ViaVela

Legal documents › ViaVela Venustas

ViaVela Data Processing Addendum (DPA) — Puerto Rico

Draft: attorney review pending Puerto Rico · English source stamp 70dfdf64632a

ViaVela Data Processing Addendum (DPA) — Puerto Rico

DRAFT — for Puerto Rico-licensed counsel review. Not legal advice and not final. Have a Puerto Rico attorney review before signing; a professional Spanish translation is also required for consumer-facing use. Fill in every bracketed […] item. This DPA is intended to attach to the Subscription Agreement (or Pilot Agreement, by reference) and govern processing of personal data performed by ViaVela on the Customer's behalf. Company master (2026-09-05). Product-specific terms are supplied by the Product Schedule named in the Order; jurisdiction riders (Puerto Rico) are applied by jurisdictions/PR.md. Attorney review required before use.

Last updated: 2026-07-10

This Data Processing Addendum (the "DPA") is entered into between ViaVela Solutions LLC, a Nebraska limited liability company ("ViaVela", "we", "us"), and the Customer that has signed the Subscription Agreement or Pilot Agreement (the "Customer"). It supplements that agreement (the "Principal Agreement") and governs ViaVela's processing of Personal Data on the Customer's behalf. Capitalized terms not defined here have the meanings given in the Principal Agreement.

1. Definitions

  • "Personal Data" means information relating to an identified or identifiable natural person that ViaVela processes on the Customer's behalf through the Platform.
  • "Processing" means any operation performed on Personal Data — including collection, recording, storage, retrieval, use, disclosure, erasure, and destruction.
  • "Customer" is the Controller of Personal Data; ViaVela is the Processor. Where the Customer's clients ("End Users" — the Customer's clients or guests who use the Product's end-user-facing experience) are the data subjects, the Customer is the Controller of their data as between the Customer and ViaVela.
  • "Sub-processor" means a third party engaged by ViaVela to process Personal Data on the Customer's behalf (e.g., hosting provider, email provider, payment processor).
  • "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by ViaVela.

2. Scope, roles, and instructions

2.1 ViaVela will Process Personal Data only on the Customer's documented instructions, including (a) as set out in the Principal Agreement and this DPA, (b) the Customer's reasonable use of the Platform's features, and (c) any other written instructions the Customer gives ViaVela. ViaVela will notify the Customer if, in its opinion, an instruction infringes applicable data-protection law.

2.2 Subject matter and duration. ViaVela Processes Personal Data for the duration of the Principal Agreement and any agreed export window after termination.

2.3 Nature and purpose of processing. Operating the Platform for the purposes described in the Product Schedule, and providing related support.

bookings, check-ins, payments accounting, payroll figures, audit logging, email reminders, and the client booking/self-checkout portals

2.4 Categories of data subjects. The Customer's clients (End Users), the Customer's staff and technicians, and the Customer's authorized end users of the Platform.

2.5 Categories of Personal Data. The categories of Personal Data the Platform processes are described in the Product Schedule. A full inventory is maintained at security/data-inventory.md.

Names; phone numbers and/or email addresses (both optional — a client may decline to provide either); appointment history; service preferences; tip and payment records (cash and other manual tenders, and where enabled card-payment references only — never full PAN / CVV); staff profile data; technician device identifiers; waiver acceptances (typed-name signature, timestamp, waiver version, IP/user-agent); and audit log entries.

2.6 Special-category data. ViaVela does not request, encourage, or require Processing of special-category data (e.g., health, biometric, or financial-account-credential data). The Customer should configure free-text fields, file uploads, and notes to avoid collecting such data.

2.5 Categories of Personal Data. Names, phone numbers, email addresses, appointment history, service preferences, tip and payment records (cash, ATH Móvil/QR, and where enabled card-payment references only — never full PAN / CVV), staff profile data, technician device identifiers, waiver acceptances (typed-name signature, timestamp, waiver version, IP/user-agent), and audit log entries.

3. Customer obligations

3.1 The Customer is responsible for the lawful basis to collect and Process Personal Data through the Platform, including providing required notices and obtaining required consents (e.g., for email reminders, the in-app liability waiver, and any marketing communications the Customer chooses to send).

3.2 The Customer warrants that its instructions to ViaVela comply with applicable data-protection law.

3.3 The Customer is responsible for the accuracy, content, and retention choices it configures for its data in the Platform.

including records_retain_days and audit_log_retain_days.

4. ViaVela obligations

4.1 ViaVela will (a) Process Personal Data only for the purposes set out in this DPA and the Principal Agreement; (b) ensure that personnel authorized to Process Personal Data are bound by confidentiality; (c) maintain the security measures described in Annex II; and (d) assist the Customer as set out in Section 7.

4.2 ViaVela will not sell Personal Data and will not Process it for ViaVela's own commercial purposes outside of operating and improving the Platform.

