Data Processing Addendum
This addendum sets out how Vettasy processes personal data on behalf of Customers. It forms part of the Terms of Service. A countersigned copy is available on request.
1Scope and roles
This Data Processing Addendum (“DPA”) applies where Vettasy processes personal data on behalf of the Customer in providing the Service (“Customer Personal Data”). The Customer is the controller and Vettasy the processor. Where the Customer acts as a processor for another controller, Vettasy acts as its subprocessor.
The DPA covers the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection and US state privacy laws, where they apply. Terms not defined here have the meaning given in the GDPR or in the Terms of Service.
2Details of processing
3Instructions
Vettasy processes Customer Personal Data only on the Customer’s documented instructions. The Terms, this DPA, the Customer’s settings in the Workspace, including retention periods, and the Customer’s written requests are those instructions.
Vettasy informs the Customer if an instruction appears to infringe data protection law and may suspend that processing until the Customer confirms or changes it.
If the law requires processing beyond the instructions, Vettasy informs the Customer first, unless the law forbids it.
4Personnel and access
People at Vettasy who process Customer Personal Data are bound by confidentiality. Access to recordings is limited to dispute review and to support at the Customer’s written request. Every access is logged and appears in the Customer’s audit log.
5Security measures
Vettasy maintains technical and organisational measures appropriate to the risk, including:
- Encryption at rest with AES-256 and in transit with TLS 1.3.
- Encrypted backups that rotate within 30 days.
- Single sign-on with a second factor for staff, least-privilege roles and quarterly access reviews.
- Logging of administrative actions and of every access to recordings.
- Separation of Customer environments at the application and storage layers.
- Code-signed builds, dependency scanning and code review for every change.
- Vulnerability disclosure at [email protected] and through /.well-known/security.txt.
- An independent penetration test every year, the first in Q4 2026.
- Hosting in ISO/IEC 27001 certified data centers in Germany.
- An incident response plan tested at least once a year.
Vettasy may update these measures, provided the overall level of protection does not decrease.
6Subprocessors
The Customer gives general authorisation for Vettasy to engage subprocessors. Vettasy imposes data protection obligations on each subprocessor that are no less protective than this DPA and remains responsible for their performance. The current list:
Vettasy announces a new subprocessor at least 30 days in advance, by email to the Customer’s administrators and on the Trust page. The Customer can object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for it.
7Data subject requests
Vettasy forwards requests from data subjects to the Customer without undue delay and within five business days, and does not answer them unless the Customer instructs it to. The Workspace lets the Customer find, export and delete a Candidate’s data. Vettasy assists with requests that cannot be handled in the Workspace.
8Personal data breaches
Vettasy notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay and no later than 48 hours after becoming aware of it. The notice describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences and the measures taken or proposed.
Vettasy updates the Customer as more information becomes available and cooperates with the Customer’s notifications to authorities and data subjects.
9Assessments and consultations
Vettasy provides the information the Customer needs for data protection impact assessments and for prior consultations with authorities. A template impact assessment for structured interviews in Vettasy is available on request.
10Deletion and return
During the subscription, Customer Personal Data is deleted at the end of the retention period set for each role. Deletion on request takes up to 30 days and includes backups.
On termination, the Customer can export Customer Personal Data. Vettasy deletes it 30 days after termination unless the law requires retention and confirms deletion in writing on request. Candidates keep access to their copies until the original retention period ends.
11Audits
Vettasy makes available the information needed to demonstrate compliance with this DPA: the security overview, the summary of the latest penetration test and, once issued, the SOC 2 Type II report. Where that information is not enough, the Customer may audit Vettasy once a year with 30 days’ notice, during business hours, at its own cost and under confidentiality. Audits of subprocessors rely on their certifications and reports.
12International transfers
Customer Personal Data is stored in Germany unless the Customer chooses the US region. For transfers outside the EEA, the parties agree to the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914: Module 2 where the Customer is a controller and Module 3 where it is a processor. For the UK, the International Data Transfer Addendum applies. For Switzerland, the Clauses apply with the changes Swiss law requires. Transfers to recipients certified under the EU-US Data Privacy Framework may rely on that certification.
Remote access by Vettasy staff from its principal office in Hong Kong, for support and dispute review, is covered by these Clauses. The data stays stored in Germany.
Vettasy challenges requests from public authorities that are unlawful or overbroad, discloses the minimum required and informs the Customer unless the law forbids it.
13Liability
Each party’s liability under this DPA is subject to the limitations in the Terms of Service, except where the law does not allow them.
14Contact and signature
Questions about this DPA go to [email protected]. A copy countersigned by Vettasy is available on request from the same address. The DPA applies from the moment the Customer accepts the Terms, with or without a signed copy.
