Data Processing Agreement

Version 1.0 · Effective date: 5 September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between [Legal Entity Name] ("Vivora", "Processor") and the Customer ("Controller") wherever Vivora processes personal data on the Controller's behalf in the course of providing the Service. This DPA is incorporated automatically for every Customer; a separately signed copy is available on request for Customers who require one for their own compliance records (e.g. EU/UK-based Customers).

1. Roles of the parties

The Controller determines the purposes and means of processing personal data entered into the Service (e.g. the Controller's own customer/supplier/employee records). Vivora acts solely as a Processor with respect to that data, processing it only to provide the Service and only on the Controller's documented instructions, which are given by the Controller's configuration and use of the Service's features.

2. Processing instructions

Vivora will process personal data only: (a) to provide, maintain, and support the Service as described in the Terms of Service; (b) as necessary to comply with applicable law; or (c) as otherwise instructed in writing by the Controller. Vivora will not use Controller personal data for its own independent purposes (e.g. marketing, profiling, or training any Vivora-controlled model) without the Controller's separate written consent.

3. Sub-processors

The Controller authorises Vivora to engage the following sub-processors, each of whom is bound by contractual data protection obligations at least as protective as this DPA:

Sub-processorPurposeLocation
Supabase Inc.Application database, authentication, and file storage[Region of your Supabase project, e.g. Singapore/Mumbai]
Cloudflare, Inc.Application hosting, CDN, and DDoS protectionGlobal edge network
Stripe, Inc.Payment processingIreland/United States (per Stripe's own documented sub-processor list)
PostHog (planned, not yet active)Product analytics[EU or US, depending on hosting option chosen]

Vivora will notify the Controller at least 14 days before adding or replacing a sub-processor that will process the Controller's personal data, by email or in-app notice, giving the Controller an opportunity to object on reasonable data-protection grounds. If the parties cannot resolve the objection, the Controller may terminate the affected part of the Service without penalty.

4. Assisting with data subject rights

Where the Service's built-in self-service tools (data export, record edit/delete) are not sufficient to fulfil a data subject access, correction, deletion, or portability request the Controller has received, Vivora will provide reasonable assistance to the Controller in fulfilling that request, at the Controller's cost if the assistance requires material engineering effort beyond standard support.

5. Security measures

Vivora implements the following technical and organisational measures:

6. Audit

On reasonable written request, no more than once per 12-month period (unless required by a regulator or following a security incident), Vivora will provide the Controller with a summary of its security practices sufficient to demonstrate compliance with this DPA. On-site audits or third-party audit access require at least 30 days' notice, are subject to confidentiality obligations, and may be subject to reasonable cost recovery from the Controller.

7. Data breach notification

Vivora will notify the Controller without undue delay, and in any event within [e.g. 72 hours] of becoming aware, of any confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Controller personal data processed by Vivora. The notification will describe, to the extent then known, the nature of the breach, categories and approximate number of data subjects/records affected, and the measures taken or proposed to address it.

8. International data transfers

Today, Vivora's Customers and the personal data they process are based in India, and Vivora's infrastructure providers may store data outside India as described in Section 3. If and when Vivora processes personal data of individuals located in the EU or UK, any transfer of that data outside the EU/UK will be made subject to Standard Contractual Clauses (SCCs) or another lawful transfer mechanism recognised under GDPR/UK GDPR, incorporated by reference into this DPA at that time.

9. Termination

On termination of the Service, Vivora will, at the Controller's election made within 30 days of termination, either (a) enable the Controller to export their Customer Data via the Service's built-in tools, or (b) delete the Controller's personal data from Vivora's production systems, in each case subject to any retention Vivora is required to maintain by law (e.g. billing records — see our Privacy Policy).

10. Liability

Each party's liability under this DPA is subject to the limitation of liability set out in Section 7 of the Terms of Service. Nothing in this DPA relieves the Controller of its own obligations as a data controller under applicable data protection law, including obtaining any consents required from its own data subjects before entering their data into the Service.