VAVUS

Legal

Vavus Concierge Data Processing Agreement

The data processing agreement between Vavus Concierge tenants and DCI Brands LLC: roles, security, subprocessors, transfers, deletion, and audit for visitor data processed through a Concierge workspace.

Last updated: September 16, 2026 - Version 1.0

1. Parties and scope

This Data Processing Agreement ("DPA") is between DCI Brands LLC ("Vavus", "we", the processor), 312 W 2nd Street, Casper, WY 82601, United States, and the business operating a Vavus Concierge workspace (the tenant, the controller). It applies to visitor data that Vavus processes on the tenant's instruction through the Concierge service: the console, the website widget, hosted agent pages, phone and message channels, and bookings.

It is a supplement to the Vavus Concierge Terms of Service, which the tenant accepts together with this DPA. Where this DPA conflicts with the Concierge Terms on the processing of visitor data, this DPA controls. It is written to satisfy Article 28 of the GDPR and comparable processor commitments elsewhere; where local law imposes stricter processor obligations, those prevail for processing in that jurisdiction.

2. Roles and instructions

The tenant is the controller of visitor data: it decides what the assistant does, what knowledge it holds, which channels operate, and what is asked of visitors. Vavus is the processor: we act only on the tenant's instruction through the console and the service's normal operation, and process visitor data solely to provide Concierge.

We will immediately inform the tenant if, in our opinion, an instruction infringes applicable data protection law, and we will not act on a plainly unlawful instruction. If law requires processing outside the documented instructions, we will inform the tenant before that processing unless the law prohibits doing so. We do not process visitor data for our own purposes, and we do not use it to train our models or sell it.

3. Details of processing

Categories of visitor data, as the tenant's configuration collects them: identifiers the visitor provides (name, phone number, email address), conversation content (messages, transcripts, and any recordings the tenant operates), contact and booking records the assistant creates on the visitor's actions, and technical session data (timestamps, channel, language).

Data subjects are the tenant's visitors, customers, prospective customers, and staff whose information is provided to the service. Processing includes collection, transmission, organisation, storage, retrieval, translation, generation of replies, disclosure to authorised staff and connected providers, and deletion. Purpose: providing Concierge on the tenant's instructions. Duration follows the applicable retention settings and Section 9, rather than automatically lasting for the entire life of the workspace.

4. Confidentiality

Only personnel who need access to operate or secure the service have it, under confidentiality obligations, and access is logged for healthcare-configured workspaces. We do not place visitor content in analytics payloads, support chats, or public trackers.

5. Security

The service runs on our own infrastructure under the measures described on our Security page: TLS in transit, encryption at rest, least-privilege access, audit logging, secure deletion for files past their retention, and hardened endpoints behind a web application firewall. Recordings are held in access-controlled object storage; console access is authenticated and role-scoped.

6. Subprocessors

We engage subprocessors by function: cloud hosting and storage (Google Cloud), speech recognition, synthesis, translation, and AI models (including OpenAI and Google), payments (Stripe), email delivery (Resend, plus our self-hosted Postal server on our own infrastructure), and - where the tenant connects telephony or messaging - the tenant's own providers (such as Twilio or WhatsApp's provider), which the tenant engages directly under its own authority.

The tenant gives general written authorisation for the subprocessors identified in the current list supplied for its service. We impose data protection obligations equivalent to those in this DPA on each subprocessor under a written agreement and remain responsible to the tenant for its performance. Visitor content must not be used for model training without a separate lawful instruction and contractual basis. The current named list is available on request, and we give the tenant at least 30 days' notice in the console or by email before a new subprocessor handles visitor data, during which the tenant may object and terminate.

7. International transfers

The service operates in the United States and, for lower latency, an edge in the European Union (Frankfurt). Visitor data may therefore be processed in either region as the session routing requires. Before a restricted international transfer takes place, the parties must establish the applicable lawful transfer mechanism and document the destinations and safeguards. Where Standard Contractual Clauses are used, the applicable clauses, module, options and completed annexes must form part of the transfer agreement. For transfers of visitor data from the European Economic Area to us in the United States, Section 13 and its annexes are that agreement: they incorporate the Clauses, select the module and options, and complete the annexes, so an EEA tenant relies on this DPA without a separate signature. UK transfers cannot ride on the Clauses; they require the UK's own transfer instrument (the International Data Transfer Addendum), which is separate from this DPA - contact us before enabling processing that requires it.

8. Data subject requests and incidents

Visitors are the tenant's customers: requests from a visitor about their data (access, correction, deletion, objection) go to the tenant as controller, and the tenant answers them using the console's per-contact deletion. Taking account of the nature of processing, we assist through appropriate technical and organisational measures with requests under Chapter III of the GDPR. Taking account of the information available to us, we also assist with security, breach notifications, data protection impact assessments and prior consultation with supervisory authorities under Articles 32 to 36.

If we become aware of a security incident affecting visitor data in a workspace, we notify the tenant without undue delay after becoming aware of a personal data breach. We do not wait for a completed investigation or treat the controller's regulatory reporting deadline as our notification period. We provide the available details of the breach, affected data and people, likely consequences, contact point and mitigation, and provide further information in phases as it becomes available. The tenant handles any notification to its own visitors or to regulators, as controller.

9. Deletion and return

Workspace deletion removes the workspace's configuration and conversation material, including recordings from object storage, subject to encrypted backups aging out under our lifecycle policy and records the law requires us to keep (billing records for the statutory tax period). Per-contact deletion removes that contact's conversation material. At the tenant's choice on termination, we return its remaining personal data in a usable format or delete it, and delete existing copies unless applicable law requires retention. A return request must precede an irreversible deletion instruction. Retained backup copies remain protected, are not used for ordinary processing, and are deleted under the applicable documented lifecycle; if restored, deletion instructions must be reapplied.

