1. Parties, roles and scope
This Data Processing Agreement (“DPA”) forms part of the agreement between the business customer (“Customer”) and VAIONYX LLC, doing business as VAI IA (“Provider”), for the Services. It applies when Provider processes personal data on Customer's behalf.
For that processing, Customer is the controller or business and Provider is the processor or service provider, as those concepts apply. Each party remains independently responsible for personal data it processes for its own purposes, including account administration, security, legal compliance and billing.
If a signed order or negotiated DPA conflicts with this public DPA, the signed document controls for the conflict.
2. Processing details
Subject matter and duration
Providing configured conversational-assistant, scheduling, messaging, dashboard, support and related SaaS functions during the service term, plus limited retention needed for security, backup, dispute resolution and law.
Nature and purpose
Receiving, storing, organizing, retrieving, transmitting and deleting data to operate Customer-configured workflows, respond to end users, support appointments, deliver configured notifications, administer tenants and secure the Services.
Data subjects
Customer personnel, authorized users, prospective and current customers of Customer, website visitors, message recipients, appointment participants and other individuals whose data Customer submits.
Data categories
Names, contact details, account and tenant identifiers, messages, prompts, conversation context, appointment details, configuration, support records, technical and security metadata, and billing metadata when billing is enabled. Customer must not submit sensitive or regulated data unless expressly authorized in writing and appropriately configured.
3. Instructions and party duties
Provider will process Customer personal data only on documented instructions in the agreement, product configuration and authorized support requests, unless applicable law requires otherwise. Provider will inform Customer if an instruction appears to violate applicable data protection law, without assuming Customer's legal obligations.
Personnel authorized to process Customer personal data are subject to confidentiality obligations. Customer is responsible for lawful instructions, notices, legal bases or permissions, data accuracy, channel consents, data-subject communications and limiting submitted data to what is necessary.
4. Security measures
Taking account of the service and risk, Provider will maintain reasonable technical and organizational measures such as access controls, signed HTTP-only sessions, transport encryption for production, environment-based secret management, input validation, tenant association, restricted database permissions, logging and incident procedures. These measures evolve and do not guarantee absolute security.
Customer must implement the responsibilities described in the Security Overview.
5. Individual requests, assessments and incidents
Taking into account the nature of processing and information available, Provider will provide reasonable assistance for Customer's response to applicable requests for access, export, correction or deletion, impact assessments and regulator consultations. Customer remains responsible for determining whether and how to respond.
Provider will notify Customer without undue delay after becoming aware of a confirmed personal-data breach involving Customer personal data, to the extent required by applicable law or agreement, and provide reasonably available information. Notification is not an admission of fault.
6. Subprocessors
Customer authorizes the subprocessors below for the stated functions, including conditional providers only when Customer enables the relevant integration. “Prepared-disabled” means code exists but processing is not active by default. Provider remains responsible for its subprocessor obligations to the extent required by the agreement and applicable law.
| Provider | Purpose | Data | Status |
|---|---|---|---|
| Supabase | Database hosting and application data storage. | Account, tenant and application data. | active |
| Vercel | Website hosting and previews. | Request and deployment metadata. | active |
| Groq | AI model inference. | Prompts and limited conversation context. | active |
Provider may replace or add a subprocessor as services evolve. Provider will update this list before the new provider handles Customer personal data and, where a negotiated agreement requires advance notice or objection rights, follow that agreement.
7. International transfers
Customer acknowledges that Provider and subprocessors may process data in countries outside the Customer's country. Each party will use a legally valid transfer mechanism when required for its processing. A specific mechanism—such as contractual clauses or another recognized safeguard—must be confirmed for the applicable parties, locations and law rather than presumed universally by this page.
8. Return, deletion and retention
At Customer's documented request or service termination, Provider will delete or return Customer personal data within a commercially reasonable period, unless retention is required by law, needed to establish or defend claims, or remains in protected backups until ordinary overwrite. Customer should export needed data before termination. Deletion cannot remove data independently retained by third parties under Customer's direct relationship.
9. Information and audits
Provider will make reasonably available information needed to demonstrate the obligations in this DPA. If that information is insufficient and applicable law requires an audit, the parties will agree on a scoped, confidential audit that minimizes operational and security risk, normally no more than once per year unless a confirmed incident or regulator requires otherwise. Customer bears reasonable audit costs unless a material Provider breach is found.
10. General terms and contact
The agreement's liability limits, dispute terms, governing law and termination provisions apply to this DPA to the extent permitted by law. If this DPA conflicts with the agreement on personal-data processing, this DPA controls for that issue; mandatory law controls where it cannot be varied. Invalid provisions will be adjusted narrowly without invalidating the remainder.
Privacy requests and requests for a signed DPA: coceo@vainyx.com.