4.3 ViaVela may Process aggregated, de-identified data that does not identify the Customer, any data subject, or any Customer to operate, secure, and improve the Platform.

5. Sub-processors

5.1 The Customer authorizes ViaVela to engage Sub-processors to Process Personal Data, subject to this Section.

5.2 ViaVela will maintain a current list of Sub-processors in Annex I of this DPA (the canonical published list lives at https://viavelahq.com/sub-processors when ViaVela has launched the page — in the interim Annex I governs).

5.3 ViaVela will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains responsible for each Sub-processor's acts and omissions as if performed by ViaVela.

5.4 ViaVela will notify the Customer of a proposed change in Sub-processors at least 15 days in advance. The Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Service component pro rata.

6. Security

6.1 ViaVela will implement and maintain appropriate technical and organizational measures designed to protect Personal Data, as described in Annex II and the documents under security/. These measures are NIST-aligned in design; this is a description of security posture, not a certification, and ViaVela does not represent that it holds any particular compliance certification (e.g., SOC 2, HIPAA, PCI-DSS certification).

6.2 The measures include encryption in transit (TLS) for relay/API endpoints; role-based access control; per-tenant scoping in all reads and writes; Argon2id password hashing for staff sign-in; optional TOTP multi-factor authentication for owners; account lockout after repeated failed sign-ins; audit logging; a documented key-rotation playbook; and a documented backup-and-restore plan.

Role-based access control across Owner, Manager, and Host staff roles, with a separately-authenticated technician app; per-tenant scoping in all reads and writes (salon-key authentication on every relay request).

6.3 ViaVela reviews and updates these measures on a recurring basis as the threat landscape evolves.

7. Assistance to the Customer

7.1 Data-subject requests. ViaVela will (a) where feasible, route data-subject access, correction, deletion, and similar requests it receives directly to the Customer for response; and (b) provide reasonable assistance to the Customer to respond, including by providing export, redaction, or deletion tooling in the Platform.

7.2 Data-protection impact assessments. On request, ViaVela will provide information reasonably necessary to support the Customer's data-protection impact assessments and consultations with regulators.

7.3 Audits. Once per twelve months (or more frequently following a Security Incident or a regulator's request), the Customer may, on 30 days' written notice, request a summary of ViaVela's most recent self-assessment, penetration test report, or third-party audit, to the extent one exists. On-site audits, where required, will be performed by a mutually agreed independent auditor under reasonable confidentiality terms, during normal business hours, at the Customer's expense.

7.2 Data-protection impact assessments. On request, ViaVela will provide information reasonably necessary to support the Customer's data-protection impact assessments and consultations with regulators, including DACO where applicable.

8. Security Incidents

8.1 ViaVela will notify the Customer of a Security Incident without undue delay after becoming aware of it, and in any event within 72 hours where practicable.

8.2 The notification will describe, to the extent then known: (a) the nature of the incident; (b) the categories and approximate number of data subjects and Personal Data records concerned; (c) the likely consequences; and (d) the measures taken or proposed to address it and mitigate its adverse effects.

8.3 ViaVela will cooperate with the Customer's reasonable requests for information necessary to enable the Customer to comply with its own notification obligations under applicable law. ViaVela's incident-response process is documented at security/incident-response-plan.md.

8.3 ViaVela will cooperate with the Customer's reasonable requests for information necessary to enable the Customer to comply with its own notification obligations under applicable law (including any notice the Customer must give DACO or its own PR clients).

9. Cross-border transfers

9.1 ViaVela Processes Personal Data in the United States. If the Customer or its data subjects are located outside the United States, the Customer acknowledges and consents to the transfer for the purposes of operating the Platform.

9.2 If applicable law requires additional transfer mechanisms (e.g., Standard Contractual Clauses, transfer impact assessments, or supplementary measures), the parties will negotiate and execute them in good faith.

9.1 ViaVela Processes Personal Data in the United States, on hosting infrastructure located in the mainland United States. Where the Customer or its data subjects are located in Puerto Rico, the Customer acknowledges that Personal Data collected in Puerto Rico is transferred to, and stored and processed on, servers located in the mainland United States (outside Puerto Rico), and consents to that processing for the purpose of operating the Platform. (PR counsel to confirm whether this cross-border (PR-to-mainland) processing triggers any additional notice obligation to the Customer's own PR clients.)

9.3 Puerto Rico. Nothing in this DPA limits any non-waivable right of a Puerto Rico Customer (or its data subjects) under Puerto Rico consumer-protection law, including the jurisdiction of the Departamento de Asuntos del Consumidor ("DACO"). This DPA does not impose binding arbitration or a class-action waiver on a Puerto Rico consumer data subject. (PR counsel to confirm enforceability.)

10. Retention, return, and deletion

10.1 ViaVela will retain Personal Data only as long as needed to provide the Platform and as set out in security/data-inventory.md and the Customer's retention settings.

