Data Processing Addendum

How VividStack processes personal data on a customer’s behalf.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Vividstack LLC (“VividStack”, “Processor”) and the customer that accepted those Terms (“Customer”, “Controller”). It applies where VividStack processes personal data on the Customer’s behalf in providing the VividHarbor AI Assistant.

No signature is required. This DPA is automatically incorporated into your agreement when you accept the Terms of Service. If your organization requires a countersigned copy, email privacy@vividstack.dev.

1. Roles of the parties

The Customer is the controller of Visitor Data collected through the chat widget on the Customer’s website, and of personal data contained in Customer Content. VividStack is the processor of that data and will process it only on the Customer’s documented instructions, which include the Terms, this DPA, and the Customer’s configuration of the Service.

VividStack is an independent controller for its own account, billing, and security data as described in the Privacy Policy. That processing is outside the scope of this DPA.

2. Details of processing

  • Subject matter: provision of an AI chat assistant that answers questions using the Customer’s approved website pages and uploaded documents.
  • Duration: for the term of the Customer’s subscription, plus the deletion period in section 9.
  • Nature and purpose: hosting, storage, indexing, retrieval, transmission to AI model providers for response generation, analytics presented to the Customer, security monitoring, and deletion.
  • Categories of data subjects: visitors to the Customer’s website, and any individuals referenced in Customer Content.
  • Categories of personal data: chat message content (which may include whatever a visitor chooses to type), timestamps, session identifiers, detected language, originating domain, and IP-derived rate-limiting metadata.
  • Special categories: none are requested by the Service. The Customer must not upload or solicit special category data without a separate written agreement.

3. Processor obligations

VividStack will:

  • Process personal data only on the Customer’s documented instructions, unless required by law, in which case it will notify the Customer unless legally prohibited.
  • Ensure personnel authorized to process personal data are bound by confidentiality obligations.
  • Implement the technical and organizational measures described in section 6.
  • Not sell, rent, or disclose personal data, and not use it for its own purposes, including model training.
  • Inform the Customer if, in its opinion, an instruction infringes applicable data protection law.

4. Subprocessors

The Customer provides general authorization for VividStack to engage subprocessors. Our current subprocessors are listed on the Subprocessors page. Each subprocessor is bound by written terms providing at least the level of data protection required by this DPA, and VividStack remains liable for their performance.

We will provide at least 30 days’ notice before adding or replacing a subprocessor by updating that page and notifying customers who have subscribed to notifications. If you reasonably object on data protection grounds within that period, we will work with you in good faith on an alternative; if none is available, you may terminate the affected subscription without penalty for the remainder of the prepaid term.

5. Assistance to the Customer

Taking into account the nature of the processing, VividStack will provide reasonable assistance to the Customer with:

  • Responding to data subject requests for access, correction, deletion, restriction, objection, or portability. If we receive such a request directly from a visitor, we will refer them to the Customer.
  • Data protection impact assessments and prior consultations with supervisory authorities.
  • Demonstrating compliance, including by making available the information reasonably necessary for the Customer’s audits. Audits are limited to once per twelve months unless required by a supervisory authority, must be conducted with reasonable notice and during business hours, and must not unreasonably disrupt operations.

6. Security measures

VividStack maintains measures appropriate to the risk, including:

  • Encryption of personal data in transit using TLS, and encryption at rest with our infrastructure providers.
  • Logical tenant isolation so a tenant’s content and chat history are only accessible within that tenant.
  • Domain allowlisting that restricts which websites may embed and call a given chatbot.
  • Role-based access control in the admin portal and scoped, revocable upload and API tokens.
  • Access to production systems limited to authorized personnel on a need-to-know basis.
  • Logging and monitoring for security and abuse detection.
  • Regular backups and documented restoration procedures.

7. Personal data breach

VividStack will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer’s personal data. The notification will describe the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for further information, to the extent known. VividStack will provide reasonable assistance with the Customer’s own notification obligations.

8. International transfers

VividStack processes personal data primarily in the United States. Where the Customer transfers personal data subject to GDPR, UK GDPR, or Swiss data protection law to VividStack, the parties agree that the European Commission’s Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this DPA by reference, with the Customer as data exporter and VividStack as data importer, and with the details in section 2 populating the relevant annexes. The UK International Data Transfer Addendum applies to UK transfers, and the Swiss amendments apply to Swiss transfers.

9. Deletion and return of data

The Customer may export or delete Customer Content at any time through the admin portal. On termination of the subscription, VividStack will delete or anonymize personal data processed under this DPA within 30 days, except where retention is required by law. Residual copies in encrypted backups are deleted on the normal backup rotation cycle.

10. U.S. state privacy laws

Where the California Consumer Privacy Act or a comparable U.S. state law applies, VividStack acts as a “service provider” or “processor”. VividStack will not sell or share personal information, will not retain, use, or disclose it for any purpose other than performing the Service, and will not combine it with personal information from other sources except as permitted by law.

11. Order of precedence

In the event of a conflict, this DPA controls over the Terms of Service with respect to the processing of personal data. Any separately signed dedicated or enterprise data protection agreement controls over this DPA.

Contact

Company: Vividstack LLC
Email: privacy@vividstack.dev