Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Oceanx Consulting Pty Ltd (ABN 67 615 055 368), trading as Vendarity (“we”), and the customer (“you”). You accept it when you accept the Terms; no separate signature is needed. It applies whenever we process personal information on your behalf in your Vendarity workspaces.
In short
- You decide what personal information goes into your workspace; we process it only to provide Vendarity on your instructions.
- We use the subprocessors on our public list and give at least 30 days’ notice before adding or replacing one.
- We tell you about a personal data breach without undue delay, and where feasible within 72 hours.
- You can export everything at any time. After a workspace ends, it is deleted after 30 days and recovery copies expire within 35 more days.
1. Scope and definitions
Customer personal data means personal information (personal data) in customer data that we process for you: information about your users, supplier contacts, auditors and anyone named in documents or messages in your workspace. It does not include information we handle as a controller under our Privacy Policy, such as buyer sign-in accounts, billing relationships and website traffic, or records a supplier keeps in its own supplier library (a feature not offered today). A document a supplier shares from its library becomes customer data when you take it into review.
Data protection laws means the laws that apply to that processing, including Australia’s Privacy Act 1988, New Zealand’s Privacy Act 2020, the UK GDPR and Data Protection Act 2018, Canada’s PIPEDA and Quebec’s private-sector privacy law, and US state privacy laws such as the California Consumer Privacy Act. Terms such as controller, processor, service provider and personal data breach have the meanings those laws give them.
2. Roles and instructions
You are the controller (or, in the United States, the business) for customer personal data, and we are your processor (service provider). If you act for another controller, you confirm that you have its authority and we are your subprocessor.
We process customer personal data only on your documented instructions. Your instructions are these terms and your use and configuration of Vendarity: the records and files you add, requests and reminder settings, AI-assisted review if you turn it on, exports, auditor sharing and support-access grants. We will tell you if we believe an instruction breaks a data protection law, and we may decline to follow it. If the law requires us to process it otherwise, we will tell you first unless the law forbids it.
You are responsible for having a lawful basis and any permission or notice the law requires for the personal information you add and the messages you ask us to send.
3. Details of the processing
- Subject matter and purpose: providing Vendarity: collecting, scanning, storing, displaying, extracting details from, reviewing, reporting on, exporting and deleting supplier documents and related records, and sending requests and reminders.
- Duration: for the term of the agreement and the deletion periods in section 10.
- People concerned: your workspace users, supplier contacts, invited auditors, and people named in documents, messages and notes.
- Types of information: names, business email addresses and phone numbers, roles, timezone, message and channel permissions, sign-in and activity records, documents and their contents (for example names and signatures on certificates), messages, answers and review decisions.
- Sensitive information: not intended. You must not upload medical records, government identity documents, payment-card details or employee credentialing records.
- Locations: The application server and database run on a Hostinger VPS in Malaysia (Kuala Lumpur). Evidence files are stored in a private Backblaze B2 bucket in US East (us-east-005). This is not Australian-only hosting. Other locations are listed on the Subprocessors page.
4. Our people and support access
Everyone we allow to process customer personal data is bound by confidentiality. Our support operators are named, use multi-factor authentication, and see account metadata only (names, counts and dates). They can open evidence only while your Owner or Admin has granted time-limited support access (1 to 72 hours, revocable at any time), and every view and download is recorded in your workspace’s activity history. There is no hidden or permanent impersonation.
5. Security measures
We maintain technical and organizational measures appropriate to the risk, including:
- HTTPS for all traffic, secure HttpOnly cookies, origin checks, a restrictive content security policy, and no caching of private pages;
- workspace isolation enforced by database row-level security as well as the application, separate least-privilege runtime database roles, and tenant-bound background jobs;
- authenticator-app multi-factor authentication for Owners, Admins and operators, re-authentication for exports and closure, session controls and rate limits;
- quarantined uploads, malware scanning in an isolated sandbox without network access, and clean copies kept separately; evidence files encrypted at rest (Backblaze SSE-B2, AES-256) in a private bucket with random object names;
- original files streamed only after checking current access, so revocation is immediate; no reusable public file links;
- append-only decision and activity records with signed daily digests kept off the database server, so later changes are detectable;
- AI requests sent only for a workspace that opted in, with no search, tools or stored interactions, and outputs checked against a fixed schema before a person reviews them.
Not yet in place: independent backups in a separate location and verified encryption of the database disk. We hold no SOC 2, ISO 27001 or similar certification. We will update this list when these change.
