https://app.veloratech.live/legal/dpa
Velora Legal
Data Processing Addendum
Version 1.0Effective Current
Contents
Part II - Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") forms part of the Agreement between Customer and Velora. It applies when Velora processes Personal Data on behalf of Customer in connection with the Service. Capitalized terms not defined here have the meanings given in the Terms or applicable Data Protection Law.
1. Roles and scope
For Customer Personal Data processed to provide the Service, Customer is the controller or business and Velora is the processor or service provider, except where applicable law requires a different role for a specific activity. If Customer is itself a processor for another controller, Velora acts as Customer’s subprocessor for that processing.
Each party will comply with the data protection laws applicable to its role. Customer is responsible for the lawfulness of its instructions, legal bases, notices and disclosures to data subjects.
2. Documented instructions
Velora will process Customer Personal Data only on documented instructions from Customer, including the Agreement, Customer’s use and configuration of the Service, and other written instructions accepted by Velora, unless processing is required by applicable law. If legally permitted, Velora will inform Customer before processing required by law.
Velora will promptly inform Customer if, in Velora’s reasonable opinion, an instruction infringes applicable Data Protection Law and may suspend the affected processing until the parties resolve the issue.
3. Confidentiality and personnel
Velora will ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only where reasonably necessary to perform their duties.
4. Security
Velora will maintain appropriate technical and organizational measures as required by Article 32 GDPR and comparable laws, taking into account the state of the art, implementation costs, and the nature, scope, context, purposes and risks of processing. The measures in Part III are the current baseline.
Velora may update security measures where the update does not materially reduce the overall level of protection of Customer Personal Data.
5. Subprocessors
Customer gives Velora general written authorization to engage the subprocessors listed in Part V and future subprocessors needed to provide the Service.
Velora will impose written data protection obligations on each subprocessor that are appropriate to the services it provides and no less protective in substance than Velora’s relevant obligations under this DPA. Velora remains responsible to Customer for performance of its obligations under this DPA where processing is delegated to a subprocessor.
Velora will make an up-to-date Subprocessor List available and, where reasonably practicable, provide at least 15 days’ advance notice before a new subprocessor begins processing Customer Personal Data. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If no solution is reasonably available, either party may terminate the affected Service without penalty for future periods. Urgent replacements required for security, availability or legal reasons may occur on shorter notice.
6. International transfers
Velora will not transfer Customer Personal Data outside the EEA, Switzerland or another jurisdiction recognized as adequate unless the transfer is permitted under applicable Data Protection Law. Where required, Velora or the relevant subprocessor will rely on an adequacy decision, the EU Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where valid and applicable, or another lawful transfer mechanism.
Where Velora, acting as an EEA processor, transfers Customer Personal Data to a non-EEA subprocessor that is not otherwise covered by an adequate transfer mechanism, Velora will use the appropriate processor-to-processor transfer mechanism, including Module 3 of the EU SCCs where applicable.
7. Data-subject requests
Taking into account the nature of processing, Velora will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to requests to exercise data-subject rights. If Velora receives a request relating to Customer Personal Data, Velora will direct the requester to Customer where practicable and will not substantively respond on Customer’s behalf unless instructed or legally required.
8. Personal-data incidents
Velora will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will be sent to Customer’s designated security/privacy contact and will include available information reasonably necessary for Customer to meet its legal obligations, including the nature of the incident, affected data/data subjects where known, likely consequences, and mitigation/remediation measures.
Notification is not an admission of fault or liability. Velora may provide information in phases as the investigation develops. Unless expressly authorized, Customer remains responsible for regulatory and data-subject notifications required of it as controller.
9. Assistance with Articles 32-36 and analogous laws
Taking into account the nature of processing and information available to Velora, Velora will reasonably assist Customer with security obligations, breach assessment, data-protection impact assessments, prior consultation and comparable privacy risk assessments required by applicable law. Velora may provide standard security, architecture and processing documentation to support that work.
10. Audit and compliance information
Velora will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. Customer may conduct an audit no more than once per twelve-month period, and additionally after a material Personal Data Breach or where a regulator requires it, subject to reasonable notice, confidentiality, scope limitations and measures to avoid compromising other customers or Velora security.
