# Data processing addendum

URL: https://vrisic.com/data-processing-addendum/
Last updated: 2026-10-04

> The terms that apply when we handle personal data inside your systems or data while building for you.

**Last updated:** 4 October 2026

This addendum forms part of every proposal, statement of work or services agreement in which Vrisic (“Vrisic”) processes personal data on behalf of a client (“you”). If a signed data processing agreement exists for your project, that signed version applies instead. We are happy to sign your own template after review.

## 1. Roles

You are the controller (or business, or data fiduciary) and Vrisic is the processor (or service provider) for personal data we handle while building, testing or supporting your systems. We process it only to deliver the services in the agreement and on your documented instructions, unless the law requires otherwise, in which case we tell you first where we are allowed to.

## 2. What we process

- **Subject matter and duration:** the services in the agreement, for its term and the deletion period below.
- **Types of data:** those in the sample data, documents, systems and logs you give us access to, such as names, contact details, account and transaction records, or support conversations.
- **People concerned:** your customers, users, employees or contacts, as set by your use case.
- **Special categories:** only if agreed in writing, with extra safeguards. For US health data we use de identified samples unless a Business Associate Agreement is signed.

## 3. Our duties

- Everyone who can access your data is bound by confidentiality.
- We apply the security measures on our [security page](https://vrisic.com/security/) , including least privilege access, two factor authentication, encryption in transit and at rest, and private environments per client.
- We do not use your personal data to train models for anyone else, and we do not sell it or use it for our own purposes.
- We help you answer requests from individuals, carry out data protection impact assessments and meet your security and breach duties, as far as our role allows.
- We tell you without undue delay, and in any case within 48 hours, after we become aware of a personal data breach affecting your data, with the information we have at the time.

## 4. Subprocessors

You authorise the subprocessors listed on our [subprocessors page](https://vrisic.com/subprocessors/) and any named in your proposal. We give you at least 14 days notice before adding or replacing one that will process your personal data, so you can object on reasonable grounds. We impose the same data protection duties on them and stay responsible for their work.

## 5. International transfers

Our team works from India. Where personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, the European Commission’s Standard Contractual Clauses (controller to processor or processor to processor, as the case may be), the UK International Data Transfer Addendum and the Swiss adaptations are incorporated by reference. For the UAE, Saudi Arabia, DIFC or ADGM we follow the transfer rules of the law that applies. If you need data to stay in a region, we agree the hosting region and keep production data there.

## 6. Audits

We make available the information reasonably needed to show compliance with this addendum and allow reviews by you or an independent auditor bound by confidentiality, with reasonable notice, at most once a year unless a regulator requires more or there has been a breach.

## 7. Return and deletion

At the end of the services, or earlier on your request, we return or delete your personal data and copies within 30 days, unless the law requires us to keep some of it, in which case we keep it secure and use it for nothing else.

## 8. Laws covered

This addendum is written to meet Article 28 of the GDPR and UK GDPR, the service provider rules of the CCPA and CPRA and other US state privacy laws, the UAE and Saudi Personal Data Protection Laws, Canada’s PIPEDA, Australia’s Privacy Act 1988, and India’s Digital Personal Data Protection Act, 2023. Questions:

- Email: [info@vrisic.com](mailto:info@vrisic.com)
- WhatsApp: [+91 63777 67206](https://wa.me/916377767206?text=Hi%20Vrisic%2C%20I%20found%20you%20on%20your%20website%20%28Privacy%20or%20legal%20question%29.%20I%20would%20like%20to%20talk%20about%20an%20AI%20project.)
- Postal address: India (remote first company)

---
Vrisic · https://vrisic.com/ · Contact: info@vrisic.com · Book a call: https://vrisic.com/contact/