This Data Processing Agreement ("DPA") applies where VeryBusy, Inc. ("VeryBusy," "Provider," "we") processes personal data on behalf of a customer ("Customer," "you") in the course of providing the VeryBusy service.
This DPA has two parts:
The Key Terms set out on this page, and
The Common Paper Data Processing Agreement Standard Terms Version 1.1, published at commonpaper.com/standards/data-processing-agreement/1.1 ("DPA Standard Terms"), which is incorporated by reference.
If there is any inconsistency between the two parts, the Key Terms on this page control. Capitalized terms not defined on this page have the meanings given in the DPA Standard Terms or in the Agreement.
How this DPA applies to you
This DPA forms part of, and supplements, our End-User License Agreement and Terms and Conditions (together, the "Agreement"). By accepting the Agreement and using the service, you accept this DPA. No signature is required.
Customers with a separately negotiated and signed Data Processing Agreement are governed by that agreement instead of this one.
If you require a countersigned copy of this DPA for your records, contact us at support@verybusy.io.
Key Terms
Agreement
This DPA supplements the End-User License Agreement and Terms and Conditions between VeryBusy, Inc. and Customer.
Approved Subprocessors
Our current subprocessors are listed at Subprocessors, which is incorporated into this DPA by reference. We update that page when we add or replace a subprocessor.
Provider Security Contact
Security Policy
As described in VeryBusy Security, Infrastructure, and 3rd Party Vendors and in Annex II below.
Service Provider Relationship
To the extent the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq ("CCPA") applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.
Governing Member State
EEA Transfers: Netherlands
UK Transfers: England and Wales
Annex I(A): List of Parties
Data Exporter
Name: the Customer accepting this DPA
Activities relevant to transfer: See Annex I(B)
Role: Controller
Data Importer
Name: VeryBusy, Inc.
Contact person: Peter Hunner, Co-founder, notices@verybusy.io
Address: 400 South 4th Street, Ste 410, PMB 90563, Minneapolis, Minnesota 55415, USA
Activities relevant to transfer: See Annex I(B)
Role: Processor
Annex I(B): Description of Transfer and Processing Activities
Service
The Service is: VeryBusy
Categories of Data Subjects
Customer's end users or customers
Customer's employees, contractors, and external collaborators invited to review or approve content
Categories of Personal Data
Name
Contact information such as email, phone number, or address
User activity and analysis such as device information or IP address
Location information
Images, files, and documents uploaded by Customer's users which may incidentally contain personal data
Special Category Data
Is special category data (as defined in Article 9 of the GDPR) processed? No.
Frequency of Transfer
Continuous
Nature and Purpose of Processing
Provider will process Customer Personal Data as instructed in Section 2.3 of the DPA Standard Terms. The nature of processing includes:
Receiving data, including collection, accessing, retrieval, recording, and data entry
Holding data, including storage, organization, and structuring
Using data, including analysis, consultation, testing, automated decision making, and profiling
Updating data, including correcting, adaption, alteration, alignment, and combination
Protecting data, including restricting, encrypting, and security testing
Sharing data, including disclosure, dissemination, allowing access, or otherwise making available
Returning data to the data exporter or data subject
Erasing data, including destruction and deletion
Duration of Processing
Provider will process Customer Personal Data as long as required (i) to conduct the processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.
Annex I(C)
Competent Supervisory Authority
The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.
Annex II: Technical and Organizational Security Measures
See Security Policy.
Pseudonymization and encryption of personal data: Data encrypted in transit (TLS) and at rest (AWS KMS).
Ability to restore the availability of and access to Customer Personal Data in a timely manner following a physical or technical incident: Automated backups with documented restoration procedures.
Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures used to secure processing: Continuous vulnerability scanning (Amazon Inspector, GuardDuty) and independent SOC 2 examination as described in the Security Policy. Provider holds a SOC 2 Type 1 report and is undergoing a SOC 2 Type 2 examination.
User identification and authorization process and protection: SSO with MFA and least-privilege, role-based access for Provider personnel. For Customer's own users, the Application supports single sign-on via Customer's identity provider, with user access administered by Customer. Automated SCIM provisioning and deprovisioning (Okta, Microsoft Entra ID) is available on enterprise plans. Each user account is limited to a single active session; signing in from a new device or browser ends any existing session for that account.
Protecting Customer Personal Data during transmission (in transit): All data in transit protected with TLS.
Protecting Customer Personal Data during storage (at rest): AWS-managed encryption (KMS) on all data stores and backups.
Physical security where Customer Personal Data is processed: Hosted in AWS data centers; Provider maintains no physical infrastructure.
Events logging: Centralized logging and monitoring via AWS CloudTrail, CloudWatch, and New Relic.
Internal IT and IT security governance and management: Provider maintains written information security policies reviewed at least annually.
Certification or assurance of processes and products: SOC 2 Type 1 report (Security, Availability, Confidentiality) issued by an independent auditor. Provider is currently undergoing a SOC 2 Type 2 examination covering the same trust services criteria. Reports are available to Customer on request, subject to confidentiality obligations.
Questions
For questions about this DPA, contact support@verybusy.io. For security matters, contact security@verybusy.io.
