Data processing agreement
Draft: this document hasn't been reviewed by counsel yet. It describes how Velnor works today, and it may change before it's final.
Roles
For the data your organisation puts into Velnor, your organisation is the controller and we are its processor. This agreement is part of the terms of service.
What we do with it
We process it only to run the service, as you instruct us through the panel and these terms, and for no other purpose. Everyone who can reach it is bound to keep it confidential.
Security
We keep it apart from every other organisation's, encrypt it in transit, and back it up, as the security page describes.
Subprocessors
We use only the subprocessors we list, and add one only after announcing it there 30 days ahead, so you can object.
See also: Subprocessors
Helping you
We help you answer the people whose data it is, and we tell you without undue delay if a breach affects your data.
At the end
Ask at [email protected] for a copy of your data, or for your organisation to be deleted, at any time. Once it's deleted, its data is gone from the service, and the backups that held it expire within 30 days.
Signing it
To sign a copy with your organisation's details, write to [email protected]. Transfers between regions, and the clauses that cover them, are set in the final version.
Version history
- : First draft.