Legal
Data Processing Addendum
This Data Processing Addendum applies when Vebbl processes personal data on behalf of a business customer. Consumers should see our Privacy Policy.
1. Scope and Roles
This Data Processing Addendum ("DPA") applies where Vebbl LLC ("Vebbl") processes personal data on behalf of a business customer ("Customer") in connection with the Vebbl for Business products. It forms part of, and is governed by, the agreement between Vebbl and the Customer (the "Agreement").
For that processing, the Customer acts as the controller (or equivalent) and Vebbl acts as the processor (or service provider). This DPA does not apply to personal data that Vebbl processes for its own purposes as a controller — for example, information about individual consumers who use Vebbl — which is described in our Privacy Policy.
2. Processing Instructions
Vebbl processes personal data only to provide the products, as otherwise instructed by the Customer through the product's features and settings, and as required by applicable law. The Agreement, together with the Customer's use and configuration of the products, constitutes the Customer's documented instructions. If Vebbl believes an instruction violates applicable data-protection law, it will inform the Customer.
3. Confidentiality
Vebbl ensures that personnel authorized to process personal data are bound by appropriate obligations of confidentiality.
4. Security
Vebbl maintains technical and organizational measures designed to protect personal data appropriate to the risk. No safeguards can guarantee absolute security, and this DPA does not create a warranty of uninterrupted or error-free security.
5. Subprocessors
The Customer authorizes Vebbl to engage subprocessors to process personal data. Our current subprocessors are listed on our Subprocessors page. Vebbl imposes data-protection obligations on its subprocessors that are consistent with those in this DPA and remains responsible for their performance.
Where required by applicable law or the Agreement, Vebbl will make available a mechanism to receive notice of new subprocessors before they begin processing.
6. International Transfers
Where processing involves transferring personal data across borders, Vebbl relies on an appropriate transfer mechanism where one is required by applicable law (for example, standard contractual clauses or another recognized safeguard).
7. Data Subject Requests
Taking into account the nature of the processing, Vebbl provides reasonable assistance to help the Customer respond to requests from individuals to exercise their rights under applicable data-protection law, insofar as the Customer cannot address the request through the product's own features.
8. Personal Data Breach
Vebbl notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf, and provides information reasonably available to Vebbl to help the Customer meet its own notification obligations.
9. Return and Deletion
On termination of the Agreement, Vebbl deletes or returns personal data processed on the Customer's behalf in accordance with the product's functionality, except where retention is required or permitted by applicable law.
10. Records and Audits
Vebbl makes available information reasonably necessary to demonstrate compliance with this DPA. Any audit right is subject to reasonable notice, frequency, scope, confidentiality, and security conditions, and must not disrupt Vebbl's operations or compromise the data of other customers.
11. Precedence and Liability
In the event of a conflict between this DPA and the rest of the Agreement regarding the processing of personal data, this DPA controls for those data-protection matters. This DPA does not increase, and is subject to, the limitations and exclusions of liability set out in the Agreement.
12. Contact
Questions about this DPA can be sent to legal@vebbl.io. Data-protection requests can be sent to privacy@vebbl.io.