Skip to content
VenditaBack to home
LegalTerms of ServicePrivacy PolicyData Processing AgreementAcceptable Use Policy

Data Processing Agreement

Effective Date: 1st Jan 2026
This Data Processing Agreement is entered into between:

Vendita, a company organised and existing under the laws of NSW Government, ("Provider"); and

the subscriber identified in the applicable Terms of Service, order form, or other services agreement ("Subscriber").

This Data Processing Agreement ("DPA") forms part of and is incorporated into the applicable Terms of Service, order form, or other written agreement governing Subscriber’s use of the Platform (the "Agreement").

1. Purpose and Scope

1.1 This DPA applies to the extent Provider Processes Customer Personal Data on behalf of Subscriber in connection with the provision of the Platform and related services under the Agreement.

1.2 This DPA does not apply to personal data for which Provider acts as a Controller in its own right, including personal data relating to Subscriber account administration, billing, payment processing, subscription management, direct business relationship management, website operations, support communications, fraud prevention, or Provider’s own legal and regulatory obligations.

1.3 In the event of any conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA will prevail to the extent of that conflict.

2. Definitions

In this DPA, unless the context requires otherwise:

"Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, and any national laws implementing, supplementing, or replacing them.

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Process", "Processing", and "Supervisory Authority" have the meanings given to them under Applicable Data Protection Law.

"Customer Personal Data" means Personal Data Processed by Provider on behalf of Subscriber in connection with the provision of the Platform and related services under the Agreement.

"GDPR" means Regulation (EU) 2016/679.

"Platform" means the hosted software platform and related services provided by Provider under the Agreement.

"Restricted Transfer" means a transfer of Customer Personal Data for which Applicable Data Protection Law requires an approved transfer mechanism.

"Sub-processor" means any third party appointed by or on behalf of Provider to Process Customer Personal Data on behalf of Subscriber in connection with the Agreement.

"UK GDPR" means the GDPR as it forms part of the law of the United Kingdom.

3. Roles of the Parties

3.1 The parties acknowledge and agree that, with respect to Customer Personal Data:

(a) Subscriber acts as the Controller, or as a controller-equivalent party that determines the purposes and means of Processing; and
(b) Provider acts as the Processor, Processing Customer Personal Data on behalf of Subscriber.

3.2 Subscriber is solely responsible for determining whether its collection, use, disclosure, transfer, retention, and other Processing of Customer Personal Data is lawful under Applicable Data Protection Law.

3.3 Nothing in this DPA relieves Subscriber of its direct responsibilities as Controller under Applicable Data Protection Law.

4. Details of Processing

4.1 The subject matter, duration, nature, and purpose of the Processing, together with the categories of Data Subjects and categories of Customer Personal Data, are described in Annex 1.

4.2 Provider may Process Customer Personal Data only for the purposes of performing the Agreement, complying with documented instructions from Subscriber, complying with Applicable Data Protection Law, and protecting the security, integrity, availability, and functionality of the Platform.

5. Documented Instructions

5.1 Provider will Process Customer Personal Data only on documented instructions from Subscriber, unless otherwise required by applicable law to which Provider is subject.

5.2 Subscriber’s documented instructions include:

(a) the Agreement;
(b) this DPA;
(c) Subscriber’s use of the Platform and its enabled functionality;
(d) Subscriber’s configuration of campaigns, workflows, integrations, automations, and AI features;
(e) administrative actions taken by Subscriber or its authorised users through the Platform; and
(f) other written instructions agreed by the parties.

5.3 If Provider is required by law to Process Customer Personal Data other than on Subscriber’s instructions, Provider will inform Subscriber of that legal requirement before the relevant Processing unless prohibited from doing so by law.

5.4 If Provider reasonably believes that an instruction from Subscriber infringes Applicable Data Protection Law, Provider may notify Subscriber and suspend the relevant Processing until the issue is resolved.

6. Subscriber Responsibilities

6.1 Subscriber represents, warrants, and undertakes that it has, and will maintain, all rights, permissions, notices, consents, and lawful bases necessary for Provider to Process Customer Personal Data on Subscriber’s behalf under the Agreement and this DPA.

