Last updated: 2026-07-10
This DPA describes how Velnezo processes personal data on behalf of business customers when we act as a processor or service provider.
For customer workspace data, the customer is typically the controller or business, and Velnezo acts as processor or service provider.
For account, billing, security, and product operations data, Velnezo may act as an independent controller where permitted by law.
Velnezo processes personal data only to provide and secure the service, comply with documented customer instructions, and meet legal obligations.
Processing may include storage, retrieval, generation, transformation, enrichment, transmission to configured processors, and deletion.
Velnezo may use subprocessors for hosting, databases, email, payments, analytics, monitoring, AI processing, and support workflows.
We require subprocessors to protect personal data using appropriate contractual and technical safeguards.
Where personal data is transferred internationally, Velnezo relies on appropriate safeguards such as contractual commitments, transfer mechanisms, and risk-based technical measures.
We assist customers with data subject requests, security reviews, incident investigation, and deletion or return of personal data where required and technically feasible.
Need a signed DPA or vendor review? [email protected]