ViaVela

Legal documents › ViaVela Viridis

ViaVela Data Processing Addendum (DPA) — US

Draft: attorney review pending United States · English source stamp 70dfdf64632a

ViaVela Data Processing Addendum (DPA) — US

DRAFT — for U.S. (Nebraska) counsel review. Not legal advice and not final. Have a licensed Nebraska attorney review before signing. Fill in every bracketed […] item. This DPA is intended to attach to the Subscription Agreement (or Pilot Agreement, by reference) and govern processing of personal data performed by ViaVela on the Customer's behalf. Company master (2026-09-05). Product-specific terms are supplied by the Product Schedule named in the Order; jurisdiction riders (Puerto Rico) are applied by jurisdictions/PR.md. Attorney review required before use.

Last updated: 2026-07-10

This Data Processing Addendum (the "DPA") is entered into between ViaVela Solutions LLC, a Nebraska limited liability company ("ViaVela", "we", "us"), and the Customer that has signed the Subscription Agreement or Pilot Agreement (the "Customer"). It supplements that agreement (the "Principal Agreement") and governs ViaVela's processing of Personal Data on the Customer's behalf. Capitalized terms not defined here have the meanings given in the Principal Agreement.

1. Definitions

  • "Personal Data" means information relating to an identified or identifiable natural person that ViaVela processes on the Customer's behalf through the Platform.
  • "Processing" means any operation performed on Personal Data — including collection, recording, storage, retrieval, use, disclosure, erasure, and destruction.
  • "Customer" is the Controller of Personal Data; ViaVela is the Processor. Where the Customer's clients ("End Users" — the Customer's clients or guests who use the Product's end-user-facing experience) are the data subjects, the Customer is the Controller of their data as between the Customer and ViaVela.
  • "Sub-processor" means a third party engaged by ViaVela to process Personal Data on the Customer's behalf (e.g., hosting provider, email provider, payment processor).
  • "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by ViaVela.

2. Scope, roles, and instructions

2.1 ViaVela will Process Personal Data only on the Customer's documented instructions, including (a) as set out in the Principal Agreement and this DPA, (b) the Customer's reasonable use of the Platform's features, and (c) any other written instructions the Customer gives ViaVela. ViaVela will notify the Customer if, in its opinion, an instruction infringes applicable data-protection law.

2.2 Subject matter and duration. ViaVela Processes Personal Data for the duration of the Principal Agreement and any agreed export window after termination.

2.3 Nature and purpose of processing. Operating the Platform for the purposes described in the Product Schedule, and providing related support.

2.3 Nature and purpose of processing. Job and dispatch record-keeping; route optimization and scheduling; estimate and materials/inventory tracking; crew scheduling and status tracking; a customer-facing portal for estimate approval and visit/invoice visibility; account administration; and support.

2.4 Categories of data subjects. The Customer's clients (End Users), the Customer's staff and technicians, and the Customer's authorized end users of the Platform.

2.5 Categories of Personal Data. The categories of Personal Data the Platform processes are described in the Product Schedule. A full inventory is maintained at security/data-inventory.md.

2.5 Categories of Personal Data. Names; contact details (phone, email, mailing/service address); employment/role data for the Customer's staff and crew members; and customer records including service address, job and estimate history, estimate/invoice line items and totals, and portal messaging content. ViaVela does not store raw payment-card or bank-account numbers — its own subscription-billing fees run through Stripe's processor-hosted Checkout flow, and ViaVela stores only a processor reference (e.g., Stripe subscription ID) and payment status, never full card number (PAN), CVV, or bank account/routing numbers. As of this DPA, the Platform has no processor-hosted flow for collecting the Business's own customer payments through a Stripe-hosted invoice pay-link beyond what Section 5's Annex I describes; a full inventory is maintained at security/data-inventory.md.

2.6 Special-category data. ViaVela does not request, encourage, or require Processing of special-category data (e.g., health, biometric, or financial-account-credential data). The Customer should configure free-text fields, file uploads, and notes to avoid collecting such data.

3. Customer obligations

3.1 The Customer is responsible for the lawful basis to collect and Process Personal Data through the Platform, including providing required notices and obtaining required consents (e.g., for email reminders, the in-app liability waiver, and any marketing communications the Customer chooses to send).

3.2 The Customer warrants that its instructions to ViaVela comply with applicable data-protection law.

3.3 The Customer is responsible for the accuracy, content, and retention choices it configures for its data in the Platform.

Viridis has no records_retain_days or audit_log_retain_days configuration keys; the Platform does not expose a Customer-configurable per-record retention window, and Customer Data is retained per ViaVela's data-inventory practices described in Section 10.