Where reasonable, documentary review, certifications, third-party reports, technical documentation and written responses will be used before an on-site inspection. Customer bears its own audit costs and reimburses Velora for unreasonable or duplicative audit work unless the audit identifies a material breach by Velora.
11. Return and deletion
At termination or on Customer’s documented instruction, Velora will return or delete Customer Personal Data, at Customer’s choice where technically feasible, unless retention is required by law. Data in rolling backups or provider recovery systems may remain until overwritten under ordinary backup cycles, during which it remains protected and is not restored except for disaster recovery or legal necessity.
Velora’s operational target is to disable Customer access at termination, complete active-system deletion within 30 days after a confirmed deletion instruction or end of an agreed export period, and allow residual encrypted backups and infrastructure logs to expire under provider retention cycles. Where a third-party provider has a longer contractual post-termination deletion cycle, that cycle controls for data solely remaining at that provider.
12. U.S. state privacy terms
To the extent U.S. state privacy law applies and Customer is a regulated business/controller, Velora acts as a service provider/processor for Customer Personal Data processed under this DPA. Velora will process such data only for the specific business purposes of providing, securing, maintaining and supporting the Service and carrying out Customer’s documented instructions.
Velora will not sell or share Customer Personal Data as those terms are defined by the CCPA, will not retain, use or disclose it outside the direct business relationship for a purpose unrelated to the specified services except as permitted by law, and will not combine it with personal data obtained from another person or Velora’s own interaction with a consumer except where permitted by applicable law to provide the Service.
Velora will reasonably assist Customer with verified consumer requests, risk assessments and cybersecurity-audit information to the extent required of a service provider/processor by applicable U.S. privacy law and within Velora’s possession or control.
13. Liability and precedence
The liability provisions of the Terms apply to this DPA as between the parties, except to the extent mandatory Data Protection Law provides otherwise. Nothing in the Agreement limits the statutory rights of data subjects or the powers of supervisory authorities.
If this DPA conflicts with the Terms regarding processing of Personal Data, this DPA controls. A valid mandatory transfer mechanism such as the EU SCCs controls over inconsistent contractual terms to the extent required for that transfer.
14. Duration
This DPA remains in effect for as long as Velora processes Customer Personal Data on Customer’s behalf, including any post-termination retention period required to complete deletion, return, backup expiry or legal retention.
Schedule A - Details of Processing
| Item | Details |
|---|---|
| Subject matter | Operation of Velora as an AI-enabled real-estate workflow, intelligence and document-management service for Customer. |
| Duration | For the subscription term and any limited post-termination period needed for return, deletion, backup expiry, dispute preservation or legal compliance. |
| Nature of processing | Collection/receipt, recording, organization, structuring, storage, retrieval, consultation, matching, classification, extraction, summarization, generation, transmission, access control, logging, support, deletion and other processing necessary to provide the Service. |
| Purposes | Provide and secure the Service; route inbound correspondence; maintain contacts/opportunities; generate AI-assisted summaries, drafts, recommendations and market insights; enable team/workspace features; store authorized Vault documents; provide support; prevent abuse; comply with Customer instructions and law. |
| Data subjects | Customer owners, employees, agents, contractors and Authorized Users; Customer’s prospects, leads, clients, counterparties and contacts; persons appearing in correspondence or documents; property-related contacts; billing/business contacts. |
| Personal data | Names, work/personal contact details, role and account data; email content and routing metadata; property/deal/opportunity data; client preferences and communications; notes and logged interactions; deal values and stage data; AI-derived classifications/summaries/drafts; technical/security metadata; documents and attachments submitted to the Service. |
| Financial/Vault data | Proof-of-funds and similar financial documents may contain financial account details, balances, identifiers, addresses, signatures and related personal data. Vault access is separately restricted. Customer should not submit more information than necessary. |
| Sensitive/special data | Velora is not designed to require GDPR special-category data or criminal-offence data. Such information may appear incidentally in unstructured emails/documents. Customer must not intentionally submit it unless necessary, lawful and appropriate safeguards are in place. |
| Frequency | Continuous or event-driven, depending on Customer use of the Service. |
| Controller rights/obligations | Customer determines purposes of its brokerage/client processing, lawful bases, notices, retention instructions and user access, and remains responsible for its professional and regulatory obligations. |