Data processing agreement

This Data Processing Agreement ("DPA") forms part of the Agreement between the customer ("Controller") and Veltron LLC, the company that provides the Peeve service ("Peeve" or "Processor"), and applies to the extent Peeve processes Personal Data on the Controller's behalf in providing the Peeve service (the "Service").

1. Definitions

Terms such as "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor", and "Supervisory Authority" have the meanings given in applicable Data Protection Law, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA) as applicable.

2. Roles and scope

The Controller determines the purposes and means of Processing. Peeve acts as Processor and processes Personal Data only on the Controller's documented instructions, including as set out in the Agreement and this DPA. Where Peeve engages Sub-processors, it acts as Sub-processor to them under this DPA.

3. Subject-matter, duration, nature and purpose

Subject-matter: provision of the Peeve Service.

Duration: the term of the Agreement, plus any period required for deletion or return of data.

Nature and purpose: hosting, storing, and processing end-user interactions so the Service can answer, guide, and act on the Controller's behalf; billing; support; and security.

Categories of Data Subjects: the Controller's end users, visitors, and authorized personnel.

Categories of Personal Data: identifiers (name, email), contact and account details, message/conversation content, usage and device metadata, and any Personal Data the Controller's end users submit through the Service. The Controller must not submit special-category data except as expressly agreed.

4. Processor obligations

Peeve shall:

1. process Personal Data only on the Controller's documented instructions, including regarding international transfers, unless required by law (in which case Peeve will inform the Controller unless legally prohibited);

2. ensure persons authorized to process Personal Data are bound by confidentiality;

3. implement the technical and organizational security measures described in Section 7 (Annex II);

4. respect the conditions in Section 5 for engaging Sub-processors;

5. assist the Controller, taking into account the nature of Processing, in responding to Data Subject requests (Section 6);

6. assist the Controller in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36 GDPR);

7. at the Controller's choice, delete or return all Personal Data at the end of the provision of services (Section 8); and

8. make available information necessary to demonstrate compliance and allow for and contribute to audits (Section 9).

5. Sub-processors

The Controller provides general authorization for Peeve to engage Sub-processors to process Personal Data. A current list is maintained at peeve.ai/legal/sub-processors. Peeve will give notice of intended changes and allow the Controller a reasonable period to object on reasonable grounds relating to data protection. Peeve imposes data-protection obligations on each Sub-processor no less protective than those in this DPA and remains liable for its Sub-processors' performance.

6. Data Subject rights

Taking into account the nature of the Processing, Peeve will assist the Controller by appropriate technical and organizational measures, insofar as possible, to fulfill the Controller's obligation to respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, and objection). Where a request is made directly to Peeve, Peeve will promptly notify the Controller and will not respond except on the Controller's instructions.

7. Security measures (Annex II)

Peeve maintains measures appropriate to the risk, including: encryption of data in transit and at rest; access controls and role-based permissions; authentication and secrets management; network and application security; logging and audit trails; backup and recovery; least-privilege access to production systems; and regular review of its security program.

8. Return and deletion

Upon termination or expiry of the Agreement, and at the Controller's choice, Peeve will delete or return all Personal Data and delete existing copies unless retention is required by law. Deletion of customer workspace data is available through the Service; residual copies in backups are purged on the standard backup rotation.

9. Audit

Peeve will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and security conditions and no more than once per year absent a substantiated concern or regulatory requirement.

10. International transfers

Where Processing involves the transfer of Personal Data outside the EEA, UK, or other restricted jurisdiction, such transfers are made under an appropriate transfer mechanism, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference where applicable.

11. Personal data breach

Peeve will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and will provide information reasonably available to help the Controller meet its own notification obligations.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations of liability in the Agreement. In the event of a conflict between this DPA and the Agreement regarding data protection, this DPA prevails.

13. Governing law

This DPA is governed by, and construed in accordance with, the laws of the State of Texas, USA, without regard to its conflict-of-laws rules, and the parties submit to the exclusive jurisdiction of the state and federal courts located in Texas. This does not override any mandatory Data Protection Law of the Data Subject's jurisdiction, the transfer mechanisms in Section 10, or a Data Subject's statutory rights, which continue to apply where required.

Annexes

Annex I. Parties and processing details: as described in Sections 2–3.

Annex II. Technical and organizational measures: as described in Section 7.

Annex III. Sub-processors: peeve.ai/legal/sub-processors.

Contact

Questions about this DPA, or to sign it, go to legal@peeve.ai.