Data Processing Addendum
How Viznerve processes personal data on your studio’s behalf. You’re the controller; we’re the processor — and we only act on your instructions.
01Parties & roles
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified on the account (“Customer”, “you”) and VizNerve LLC, a limited liability company organised in Wyoming, USA, operating from India, the provider of Viznerve (“Viznerve”, “we”, “us”) [LAWYER: insert VizNerve LLC’s registered Wyoming address]. It applies whenever Viznerve processes personal data on your behalf in connection with the Viznerve application, and supplements our Terms of Service and Privacy Policy.
For the personal data described in this DPA, you are the controller (you decide why and how it’s processed) and Viznerve is the processor (we process it only to run the service for you). Where data-protection law uses different labels — such as “business” and “service provider” under the CCPA/CPRA — the equivalent roles apply.
02Subject-matter, duration, nature & purpose
- Subject-matter. The provision of Viznerve — an AI operator for creative studios and agencies that triages inbound inquiries, drafts replies and quotes, and surfaces studio health.
- Duration. The term of your subscription, plus the deletion window in Return & deletion below.
- Nature of processing. Collection via the accounts you connect, storage, structuring, classification, AI-assisted analysis and drafting, retrieval, display to your team, and deletion.
- Purpose. Solely to provide, secure, and support the service as described in the Terms — and for nothing else.
03Categories of data subjects & personal data
What Viznerve processes depends on what you connect. Typically:
- Data subjects — your studio’s team members (users of the account); your clients, prospects, and inbound inquirers; other individuals appearing in the emails, calendar events, and files you connect.
- Personal data — names, email addresses, and contact details; the content of inbound inquiry emails and threads (Gmail, if connected); calendar event details (Google Calendar, if connected); project files and their metadata (Google Drive or Dropbox, if connected — per-file scope only, never your whole drive); invoicing and billing records; and usage records of the account itself.
- Special categories. The service is not designed to process special categories of personal data (health, biometrics, etc.). You agree not to use Viznerve to process them deliberately; incidental content inside connected emails or files is processed under the same protections as everything else.
04Processor obligations
Viznerve will:
- Process personal data only on your documented instructions — which are: the Terms, this DPA, your configuration of the service, and the actions you and your team take in the app. We’ll tell you if we believe an instruction breaks data-protection law.
- Ensure everyone we authorise to process the data is bound by confidentiality obligations.
- Never sell your data, never share it for advertising, and never use it to train, fine-tune, or improve any AI model — by us or on our behalf.
- Assist you, taking into account the nature of the processing, with your own obligations — data-subject rights, security, breach notification, and (where required) data-protection impact assessments.
- Not process the data for any purpose other than providing the service.
05Security measures
Viznerve implements appropriate technical and organisational measures, including:
- Tenant isolation — every studio is isolated at the database layer; data is filtered to your tenant on every query, enforced at the storage level, not just in application code.
- Encryption at rest — sensitive content (including raw email bodies and connection tokens) is encrypted with a per-studio key; tokens are never logged.
- Encryption in transit — all traffic is served over HTTPS/TLS.
- Access controls — role-based access inside the app; passwordless sign-in via secure email links; internal access to production data limited to what operating the service requires.
- Scoped connections — Google connections (Gmail, Calendar, Drive) are brokered by Composio’s verified Google app under least-privilege scopes (Drive is per-file, Calendar is read-only events); Viznerve holds no Google OAuth client of its own. Gmail sync covers your Primary inbox, not your entire mailbox.