4. ViaVela obligations

4.1 ViaVela will (a) Process Personal Data only for the purposes set out in this DPA and the Principal Agreement; (b) ensure that personnel authorized to Process Personal Data are bound by confidentiality; (c) maintain the security measures described in Annex II; and (d) assist the Customer as set out in Section 7.

4.2 ViaVela will not sell Personal Data and will not Process it for ViaVela's own commercial purposes outside of operating and improving the Platform.

4.3 ViaVela may Process aggregated, de-identified data that does not identify the Customer, any data subject, or any Customer to operate, secure, and improve the Platform.

5. Sub-processors

5.1 The Customer authorizes ViaVela to engage Sub-processors to Process Personal Data, subject to this Section.

5.2 ViaVela will maintain a current list of Sub-processors in Annex I of this DPA (the canonical published list lives at https://viavelahq.com/sub-processors when ViaVela has launched the page — in the interim Annex I governs).

5.3 ViaVela will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains responsible for each Sub-processor's acts and omissions as if performed by ViaVela.

5.4 ViaVela will notify the Customer of a proposed change in Sub-processors at least 15 days in advance. The Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Service component pro rata.

6. Security

6.1 ViaVela will implement and maintain appropriate technical and organizational measures designed to protect Personal Data, as described in Annex II and the documents under security/. These measures are NIST-aligned in design; this is a description of security posture, not a certification, and ViaVela does not represent that it holds any particular compliance certification (e.g., SOC 2, HIPAA, PCI-DSS certification).

6.2 The measures include encryption in transit (TLS) for relay/API endpoints; role-based access control; per-tenant scoping in all reads and writes; Argon2id password hashing for staff sign-in; optional TOTP multi-factor authentication for owners; account lockout after repeated failed sign-ins; audit logging; a documented key-rotation playbook; and a documented backup-and-restore plan.

6.2 The measures include: encryption in transit (TLS) for all API and application traffic; role-based access control across the Customer's office_admin (office staff), crew, and customer roles, enforced by a single authoritative role-permission map (deny-by-default for any unmapped role or permission); per-tenant scoping enforced by structural company-scoping on every read and by-id access, where a cross-company id returns a not-found response rather than a leak-revealing forbidden response; Argon2id password hashing for staff sign-in; optional time-based multi-factor authentication; account lockout after repeated failed sign-ins; audit logging; a documented key-rotation playbook; and a documented backup-and-restore plan. There is no separate technician/crew app or salon-key credential.

6.3 ViaVela reviews and updates these measures on a recurring basis as the threat landscape evolves.

7. Assistance to the Customer

7.1 Data-subject requests. ViaVela will (a) where feasible, route data-subject access, correction, deletion, and similar requests it receives directly to the Customer for response; and (b) provide reasonable assistance to the Customer to respond, including by providing export, redaction, or deletion tooling in the Platform.

7.2 Data-protection impact assessments. On request, ViaVela will provide information reasonably necessary to support the Customer's data-protection impact assessments and consultations with regulators.

7.3 Audits. Once per twelve months (or more frequently following a Security Incident or a regulator's request), the Customer may, on 30 days' written notice, request a summary of ViaVela's most recent self-assessment, penetration test report, or third-party audit, to the extent one exists. On-site audits, where required, will be performed by a mutually agreed independent auditor under reasonable confidentiality terms, during normal business hours, at the Customer's expense.

8. Security Incidents

8.1 ViaVela will notify the Customer of a Security Incident without undue delay after becoming aware of it, and in any event within 72 hours where practicable.

8.2 The notification will describe, to the extent then known: (a) the nature of the incident; (b) the categories and approximate number of data subjects and Personal Data records concerned; (c) the likely consequences; and (d) the measures taken or proposed to address it and mitigate its adverse effects.

8.3 ViaVela will cooperate with the Customer's reasonable requests for information necessary to enable the Customer to comply with its own notification obligations under applicable law. ViaVela's incident-response process is documented at security/incident-response-plan.md.

9. Cross-border transfers

9.1 ViaVela Processes Personal Data in the United States. If the Customer or its data subjects are located outside the United States, the Customer acknowledges and consents to the transfer for the purposes of operating the Platform.

9.2 If applicable law requires additional transfer mechanisms (e.g., Standard Contractual Clauses, transfer impact assessments, or supplementary measures), the parties will negotiate and execute them in good faith.

10. Retention, return, and deletion

10.1 ViaVela will retain Personal Data only as long as needed to provide the Platform and as set out in security/data-inventory.md and the Customer's retention settings.

10.2 On termination or expiration of the Principal Agreement, ViaVela will provide the Customer a reasonable export window of 30 days and then, on the Customer's written request, delete Personal Data within 30 days, except for data ViaVela must retain by law or that resides in routine backups (which will be deleted in the ordinary course of backup rotation).

