Data Processing Agreement

Version 2.0 · 14 August 2026 · Supersedes version 1.0 (2 January 2026)

This page publishes the Data Processing Addendum that forms Exhibit D to the ValueNova Master Services Agreement, and the hosting commitment from Exhibit C (Data Security Measures). Where a customer has executed an MSA, the version incorporated into that agreement governs.

Where your data is hosted

All Customer Data is hosted within the European Union. Compute and object storage are provided on Google Cloud Platform in the europe-west1 region (Belgium) by Google Ireland Limited; the primary database is provided by Supabase in Stockholm, Sweden. This applies to all Customers regardless of the Customer's location — ValueNova does not operate per-country or United States hosting of Customer Data. Processing outside the European Union is limited to (a) AI inference (including speech-to-text transcription of voice input) and transactional email performed by the sub-processors listed at valuenova.ai/subprocessors, and (b) support access by ValueNova personnel, in each case subject to the transfer mechanisms set out in the Data Processing Addendum. ValueNova shall give Customer not less than thirty (30) days' written notice before any material change to this hosting arrangement.

This Data Processing Addendum ("DPA") supplements the Agreement and applies to the extent that ValueNova processes personal data on behalf of Customer in connection with the Service.

1. Definitions

For purposes of this DPA, "personal data," "processing," "controller," "processor," and "data subject" have the meanings given to them in applicable Data Protection Laws (including the UK GDPR, EU GDPR, CCPA, and their successors). "Data Protection Laws" means all applicable laws relating to data protection and privacy, including the EU General Data Protection Regulation 2016/679, the UK GDPR (as defined in the Data Protection Act 2018), the California Consumer Privacy Act (as amended by the CPRA), and any other applicable data protection legislation.

2. Roles and scope

The Parties acknowledge that with respect to personal data contained in Customer Data: (a) Customer is the controller (or "business" under CCPA); (b) ValueNova is the processor (or "service provider" under CCPA); and (c) ValueNova will process personal data only on behalf of and in accordance with Customer's documented instructions, except where required by applicable law. Should this determination change, the Parties shall use all reasonable endeavours make any changes that are necessary to this Exhibit.

Both Parties will comply with all applicable requirements of the applicable Data Protection Laws. This Exhibit is in addition to, and does not relieve, remove or replace, a party's obligations or rights under the Data Protection Laws.

Without prejudice to the above, the Customer will ensure that it has all necessary appropriate consents and notices in place to enable lawful transfer of Personal Data to ValueNova and/or lawful collection of the same by ValueNova for the duration and purposes of this agreement.

CCPA Service Provider Terms. To the extent the California Consumer Privacy Act (as amended by the California Privacy Rights Act) applies to personal information processed under this DPA, ValueNova shall not: (a) sell or share the personal information (as those terms are defined in the CCPA); (b) retain, use, or disclose the personal information for any purpose other than performing the Services or as otherwise permitted by the CCPA; (c) retain, use, or disclose the personal information outside the direct business relationship between the Parties; or (d) combine the personal information with personal information received from or on behalf of any other person, except as permitted by the CCPA. ValueNova certifies that it understands these restrictions and will comply with them, and shall notify Customer if it determines that it can no longer meet its obligations under the CCPA.

Either Party may, where required by a change in applicable Data Protection Laws and on not less than 30 days' notice, revise this Exhibit by replacing it with any applicable controller to processor standard clauses or similar terms forming part of an applicable certification scheme (which shall apply when replaced by attachment to this agreement).

3. Processing instructions

The following sets out the nature and categories of personal data processed by ValueNova as data processor on behalf of Customer as data controller under this Agreement:

Types of Personal Data: (a) in respect of Authorised Users — names, business email addresses, job titles, company names, IP addresses, and usage and log data; and (b) in respect of the Customer's own clients and prospects — names, business contact details (including email addresses and telephone numbers), job titles, company names, and any other business information that the Customer inputs into or uploads to the Service.

Categories of Data Subjects: (a) Authorised Users — employees, consultants, contractors, and agents of Customer who are granted access to the Service; and (b) the Customer's own clients and prospects whose personal data the Customer inputs into the Service.

Duration of Processing: For the duration of the Subscription Term and thereafter as required by applicable law or as set out in Section 12.3 and Exhibit D Section 9 of this Agreement.

