Skip to main content

Data Processing Agreement

This Data Processing Agreement ("DPA") applies where VeryBusy, Inc. ("VeryBusy," "Provider," "we") processes personal data on behalf of a customer ("Customer," "you") in the course of providing the VeryBusy service.

This DPA has two parts:

  1. The Key Terms set out on this page, and

  2. The Common Paper Data Processing Agreement Standard Terms Version 1.1, published at commonpaper.com/standards/data-processing-agreement/1.1 ("DPA Standard Terms"), which is incorporated by reference.

If there is any inconsistency between the two parts, the Key Terms on this page control. Capitalized terms not defined on this page have the meanings given in the DPA Standard Terms or in the Agreement.

How this DPA applies to you

This DPA forms part of, and supplements, our End-User License Agreement and Terms and Conditions (together, the "Agreement"). By accepting the Agreement and using the service, you accept this DPA. No signature is required.

Customers with a separately negotiated and signed Data Processing Agreement are governed by that agreement instead of this one.

If you require a countersigned copy of this DPA for your records, contact us at support@verybusy.io.

Key Terms

Agreement

This DPA supplements the End-User License Agreement and Terms and Conditions between VeryBusy, Inc. and Customer.

Approved Subprocessors

Our current subprocessors are listed at Subprocessors, which is incorporated into this DPA by reference. We update that page when we add or replace a subprocessor.

Provider Security Contact

Security Policy

As described in VeryBusy Security, Infrastructure, and 3rd Party Vendors and in Annex II below.

Service Provider Relationship

To the extent the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq ("CCPA") applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.

Governing Member State

EEA Transfers: Netherlands

UK Transfers: England and Wales

Annex I(A): List of Parties

Data Exporter

Name: the Customer accepting this DPA

Activities relevant to transfer: See Annex I(B)

Role: Controller

Data Importer

Name: VeryBusy, Inc.

Contact person: Peter Hunner, Co-founder, notices@verybusy.io

Address: 400 South 4th Street, Ste 410, PMB 90563, Minneapolis, Minnesota 55415, USA

Activities relevant to transfer: See Annex I(B)

Role: Processor

Annex I(B): Description of Transfer and Processing Activities

Service

The Service is: VeryBusy

Categories of Data Subjects

  • Customer's end users or customers

  • Customer's employees, contractors, and external collaborators invited to review or approve content

Categories of Personal Data

  • Name

  • Contact information such as email, phone number, or address

  • User activity and analysis such as device information or IP address

  • Location information

  • Images, files, and documents uploaded by Customer's users which may incidentally contain personal data

Special Category Data

Is special category data (as defined in Article 9 of the GDPR) processed? No.

Frequency of Transfer

Continuous

Nature and Purpose of Processing

Provider will process Customer Personal Data as instructed in Section 2.3 of the DPA Standard Terms. The nature of processing includes:

  • Receiving data, including collection, accessing, retrieval, recording, and data entry

  • Holding data, including storage, organization, and structuring

  • Using data, including analysis, consultation, testing, automated decision making, and profiling

  • Updating data, including correcting, adaption, alteration, alignment, and combination

  • Protecting data, including restricting, encrypting, and security testing

  • Sharing data, including disclosure, dissemination, allowing access, or otherwise making available

  • Returning data to the data exporter or data subject

  • Erasing data, including destruction and deletion

Duration of Processing

Provider will process Customer Personal Data as long as required (i) to conduct the processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.

Annex I(C)

Competent Supervisory Authority

The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.

Annex II: Technical and Organizational Security Measures

See Security Policy.

Pseudonymization and encryption of personal data: Data encrypted in transit (TLS) and at rest (AWS KMS).

Ability to restore the availability of and access to Customer Personal Data in a timely manner following a physical or technical incident: Automated backups with documented restoration procedures.

Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures used to secure processing: Continuous vulnerability scanning (Amazon Inspector, GuardDuty) and independent SOC 2 examination as described in the Security Policy. Provider holds a SOC 2 Type 1 report and is undergoing a SOC 2 Type 2 examination.

User identification and authorization process and protection: SSO with MFA and least-privilege, role-based access for Provider personnel. For Customer's own users, the Application supports single sign-on via Customer's identity provider, with user access administered by Customer. Automated SCIM provisioning and deprovisioning (Okta, Microsoft Entra ID) is available on enterprise plans. Each user account is limited to a single active session; signing in from a new device or browser ends any existing session for that account.

Protecting Customer Personal Data during transmission (in transit): All data in transit protected with TLS.

Protecting Customer Personal Data during storage (at rest): AWS-managed encryption (KMS) on all data stores and backups.

Physical security where Customer Personal Data is processed: Hosted in AWS data centers; Provider maintains no physical infrastructure.

Events logging: Centralized logging and monitoring via AWS CloudTrail, CloudWatch, and New Relic.

Internal IT and IT security governance and management: Provider maintains written information security policies reviewed at least annually.

Certification or assurance of processes and products: SOC 2 Type 1 report (Security, Availability, Confidentiality) issued by an independent auditor. Provider is currently undergoing a SOC 2 Type 2 examination covering the same trust services criteria. Reports are available to Customer on request, subject to confidentiality obligations.

Questions

For questions about this DPA, contact support@verybusy.io. For security matters, contact security@verybusy.io.

Related

Did this answer your question?