Data Protection Agreement (DPA)
Apr 26, 2026
This Data Protection Agreement (“DPA”) governs the processing of personal data by Vellix on behalf of its clients.
1. Roles
Client: Data Controller
Vellix: Data Processor
2. Scope
This DPA applies to all personal data processed in connection with Vellix services.
3. Data Processing
Vellix agrees to:
Process data only on documented instructions
Ensure confidentiality of personnel
Implement appropriate security measures
4. Sub-processors
Vellix may engage third-party sub-processors (e.g., cloud providers). We ensure they meet data protection standards.
5. Security Measures
We implement:
Encryption (where applicable)
Access controls
Monitoring and incident response
6. Data Breach Notification
In case of a data breach, Vellix will notify the client without undue delay.
7. Data Subject Rights
We assist clients in fulfilling requests such as:
Access
Correction
Deletion
8. Data Transfers
If data is transferred internationally, we ensure appropriate safeguards are in place.
9. Data Retention & Deletion
Upon termination, data will be deleted or returned unless legally required to retain it.
10. Audit Rights
Clients may request reasonable audits to verify compliance.
11. Liability
Each party is responsible for compliance with applicable data protection laws.
12. Governing Law
This DPA is governed by the laws of [Insert Country/Region].