6.2 Subscriber is solely responsible for:

(a) the legality, accuracy, quality, and integrity of Customer Personal Data;
(b) the means by which Customer Personal Data was collected or obtained;
(c) providing all notices required to Data Subjects under Applicable Data Protection Law;
(d) establishing and documenting an appropriate lawful basis for Processing;
(e) obtaining and maintaining any consents required for direct marketing, AI-enabled Processing, profiling, voice communications, or other regulated Processing;
(f) determining whether a data protection impact assessment, lawful basis assessment, transfer assessment, or other regulatory analysis is required for its use of the Platform;
(g) responding substantively to Data Subject requests and regulatory enquiries relating to Subscriber’s Processing decisions; and
(h) ensuring that its use of the Platform complies with Applicable Data Protection Law.

6.3 Subscriber must not instruct Provider to Process Customer Personal Data in a manner that would violate Applicable Data Protection Law.

6.4 Subscriber must not provide Special Category Personal Data or other similarly sensitive regulated data to Provider unless expressly authorised by Provider in writing and supported by appropriate safeguards and lawful basis.

7. Confidentiality of Personnel

Provider will ensure that all personnel authorised to Process Customer Personal Data are bound by appropriate confidentiality obligations and are subject to appropriate access controls and training relevant to the protection of Customer Personal Data.

8. Security Measures

8.1 Provider will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the nature of the Processing, the sensitivity of the data, the risks presented, and the state of the art.

8.2 A summary of the categories of security measures maintained by Provider is set out in Annex 2.

8.3 Provider may update its security measures from time to time, provided that such updates do not materially reduce the overall level of protection for Customer Personal Data.

9. Sub-processors

9.1 Subscriber authorises Provider to appoint and use Sub-processors in connection with the provision of the Platform.

9.2 Provider will:

(a) maintain a list of current Sub-processors or otherwise make such information available to Subscriber;
(b) ensure that each Sub-processor is bound by written terms requiring protection of Customer Personal Data at a level no less protective than that required by this DPA, to the extent applicable to the services performed by that Sub-processor; and
(c) remain responsible for the acts and omissions of its Sub-processors to the extent required by Applicable Data Protection Law.

9.3 Provider’s current Sub-processors are identified in Annex 3.

9.4 Where required by Applicable Data Protection Law, Provider will provide notice of material new Sub-processors and give Subscriber a reasonable opportunity to object on legitimate data protection grounds.

10. International Transfers

10.1 Provider may Process Customer Personal Data in multiple jurisdictions and may make Restricted Transfers where necessary to provide the Platform and related services.

10.2 To the extent a Restricted Transfer occurs, Provider will ensure that the transfer is subject to an appropriate lawful transfer mechanism recognised under Applicable Data Protection Law, which may include:

(a) standard contractual clauses;
(b) the UK addendum;
(c) an adequacy decision or adequacy regulation; or
(d) another lawful transfer mechanism permitted by Applicable Data Protection Law.

10.3 Subscriber acknowledges that approved Sub-processors may Process Customer Personal Data in jurisdictions outside the country in which the data was originally collected, subject to applicable safeguards where required.

11. Assistance With Data Subject Requests

11.1 Taking into account the nature of the Processing, Provider will provide Subscriber with reasonable assistance, through appropriate technical and organisational measures where possible, to enable Subscriber to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

11.2 If Provider receives a request directly from a Data Subject relating to Customer Personal Data, Provider may, where legally permitted, direct the Data Subject to Subscriber and notify Subscriber of the request as appropriate.

12. Assistance With Compliance, DPIAs, and Consultations

Taking into account the nature of the Processing and the information available to Provider, Provider will provide reasonable assistance to Subscriber with:

(a) compliance with Subscriber’s obligations relating to security of Processing;
(b) investigation and response relating to a Personal Data Breach affecting Customer Personal Data;
(c) data protection impact assessments; and
(d) prior consultations with Supervisory Authorities,

in each case to the extent required by Applicable Data Protection Law and reasonably necessary for Subscriber’s use of the Platform.

13. Personal Data Breach Notification

13.1 If Provider becomes aware of a Personal Data Breach affecting Customer Personal Data, Provider will notify Subscriber without undue delay.

13.2 Such notification will include, to the extent reasonably available at the time:

(a) a description of the nature of the Personal Data Breach;
(b) the categories of data affected;
(c) the likely consequences of the Personal Data Breach;
(d) the measures taken or proposed to address the Personal Data Breach; and
(e) such other information as Subscriber may reasonably require to meet its obligations under Applicable Data Protection Law.

