Vendi Legal

Data Processing Addendum

Effective August 25, 2026

This Data Processing Addendum ("DPA") supplements the Vendi Terms of Servicebetween Vendi Inc., a company registered in Ontario, Canada ("Vendi"), and the business customer that uses Vendi ("Customer") and describes how Vendi processes personal data on Customer's behalf.

1 · Roles

For personal data that Customer submits, imports, or authorises Vendi to fetch from a connected integration (Gmail, Google Calendar, WhatsApp Business, AI Phone), Customer is the controller (or "business" under CCPA) and Vendi is the processor(or "service provider" under CCPA). For Vendi's own account and billing data, Vendi is the controller.

2 · Scope and instructions

Vendi processes Customer personal data only to provide the Vendi service, in accordance with Customer's documented instructions (including the instructions Customer expresses by using Vendi's product features) and as otherwise permitted by applicable law.

3 · Confidentiality

Vendi personnel who access Customer personal data are bound by written confidentiality obligations and access controls, and only access data as strictly necessary to operate, secure, or support the service.

4 · Security

Vendi implements administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption of provider credentials at rest, tenant isolation for stored communications, and access controls on production systems. Vendi does not currently hold a formal third-party security certification; the specific safeguards in force at any given time are described in Vendi's public Trust surface.

5 · Subprocessors

Vendi engages the third-party service providers listed on the Subprocessors page to help provide the Vendi service. Vendi imposes written data-protection obligations on each subprocessor that are consistent with this DPA. Vendi will publish material additions to the subprocessor list on that page before onboarding the new subprocessor.

6 · Data-subject requests

Vendi provides Customer with the technical means to fulfil data-subject requests through the product (export and deletion in Settings). Where Vendi receives a data-subject request directly, Vendi will refer the data subject to the applicable Customer, unless required to respond directly under applicable law.

7 · Security incidents

Vendi notifies Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer data, and provides reasonable information to allow Customer to meet its own notification obligations.

8 · Return and deletion

On termination of the Vendi service Customer may export its data as described in the Terms; after the export window Vendi deletes Customer data in accordance with the Data Deletion Instructions. Backups are removed on normal rotation.

9 · International transfers

Vendi Inc. is registered in Ontario, Canada. Customer personal data may be processed in Canada, the United States, or in any region where Vendi's subprocessors operate the underlying infrastructure. The specific transfer mechanisms that apply to each subprocessor (for example Standard Contractual Clauses) are those in force between Vendi and the subprocessor at the time of processing.

10 · Cooperation and audit

Vendi makes available to Customer information reasonably necessary to demonstrate compliance with this DPA. Any on-site audit rights are as set out in an executed enterprise agreement between Vendi and Customer.

11 · Contact

Data-protection contact: sales@vendi.so.

Sections marked "reasonable" or "appropriate" are drafted to reflect Vendi's current operational state; enterprise customers requiring specific commitments may execute a bespoke agreement.