ValueNova shall process personal data solely for the purpose of providing the Service and performing its obligations under the Agreement, unless otherwise instructed in writing by Customer or required by applicable law.

4. Sub-processors

Customer authorises ValueNova to engage sub-processors to assist in providing the Service, subject to the following:

  • (a) ValueNova shall maintain a current list of sub-processors at a publicly accessible URL (currently valuenova.ai/subprocessors);
  • (b) ValueNova shall notify Customer at least thirty (30) days in advance of any new sub-processor engagement;
  • (c) if Customer reasonably objects to a new sub-processor within thirty (30) days of notification and the Parties cannot resolve the objection, Customer may terminate the affected Order Form on written notice with a pro-rata refund of unused prepaid Fees; and
  • (d) ValueNova shall ensure each sub-processor is bound by data protection obligations no less protective than those in this DPA.

5. Data subject rights

ValueNova shall, taking into account the nature of the processing, provide reasonable assistance to Customer in responding to requests from data subjects exercising their rights under Data Protection Laws.

6. Security

ValueNova shall implement and maintain appropriate technical and organisational measures to protect personal data as described in Exhibit C (Data Security Measures).

7. Data breach notification

In the event of a personal data breach (as defined in applicable Data Protection Laws), ValueNova shall notify Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of such breach. This forty-eight (48) hour period applies in place of the seventy-two (72) hour period in Section 7.5 of the Agreement, which continues to apply to Security Incidents not involving personal data; such notification shall contain the information listed in Section 7.5(a) to (d). ValueNova shall provide such information as Customer may reasonably require to comply with Customer's own notification obligations to supervisory authorities and data subjects under Data Protection Laws.

8. International transfers

If personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction not deemed adequate under applicable Data Protection Laws, the Parties hereby enter into the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller-to-processor), which are incorporated by reference into this DPA and completed as set out in Annex 1 to this DPA; and, for transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs (as issued by the Information Commissioner's Office), which is incorporated by reference and completed as set out in Annex 2 to this DPA. [Annexes 1 and 2 — parties, description of processing, technical and organisational measures (Exhibit C), and sub-processor list — to be populated before first use.]

ValueNova shall provide Customer with a Transfer Impact Assessment on request.

9. Data return and deletion

Upon termination of the Agreement, ValueNova shall, at Customer's election, return or delete all personal data in its possession or control in accordance with Section 12.3 of the Agreement, under which Customer may request a copy of Customer Data within thirty (30) days after termination or expiration and ValueNova shall delete or render irrecoverable all remaining personal data from its production systems and backups within sixty (60) days of expiry of that request period, unless retention is required by applicable law. Upon Customer's written request, ValueNova shall provide written certification of such deletion within ten (10) Business Days of completion.

10. Audit rights

ValueNova shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA. Customer may exercise its audit rights by: (a) requesting a completed industry-standard security questionnaire (such as SIG Lite or CAIQ) and/or a written summary of ValueNova's Security Programme, which ValueNova shall provide on written request; (b) where ValueNova has obtained SOC 2 Type II certification, reviewing ValueNova's most recent audit report and any supplementary certifications, subject to ValueNova's standard confidentiality requirements; or (c) conducting or commissioning an audit upon reasonable notice, no more than once per year (unless required by a supervisory authority or following a personal data breach). Any on-site audit shall be at Customer's expense. For the avoidance of doubt, and consistent with Section 7.7 of the Agreement and Exhibit C, ValueNova has not yet obtained SOC 2 Type II certification; route (a) is available to Customer now and route (b) becomes available upon certification.

11. Liability cap

Each Party's aggregate liability to the other under or in connection with this DPA (including for breach of UK GDPR, EU GDPR, or other Data Protection Laws) shall be subject to the aggregate liability cap set out in Section 11.2 of the Agreement or, where the claim falls within Section 11.3, the cap set out in Section 11.3, except to the extent that applicable Data Protection Laws impose a mandatory minimum liability that cannot be contractually limited. Nothing in this DPA shall exclude either Party's liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation.

12. Duration and termination

This DPA shall remain in effect for as long as ValueNova processes personal data on behalf of Customer. In the event of any conflict between this DPA and the Agreement with respect to data protection matters, this DPA shall prevail.