6. Subprocessors
You authorize the subprocessors on our Subprocessors page. We bind each by written terms that protect customer personal data at least as well as this DPA requires, and we remain responsible for them. We will email your Owners and update that page at least 30 days before a new or replacement subprocessor processes customer personal data (or as soon as possible in an emergency). You can object on reasonable data protection grounds during that period. We will discuss alternatives; if we cannot resolve the objection, you may end the affected service and we will refund fees prepaid for the period after it ends.
7. International transfers
Customer personal data is processed outside Australia, New Zealand, the United Kingdom and Canada, in the locations described in section 3. You instruct us to transfer it there to provide the service. We transfer it only to subprocessors bound by written data protection terms and protect it as section 5 describes.
- Australia: we handle the information in line with the Australian Privacy Principles, including APP 8, and remain accountable for our subprocessors.
- New Zealand: we and our subprocessors are bound by safeguards comparable to the Privacy Act 2020, as IPP 12 requires.
- United Kingdom: where the UK GDPR applies to your transfer to us, the parties incorporate the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner (Module 2, or Module 3 where you are a processor). Its tables are completed by sections 1 to 6 and 9 of this DPA, the Subprocessors page, and the security measures in section 5; neither party may end it under its section 19.
- Canada and Quebec: we will give you the information you reasonably need to assess transfers outside Quebec or Canada, including for a privacy impact assessment.
8. Requests from people and other assistance
Vendarity gives you tools to export, correct and delete workspace records (see the Privacy Policy). If we receive a request from a person about customer personal data, we will pass it to you within five business days and will not answer it ourselves except to direct the person to you, unless the law requires. We will give reasonable help, with the information we hold, for requests the tools do not cover, for data protection impact assessments, and for consultations with regulators.
9. Personal data breaches
If we become aware of a personal data breach affecting customer personal data, we will notify your Owners without undue delay and, where feasible, within 72 hours. We will include what we know about:
- what happened and when, and the records affected;
- the categories and approximate number of people;
- the likely consequences; and
- what we have done and recommend, and who to contact.
We will update you as we learn more, contain the breach, keep a record of it, and help you meet your own duties to notify regulators and people (for example under Australia’s Notifiable Data Breaches scheme, the UK GDPR, PIPEDA or Quebec law). We will not notify your suppliers or regulators on your behalf without your agreement unless the law requires us to. Notifying you is not an admission of fault.
10. Return and deletion
You can export all customer data, including original files, at any time from Settings → Data & closure, including during the read-only period. When your workspace ends (trial ended, paid subscription ended, or closed by an Owner), it is read-only for 30 days and then deleted from the live service. Recovery copies expire within 35 days after they are made, so deletion is complete within 65 days of the read-only period starting; recorded deletions are reapplied before any restored copy is used. We keep customer personal data longer only under a legal hold or where the law requires, and we will confirm deletion in writing on request.
11. Information and audits
We will make available the information reasonably needed to show that we meet this DPA, including a description of our security measures and test evidence. If that is not enough, or a regulator requires it, you may audit our compliance once a year (and after a breach) with 30 days’ notice, during business hours, under confidentiality and at your cost. Audits of our subprocessors rely on the reports and terms they provide.
12. US state privacy laws
Where the California Consumer Privacy Act or a similar state law applies, we act as your service provider (processor) and we:
- process customer personal data only for the business purpose of providing Vendarity as described in section 3;
- do not sell or share it (including for cross-context behavioural advertising), or retain, use or disclose it outside our direct business relationship with you or for any other purpose, except as those laws allow;
- do not combine it with personal information from other sources, except as those laws allow;
- provide the same level of privacy protection the law requires of you, help you answer consumer requests, and tell you if we can no longer meet these obligations.
You may take reasonable steps to stop and remedy any unauthorized use. We certify that we understand and will comply with these restrictions.
13. Liability and precedence
Liability under this DPA is subject to the limits in the Terms, which do not limit any rights people have directly under data protection laws. If this DPA conflicts with the Terms, this DPA prevails for data protection; if it conflicts with the UK transfer addendum, the addendum prevails. This DPA lasts as long as we process customer personal data. To contact us about it, use the privacy and support email address that will be published on this page before paid plans or live customer data begin (until then, contact the person at Vendarity who invited you).
Contact
Vendarity is operated by Oceanx Consulting Pty Ltd, ABN 67 615 055 368, Australia. To ask a question, exercise a privacy right or make a complaint, use the privacy and support email address that will be published on this page before paid plans or live customer data begin (until then, contact the person at Vendarity who invited you). You can also contact your privacy regulator; the Privacy Policy lists them.