13.3 Provider may provide information in phases as it becomes available.

13.4 Provider’s notification of a Personal Data Breach is not an acknowledgement of fault or liability.

14. Audit and Information Rights

14.1 Upon reasonable written request, Provider will make available to Subscriber information reasonably necessary to demonstrate Provider’s compliance with this DPA.

14.2 Subscriber may conduct an audit of Provider’s compliance with this DPA only:

(a) on reasonable prior written notice;
(b) no more than once in any twelve-month period, unless required by law or following a reasonably evidenced Personal Data Breach;
(c) during normal business hours;
(d) in a manner that minimises disruption to Provider’s operations;
(e) subject to appropriate confidentiality, security, and access restrictions; and
(f) at Subscriber’s expense, unless the audit identifies a material breach by Provider of this DPA.

14.3 Provider may satisfy its obligations under this Section by providing third-party audit reports, certifications, security summaries, or comparable compliance materials where appropriate.

15. Return and Deletion of Customer Personal Data

15.1 Upon termination or expiry of the Agreement, Provider will, at Subscriber’s choice and subject to the functionality of the Platform, either return or delete Customer Personal Data within a reasonable period, except to the extent retention is required by law or reasonably necessary for:

(a) security and integrity of systems;
(b) backup and disaster recovery processes;
(c) fraud prevention;
(d) dispute resolution;
(e) enforcement of legal rights; or
(f) compliance with legal, tax, accounting, or regulatory obligations.

15.2 Subscriber acknowledges that residual copies of Customer Personal Data may remain in routine backup systems for a limited period before secure deletion in accordance with Provider’s backup and retention processes.

16. De-Identified, Aggregated, Statistical, and Derived Data

16.1 Nothing in this DPA restricts Provider from creating, using, retaining, or disclosing data that has been de-identified, aggregated, anonymised, statistical, analytical, operational, or otherwise derived from data Processed through the Platform, provided that such data does not reasonably identify Subscriber, any Data Subject, or specific Customer Personal Data.

16.2 Provider may use such data to:

(a) operate, secure, maintain, and improve the Platform;
(b) optimise workflows, analytics, safety, and system performance;
(c) improve the quality, accuracy, and performance of AI systems hosted by Provider;
(d) conduct internal research, testing, benchmarking, modelling, and service development; and
(e) generate service-level insights and operational analytics.

16.3 Provider will not knowingly attempt to re-identify de-identified data.

17. AI and Automated Processing Acknowledgement

17.1 Subscriber acknowledges and instructs that, where enabled by Subscriber through the Platform, Customer Personal Data may be Processed by automated systems and approved Sub-processors in order to provide AI-enabled functionality, including:

(a) message generation;
(b) reply drafting;
(c) summaries;
(d) classifications;
(e) recommendations;
(f) routing;
(g) analytics; and
(h) workflow automation.

17.2 Subscriber is solely responsible for determining whether its use of such functionality requires specific disclosures, notices, consents, impact assessments, or additional controls under Applicable Data Protection Law.

18. Allocation of Responsibility

18.1 Subscriber acknowledges that it is solely responsible for its controller obligations under Applicable Data Protection Law, including obligations relating to lawful basis, transparency, purpose limitation, retention decisions, Data Subject rights, direct marketing compliance, and jurisdiction-specific regulatory requirements.

18.2 Except to the extent expressly required by Applicable Data Protection Law for a Processor, Provider does not assume and is not responsible for Subscriber’s controller obligations under Applicable Data Protection Law.

19. Indemnity

19.1 Subscriber will defend, indemnify, and hold harmless Provider, its affiliates, officers, directors, employees, contractors, and Sub-processors from and against any claims, complaints, investigations, enforcement actions, regulatory proceedings, damages, losses, liabilities, judgments, settlements, fines, penalties, costs, and expenses, including reasonable legal fees, arising out of or relating to:

(a) Subscriber’s breach of Applicable Data Protection Law;
(b) Subscriber’s failure to provide a lawful basis, required consent, or required notice for the Processing of Customer Personal Data;
(c) Subscriber’s unlawful instructions, campaigns, communications, profiling, targeting, retention practices, or other Processing decisions;
(d) Subscriber’s failure to honour Data Subject rights, opt-out rights, suppression obligations, or similar compliance duties;
(e) Subscriber’s provision of Customer Personal Data that was collected, uploaded, transferred, retained, or otherwise Processed unlawfully; or
(f) Subscriber’s breach of this DPA.