11. Liability

The limitations and exclusions of liability in the Principal Agreement apply to this DPA. This DPA does not increase a party's overall liability under the Principal Agreement.

12. Conflict

In case of conflict between this DPA and the Principal Agreement, this DPA controls with respect to the Processing of Personal Data. In case of conflict between this DPA and any Standard Contractual Clauses or other mandatory transfer mechanism executed by the parties, the latter controls.

13. Term

This DPA is effective on the date of the Principal Agreement and continues until ViaVela has deleted all Personal Data Processed on the Customer's behalf under Section 10.


Annex I — Sub-processors (as of 2026-07-10)

Sub-processorServiceLocationPersonal Data Processed
RenderApplication hosting — relay server, admin API, and static site hostingUnited StatesAll Personal Data Processed by the Platform in transit through or stored by the relay
Google LLCTransactional email delivery (Gmail API, service account)United StatesRecipient email addresses, message contents
Stripe, Inc.Card payments, refunds, and related Payment Intents (only when Customer enables card processing)United StatesCard-payment metadata (references, last 4 digits) — never full PAN/CVV

Viridis has no desktop installer or private-repository release-asset distribution; this Sub-processor row does not apply — the Platform is delivered entirely as a hosted web application.

Not currently in use. ViaVela does not currently use any third-party analytics or advertising service. It is not listed as a Sub-processor because it does not Process Personal Data today. When it becomes active, ViaVela will update this Annex and provide the 15-day change notice required by Section 5.4.

Viridis's Platform has no SMS capability; it does not use SMS/text messaging as a notification channel. It is not listed as a Sub-processor because it does not Process Personal Data today. If SMS is added in the future, ViaVela will update this Annex and provide the 15-day change notice required by Section 5.4.

The Customer chooses whether to enable optional third-party services (e.g., card payment processing). When the Customer disables a service, the corresponding Sub-processor does not Process the Customer's Personal Data.

Annex II — Technical and organizational measures (summary)

A full description lives in the security/ folder; the summary below is referenced by this DPA. These are the controls actually implemented as of the Last-updated date above; this Annex will be updated as controls change, and will not describe a control ViaVela has not implemented.

  • Access control: Role-based staff access, scoped to documented permissions; a separately paired and authenticated personnel-facing app; per-tenant scoping enforced on every read and write; account lockout after repeated failed sign-ins.

Viridis has no installed desktop application and therefore no Content-Security-Policy control scoped to one; this item does not apply. The Platform's browser-facing network control is the explicit-origin CORS allowlist (no wildcard origins) described above.

  • Authentication: Argon2id password hashing (12-character minimum) for staff sign-in; optional TOTP multi-factor enrollment for owners (not yet mandatory); idle-timeout and re-authentication windows for sensitive actions.
  • Encryption: TLS in transit for relay/API endpoints; relay state file written with restricted file permissions.
  • Network: Strict CORS allowlist for the relay in production; Content-Security-Policy on the desktop app excludes wildcards.

Access control: Role-based access across the office_admin (office staff), crew, and customer roles, enforced by a single authoritative role-permission map, deny-by-default for any unmapped role or permission, with a second scoping layer below tenancy for crews (their assigned jobs) and customers (their own estimates/jobs); per-tenant scoping enforced by structural company-scoping on every read and by-id access; account lockout after repeated failed sign-ins. There is no separately paired personnel-facing application and no salon-key credential.

  • Logging & audit: A tamper-evident audit_log of sensitive actions, with configurable retention and CSV export for the Customer's own review.
  • Vulnerability management: Severity SLAs per security/vulnerability-policy.md; periodic dependency scanning; a documented key-rotation playbook at security/key-rotation-playbook.md.

periodic dependency scanning (pip-audit for the backend, npm audit for the frontend)


© 2026 ViaVela Solutions LLC. All rights reserved.

  • Resilience: A documented backup process and restore-drill procedure (see security/backup-restore-plan.md); a documented incident-response process with a 72-hour notification target (Section 8).
  • Personnel: All ViaVela personnel with access to Customer Personal Data are bound by written confidentiality obligations.

Signatures

ViaVela Solutions LLC By: ________________________ Name: ______________ Title: ______ Date: ______

[CUSTOMER LEGAL NAME — fill at signing] By: ________________________ Name: ______________ Title: ______ Date: ______


Contact: hello@viavelahq.com · legal@viavelahq.com · viavelahq.com

Tell us what your business runs on today.

A notebook, a spreadsheet, a whiteboard, a great memory: that is the system that got you here. We start from there. No forms, no sales funnel: one email, read by a person.

hello@viavelahq.com →