06Sub-processors
You give general written authorisation for the sub-processors we use to deliver the service. Each handles only the data needed for its function:
| Sub-processor | Purpose | Personal data processed | Location |
|---|---|---|---|
| Anthropic | AI processing — classification, summaries, reply drafting | Inquiry + email content submitted for processing | USA |
| Auth0 (by Okta) | Managed sign-in / authentication | Sign-in email | USA |
| Composio | Verified Google connection layer + OAuth custodian for ALL Google services — Gmail (read/send), Google Calendar (read events), Google Drive (per-file); holds + refreshes the Google authorisation and brokers each request on the customer's own account | Gmail messages + thread/address metadata; calendar event details; Drive file metadata | USA |
| Gmail / Calendar / Drive — the customer's OWN connected account (accessed via Composio; Viznerve holds no Google token directly) | Email, calendar, and file metadata | Global (USA) | |
| Dropbox | Project files — the customer's OWN connected account | File share links + metadata (no copies stored) | USA |
| Stripe | Payment processing + billing | Billing contact + payment metadata | USA |
| PayPal | Payment processing + billing (alternative to Stripe) | Billing contact + payment metadata | USA |
| Resend | Transactional email delivery (sign-in links, briefs, notifications) — when enabled | Recipient email address + message content | USA |
| Cloudflare | DNS, CDN, edge + DDoS protection | Request metadata (IP, headers) | Global |
| Hostinger | Application + database hosting (all live data at rest) | All application personal data | India (Mumbai) |
| Hostinger (backups) | Full-server weekly snapshots | Encrypted server snapshots | Malaysia |
| Backblaze B2 | Encrypted off-site database backups | Encrypted DB dumps (AES-256, client-side before upload) | USA (US-East) |
| Amazon Web Services (KMS) | Encryption-key management (envelope encryption of data at rest) | Key material only — no personal data | eu-north-1 (Sweden) |
Error tracking (GlitchTip) runs on our own infrastructure, not a third party. Analytics/advertising tools (PostHog, Meta, LinkedIn) operate on our marketing website only and never process your studio’s application data. This list is kept consistent with Privacy Policy §6.
Infisical (secrets management) is part of our own infrastructure and processes no customer personal data — only application secrets and configuration. [LAWYER: confirm each sub-processor’s legal entity for the SCC Annex III.]
Each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than this DPA, and we remain responsible for their performance. We’ll give you notice of changes to this list before a new sub-processor processes your data. If you have a reasonable, data-protection-related objection, tell us within 30 days of notice; we’ll work with you on a fix, and if none is workable you may terminate the affected service and receive a pro-rata refund of prepaid, unused fees.
07International transfers
Viznerve does not currently transfer EU/EEA, UK, or Swiss personal data: it does not target those markets and does not store their residents’ personal data (live application data is hosted in India — see the sub-processor table and “Where data lives” above). Accordingly, no EU Standard Contractual Clauses, UK IDTA, or Swiss transfer mechanism is engaged today.
If Viznerve expands to serve EU/EEA/UK/Swiss data subjects, it will execute the applicable EU SCCs (Module 2), the UK IDTA/Addendum, and/or the Swiss equivalent with all relevant sub-processors, and complete the required Annexes, before commencing such processing. This section will be updated at that time.
08Assistance with data-subject requests
The app gives you direct tools for most requests: you can access, correct, export, and delete your studio’s data yourself. If a data subject contacts us directly about data we process for you, we won’t respond on your behalf (except to point them to you) — we’ll forward the request promptly and, taking into account the nature of the processing, assist you with appropriate measures to fulfil it.
09Personal-data-breach notification
If we become aware of a personal-data breach affecting your data, we will notify you without undue delay, and in any event within 72 hours of becoming aware — so you can meet your own notification duties (e.g. the GDPR’s 72-hour window for controllers). The notice will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and the measures taken or proposed. We’ll cooperate with your reasonable requests and keep you updated as the investigation progresses.
10Audits & information
On written request (no more than once per year, unless required by a supervisory authority or following a breach), we’ll make available the information reasonably necessary to demonstrate compliance with this DPA — security documentation, sub-processor agreements summaries, and answers to reasonable security questionnaires. Where that isn’t sufficient, we’ll allow an audit by you or an independent auditor you mandate, on reasonable notice, during business hours, under confidentiality, and without access to other customers’ data.
11Return & deletion on termination
You can export your studio’s data at any time from the app. When your account closes, we delete your studio data within 30 days, except where we’re legally required to retain limited billing records — consistent with the retention terms in our Privacy Policy. During the life of the account, raw email bodies are retained for a limited window (default 30 days) and then automatically deleted; you can also disconnect any integration and delete its imported data at any time from Settings → Integrations. When you delete data it is removed from live systems within these windows; copies may remain in our encrypted backups for a short period (up to about 14 days) until those backups rotate out automatically.
12Liability & order of precedence
Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service, except where data-protection law doesn’t permit them to be limited. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails; where mandatory Standard Contractual Clauses apply and conflict with this DPA, the Clauses prevail.
13Governing law
This DPA is governed by the laws of India, consistent with the Terms of Service, subject to any mandatory data-protection law that applies to the processing. The courts at VizNerve LLC’s registered place of business have exclusive jurisdiction. Because live application data is hosted in India (Mumbai) and the team operates from India, India’s DPDP Act applies to the processing regardless of the Wyoming incorporation. Our Grievance Officer for DPDP data-principal requests is the Founder, reachable at [email protected]. Questions about this DPA: [email protected].