10.2 On termination or expiration of the Principal Agreement, ViaVela will provide the Customer a reasonable export window of 30 days and then, on the Customer's written request, delete Personal Data within 30 days, except for data ViaVela must retain by law or that resides in routine backups (which will be deleted in the ordinary course of backup rotation).

11. Liability

The limitations and exclusions of liability in the Principal Agreement apply to this DPA. This DPA does not increase a party's overall liability under the Principal Agreement.

12. Conflict

In case of conflict between this DPA and the Principal Agreement, this DPA controls with respect to the Processing of Personal Data. In case of conflict between this DPA and any Standard Contractual Clauses or other mandatory transfer mechanism executed by the parties, the latter controls.

13. Term

This DPA is effective on the date of the Principal Agreement and continues until ViaVela has deleted all Personal Data Processed on the Customer's behalf under Section 10.


Annex I — Sub-processors (as of 2026-07-10)

Sub-processorServiceLocationPersonal Data Processed
RenderApplication hosting — relay server, admin API, and static site hostingUnited StatesAll Personal Data Processed by the Platform in transit through or stored by the relay
Google LLCTransactional email delivery (Gmail API, service account)United StatesRecipient email addresses, message contents
Stripe, Inc.Card payments, refunds, and related Payment Intents (only when Customer enables card processing)United StatesCard-payment metadata (references, last 4 digits) — never full PAN/CVV
Sub-processorServiceLocationPersonal Data Processed
GitHub, Inc. (Microsoft)Private-repository and release-asset hosting for the desktop installer downloadUnited States (confirm specific hosting region with counsel)None directly — installer binary distribution only; no Customer Personal Data is stored with GitHub

Not currently in use. ViaVela does not currently use any third-party analytics or advertising service. It is not listed as a Sub-processor because it does not Process Personal Data today. When it becomes active, ViaVela will update this Annex and provide the 15-day change notice required by Section 5.4.

ViaVela does not currently use SMS/text messaging as a notification channel (planned for a future release pending carrier registration) and does not use any third-party analytics or advertising service. Neither is listed as a Sub-processor because neither Processes Personal Data today. When either becomes active, ViaVela will update this Annex and provide the 15-day change notice required by Section 5.4.

The Customer chooses whether to enable optional third-party services (e.g., card payment processing). When the Customer disables a service, the corresponding Sub-processor does not Process the Customer's Personal Data.

Evertec, Inc. — ATH Móvil (PR pilot payment method)PR mobile/bank-linked payment tender (cash-equivalent)Puerto Rico / USPayment reference/transaction metadata only — never card PAN/CVV (confirm exact Sub-processor entity name and role with counsel before publication)

Annex II — Technical and organizational measures (summary)

A full description lives in the security/ folder; the summary below is referenced by this DPA. These are the controls actually implemented as of the Last-updated date above; this Annex will be updated as controls change, and will not describe a control ViaVela has not implemented.

  • Access control: Role-based staff access, scoped to documented permissions; a separately paired and authenticated personnel-facing app; per-tenant scoping enforced on every read and write; account lockout after repeated failed sign-ins.

Access control: Role-based staff access (Owner / Manager / Host), each scoped to the permissions in src-tauri/src/auth.rs; a separately paired and authenticated technician app; per-tenant scoping enforced on every read and write via the salon-key; account lockout after repeated failed sign-ins.

  • Authentication: Argon2id password hashing (12-character minimum) for staff sign-in; optional TOTP multi-factor enrollment for owners (not yet mandatory); idle-timeout and re-authentication windows for sensitive actions.
  • Encryption: TLS in transit for relay/API endpoints; relay state file written with restricted file permissions.
  • Network: Strict CORS allowlist for the relay in production; Content-Security-Policy on the desktop app excludes wildcards.

Network: Strict CORS allowlist for the relay in production; Content-Security-Policy on the desktop app excludes wildcards.

  • Logging & audit: A tamper-evident audit_log of sensitive actions, with configurable retention and CSV export for the Customer's own review.
  • Vulnerability management: Severity SLAs per security/vulnerability-policy.md; periodic dependency scanning; a documented key-rotation playbook at security/key-rotation-playbook.md.

periodic dependency scanning (npm audit, cargo audit)

  • Resilience: A documented backup process and restore-drill procedure (see security/backup-restore-plan.md); a documented incident-response process with a 72-hour notification target (Section 8).
  • Personnel: All ViaVela personnel with access to Customer Personal Data are bound by written confidentiality obligations.

Signatures

ViaVela Solutions LLC By: ________________________ Name: ______________ Title: ______ Date: ______

[CUSTOMER LEGAL NAME — fill at signing] By: ________________________ Name: ______________ Title: ______ Date: ______


Contact: hello@viavelahq.com · legal@viavelahq.com · viavelahq.com

Tell us what your business runs on today.

A notebook, a spreadsheet, a whiteboard, a great memory: that is the system that got you here. We start from there. No forms, no sales funnel: one email, read by a person.

hello@viavelahq.com →