19.2 Subscriber is not required to indemnify Provider to the extent that the relevant claim, loss, fine, or liability arises directly from:

(a) Provider’s breach of obligations specifically imposed on Provider as a Processor under Applicable Data Protection Law; or
(b) Provider acting outside or contrary to Subscriber’s lawful documented instructions.

20. Liability

To the extent permitted by Applicable Data Protection Law, the exclusions and limitations of liability set out in the Agreement apply to this DPA and all claims arising under it.

21. Order of Precedence

If there is any conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA will prevail to the extent of that conflict.

22. General

22.1 This DPA remains in effect for as long as Provider Processes Customer Personal Data on behalf of Subscriber under the Agreement.

22.2 If any provision of this DPA is held invalid or unenforceable, the remaining provisions will remain in full force and effect.

22.3 This DPA is governed by the governing law and dispute resolution provisions set out in the Agreement, unless otherwise required by Applicable Data Protection Law.


Annex 1

Details of Processing

Subject matter of Processing
Provision of the Platform and related services to Subscriber.

Duration of Processing
For the term of the Agreement and any limited post-termination period during which Provider retains Customer Personal Data in accordance with the Agreement, this DPA, and Applicable Data Protection Law.

Nature and purpose of Processing
Hosting, storing, organising, structuring, retrieving, transmitting, synchronising, securing, analysing, classifying, generating outputs, supporting, deleting, and otherwise Processing Customer Personal Data in order to provide contact management, communications, campaigns, AI-enabled workflows, analytics, integrations, support, and related service functionality.

Categories of Data Subjects
May include:

  • Subscriber’s prospects, leads, customers, clients, patients, suppliers, or other business contacts
  • employees, representatives, or agents of Subscriber’s prospects, customers, or counterparties
  • individuals whose personal data is included in CRM records, campaigns, communications, or workflows configured by Subscriber

Categories of Customer Personal Data
May include:

  • names
  • email addresses
  • phone numbers
  • company names
  • job titles
  • CRM identifiers and external reference IDs
  • campaign status and segmentation data
  • message, email, SMS, WhatsApp, and call content
  • conversation histories and communication records
  • opportunity and pipeline data
  • opt-out, suppression, and do-not-contact status
  • response activity and behavioural engagement data
  • AI-generated summaries, classifications, and metadata related to communications
  • other business contact data uploaded, synced, or entered by Subscriber

Special categories of data
Subscriber must not provide Special Category Personal Data or similarly sensitive regulated data unless expressly authorised by Provider in writing and supported by appropriate safeguards and lawful basis.


Annex 2

Summary of Security Measures

Provider maintains technical and organisational measures designed to protect Customer Personal Data, which may include, as appropriate:

  • role-based access controls and authentication measures
  • logical segregation of customer environments and access permissions
  • encryption and secret-management practices where appropriate
  • logging, monitoring, and integrity controls
  • incident detection, response, and recovery procedures
  • backup and disaster recovery measures
  • confidentiality obligations for authorised personnel
  • Sub-processor due diligence and contractual controls
  • measures designed to limit access to Customer Personal Data to authorised personnel and approved Sub-processors

Provider may update these measures from time to time, provided that the overall level of protection is not materially reduced.


Annex 3

Approved Sub-processors

Provider may use Sub-processors in categories such as the following:

Sub-processorService CategoryPurpose
OpenAIAI providerAI-generated messages, summaries, classifications, and related model-supported functionality
TwilioMessaging and communications providerSMS, WhatsApp, email, telephony, and related communications infrastructure
SupabaseCloud database and infrastructure providerData storage, authentication, and platform infrastructure
ElevenLabsVoice and telephony providerAI-enabled voice functionality and call handling
CRM IntegrationsStoring or transferring customer dataTo allow messaging to customer segments through the platform.

Provider may update this Annex from time to time in accordance with Section 9 of this DPA.


This DPA should now be internally aligned with the Terms and Privacy Policy. The next document in sequence should be the Acceptable Use Policy.

© 2026 Vendita
Terms of ServicePrivacy PolicyData Processing AgreementAcceptable Use Policy