enabled, to publish your Trust Center, and to enforce plan limits. We do not use your content to train models for other customers.

4.Categories of data and data subjects

The personal data processed under this addendum is whatever you choose to include in the documents, questionnaires and answers you upload. Typically this includes:

  • Data subjects: your employees, your customers or prospects mentioned in security reviews, and the people named in your policies.
  • Data categories: names, business contact details, and any personal data contained in the documents and answers you upload.

You control what you upload. You should not upload special category data unless it is necessary and you are permitted to process it.

5.Our obligations as processor

  • Process personal data only on your documented instructions, unless the law requires otherwise, in which case we will tell you where permitted.
  • Ensure people authorised to process the data are bound by confidentiality.
  • Implement the security measures described below.
  • Engage subprocessors only as set out in this addendum, and give notice before adding one.
  • Assist you, taking into account the nature of the processing, with data subject requests and with your own security, breach and impact assessment duties.
  • Delete or return personal data on termination, as described below.
  • Make available the information reasonably needed to demonstrate compliance with this addendum.

6.Confidentiality

Access to your data by our personnel is limited to those who need it to run the service, and they are bound by confidentiality obligations.

7.Security measures

We describe our security measures honestly, against what the product actually does today:

  • Data is encrypted in transit using TLS.
  • Passwords are stored only as hashes by our authentication layer; we never hold plaintext passwords.
  • Access to data is scoped to a workspace: queries are constrained to the caller's workspace so one tenant cannot read another's data.
  • The public Trust Center renders only a restricted projection of workspace data, so file references, member emails and raw document text cannot reach an unauthenticated visitor.
  • API keys are shown once at creation and stored only as a SHA-256 hash alongside a visible prefix, so a lost key cannot be recovered from our records.
  • Encryption at rest is provided by our managed database host for the data it stores. There is no separate object storage today: uploaded documents are held as extracted text in that database rather than as files.

To be candid about the boundaries of these measures: we do not currently hold a SOC 2 report or an ISO 27001 certification, and we have not commissioned an independent penetration test. We describe our posture from the actual state of the system rather than from a badge, and we update it as that changes.

8.Subprocessors

You give general authorisation for us to use the subprocessors listed below to process personal data. We give notice before adding a new one, and you may object on reasonable data protection grounds.

ProcessorPurposeData processedLocationApplies
NeonManaged Postgres databaseAll workspace data: accounts, documents and their extracted text, questionnaires, answers, Trust Center configurationThe region of your Neon projectAll plans
VercelApplication hosting and content deliveryRequests in transit, request logs, IP addressesGlobal edge network, with functions in the configured regionAll plans
Amazon Web ServicesAI model inference through Amazon BedrockThe question being answered and the excerpts retrieved from your documents to answer itThe configured AWS regionOnly when AI drafting is enabled. With MOCK_AI set, no data leaves the application.
Paddle.com Market LtdMerchant of record, payment processing, tax and invoicingBilling contact details, transaction and subscription recordsUnited Kingdom and European UnionOnly for paid plans.

The current list and how to subscribe to change notices are on our Subprocessors page.

9.Assistance with data subject requests

The product lets you access, correct, export and delete the data in your workspace yourself. Where you need more, we will assist you in responding to data subject requests, taking into account the nature of the processing and the information available to us.

10.Breach notification

If we become aware of a personal data breach affecting your data, we will notify you without undue delay after becoming aware, and provide the information you reasonably need to meet your own notification duties. Report a suspected issue to security@vendeflect.com.

11.Deletion and return on termination

On termination, and at your choice, we will delete or return the personal data we process for you. We delete workspace data within 30 days from active systems after your account is closed. Residual copies in encrypted backups are purged within 35 days as backups rotate, which is the real floor on deletion, unless we are required by law to keep data longer.

12.Audit and information rights

We will make available the information reasonably necessary to demonstrate compliance with this addendum and, on reasonable prior notice and subject to confidentiality, respond to your reasonable audit requests. We do not currently offer on-site third party audits; where you need independent assurance we will work with you on what we can provide.

13.International transfers

Where a subprocessor processes personal data across borders, we rely on the transfer mechanisms it makes available, such as standard contractual clauses. The processing locations are stated in the subprocessor table above.

Contact

Privacy requests
privacy@vendeflect.com
Entity
Vendeflect