Data Processing Addendum
The processor terms governing personal data we handle on your behalf, for customers whose own compliance obligations require a signed agreement.
This document is provided on request, not as a click-through
The DPA is executed as a countersigned agreement between your organization and Virex Systems LLC rather than published as a page you accept by scrolling past it. Ask through the contact page and we will send the current version for review, usually the same week. The scope, the subprocessor list, and the security commitments it contains are all described below, so you can assess whether it will satisfy your requirements before you ask for it.
What the DPA covers.
So you can judge the fit before requesting the document itself.
- Roles: you are the controller for personal data in your product data, and we are the processor acting on your instructions.
- Scope: the categories of data, the categories of data subjects, and the processing activities we perform.
- Subprocessors: the current list, our commitment to keep it published, and notice before we add one.
- Security: the technical and organisational measures we apply, matching what our security page states.
- Assistance: our obligations to help with data subject requests, breach notification, and audits or assessments.
- International transfers: the safeguards relied on where processing crosses borders.
- Deletion and return: what happens to your data when the agreement ends.
This summary is here to be readable. The numbered clauses below are the operative text.
What the terms say
Roles and instructions
Where we process personal data contained in your product data, your organization is the controller and Virex Systems LLC is the processor. We process that data only on your documented instructions, which include the instructions inherent in using the features you subscribed to.
For account and billing data we act as controller in our own right, and our privacy policy governs that processing.
Scope of processing
The categories of personal data are those described in our privacy policy: account identifiers for your members, and the product data your organization creates through the service, including session records and the memories your agents write.
Your source repositories and model credentials are outside this scope entirely, because they are never transmitted to us.
Subprocessors
We maintain a published list of subprocessors covering payments, infrastructure and storage, transactional email, and error monitoring. The DPA commits us to keeping that list current and to giving notice before adding a new subprocessor, with a mechanism for you to object.
Security measures
The technical and organisational measures in the DPA are the ones described on our security page, including per-organization isolation enforced at the database layer, encryption in transit and at rest, server-side session management, and audit logging of security events.
We do not claim SOC 2 certification in the DPA or anywhere else. Controls are designed to a SOC 2-oriented control set with no audit completed.
Assistance and notification
We commit to assisting you with data subject requests where the data sits in our systems, to notifying you without undue delay if we become aware of a personal data breach affecting your data, and to providing the information you reasonably need for your own assessments.
Deletion and return
On termination, tenant-scoped data held for your organization is deleted in line with our retention practices. Where you need an export before that happens, ask and we will arrange it.
How to get the document
Contact us and say your organization needs the DPA. Tell us if you have a specific framework you are working to, since that helps us route it correctly first time.
If your legal team needs redlines, or needs it alongside a countersigned order form, say so at the same time and we will handle both together rather than in sequence.
Ask before you sign.
If your legal or procurement team needs something changed, clarified, or evidenced, contact us and we will answer specifically rather than pointing at this page again.