Back to Home

Data Processing Addendum

Last updated: 1/29/2026

Overview

This Data Processing Addendum ("DPA") forms part of the agreement between Vespper and you regarding the processing of personal data in accordance with applicable data protection laws, including GDPR and CCPA.

Definitions

  • Data Controller: The entity that determines the purposes and means of processing personal data
  • Data Processor: The entity that processes personal data on behalf of the Data Controller
  • Personal Data: Any information relating to an identified or identifiable natural person
  • Processing: Any operation performed on personal data

Data Processing Terms

Vespper shall process personal data only:

  • In accordance with documented instructions from the Data Controller
  • For the purposes of providing the services outlined in our agreement
  • In compliance with applicable data protection laws and regulations
  • With appropriate technical and organizational security measures

Security Measures

Vespper implements industry-standard security measures including:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication mechanisms
  • Employee training on data protection

Sub-processors

Vespper may engage sub-processors to assist in providing services. We maintain a list of sub-processors and will notify you of any changes in accordance with applicable law.

Data Subject Rights

Vespper will assist you in responding to data subject requests, including requests for access, rectification, erasure, and data portability.

Contact

For questions about data processing, please contact our Data Protection Officer at dpo@vespper.com

Vespper Logo
The AI editor for professional documents