10. Audit

We make available the information necessary to demonstrate compliance with this DPA and allow and contribute to audits, including inspections, by the tenant or an independent auditor it mandates. We normally begin with relevant documents and remote review. Reasonable notice, confidentiality and safeguards for other customers apply, but do not prevent an inspection needed to verify compliance or a lawful regulatory request. These rights are available to every tenant and are not conditional on an enterprise subscription or an annual quota.

11. Term and precedence

This DPA runs while the tenant's workspace exists and ends when the workspace is deleted, and its data protection obligations continue for as long as we or our subprocessors retain visitor personal data. The Concierge Terms' dispute, liability, and governing-law provisions apply only to the extent they do not restrict mandatory data protection rights, regulatory powers, or an applicable transfer agreement; that agreement prevails in a conflict.

12. Contact

Data protection matters, subprocessor lists, and the Standard Contractual Clauses: constantine@vavusai.com.

13. Standard Contractual Clauses (EEA transfers)

For transfers of visitor personal data from the European Economic Area to us in the United States, this DPA incorporates the standard contractual clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the "Clauses"), Module Two (controller to processor), completed by the annexes that follow. The Clauses are incorporated without amendment. They are executed through the tenant's recorded acceptance of the Concierge Terms together with this DPA: the version and timestamp the service records of that acceptance, together with our publication of this DPA at that version, constitute the parties' written agreement to the Clauses, so no separate signature is needed.

The Clauses' options are exercised as follows. The optional docking clause (Clause 7) is not used. Clause 9(a) operates under its general written authorisation option: Section 6's subprocessor regime is the agreed authorisation, and its 30 days' advance notice fills the clause's notice period. The optional independent dispute-resolution body in Clause 11(a) is not offered. The competent supervisory authority under Clause 13 and Annex I.C is the supervisory authority of the member state in which the tenant is established, or, where none applies, the Irish Data Protection Commission. Under Clause 17 the Clauses are governed by the law of the tenant's member state, or, where that law would not allow third-party beneficiary rights, the law of Ireland; under Clause 18 the courts of that member state, or in that case the courts of Ireland, have jurisdiction.

Where the Clauses and this DPA conflict, the Clauses prevail to the extent of the conflict, consistent with Section 11. Under Clause 8.3 (Module Two) the tenant makes the Clauses, including these annexes, available to a data subject who asks; we supply the text on request to make that possible.

Annex I.A - List of parties

Data exporter: the tenant, the controller of the visitor data, established in a member state of the European Economic Area; its activities relevant to the transfer are operating its business and directing the Concierge workspace through the console. Its name, address, and contact details are those recorded for the workspace in the console.

Data importer: DCI Brands LLC ("Vavus", the processor), 312 W 2nd Street, Casper, WY 82601, United States; activities relevant to the transfer: providing the Concierge service under this DPA; contact for data protection matters: constantine@vavusai.com.

Annex I.B - Description of the transfer

Categories of data subjects: the tenant's visitors, customers, prospective customers, and staff whose information is provided to the service.

Categories of personal data: identifiers the visitor provides (name, phone number, email address), conversation content (messages, transcripts, and any recordings the tenant operates), contact and booking records the assistant creates on the visitor's actions, and technical session data (timestamps, channel, language).

Sensitive data: the service does not collect special-category data as a matter of course. Where a tenant's configuration makes health information foreseeable (healthcare-configured workspaces), access is restricted to personnel who need it and logged, and the tenant remains responsible for ensuring its collection rests on the tenant's own lawful basis and instructions.

Frequency and duration: continuous, for the life of the workspace, as sessions, bookings, and console use occur; retention follows Sections 3 and 9. Nature and purpose: collection, transmission, organisation, storage, retrieval, translation, generation of replies, disclosure to authorised staff and to the sub-processors in Annex III, and deletion, to provide Concierge on the tenant's instructions. Onward transfers are limited to Clause 9, Section 6, and the list in Annex III.

Annex I.C - Competent supervisory authority

The competent supervisory authority is the supervisory authority of the member state in which the tenant (as data exporter) is established. Where the tenant is established in an EEA state that is not an EU member state, or no member-state authority otherwise applies, the Irish Data Protection Commission is the competent supervisory authority.

Annex II - Technical and organisational measures

The measures the data importer applies to safeguard the data, as described in Sections 4, 5, 8, and 9 of this DPA:

  • TLS for data in transit and encryption at rest across the service
  • Least-privilege, role-scoped access through the authenticated console; personnel bound by confidentiality obligations
  • Access logging for healthcare-configured workspaces and audit logging of administrative actions
  • Recordings held in access-controlled object storage
  • Secure deletion of files past their retention; encrypted backups under a documented lifecycle
  • Hardened endpoints behind a web application firewall with rate limiting
  • Notification of personal data breaches to the tenant without undue delay after becoming aware, with details and follow-up in phases
  • Assistance with data subject requests and with the tenant's obligations under Articles 32 to 36 of the GDPR
  • Written sub-processor contracts carrying, in substance, the same data protection obligations as this DPA

Annex III - Authorised sub-processors

The sub-processors authorised under Clause 9(a) (general written authorisation) and Section 6, by function. Changes follow Section 6's notice and objection terms.

Telephony or messaging providers the tenant connects (such as Twilio or WhatsApp's provider) are engaged by the tenant directly under its own authority and are not our sub-processors.

  • Google Cloud - cloud hosting and storage (United States primary region, EU edge in Frankfurt)
  • OpenAI - AI models
  • Google - speech recognition, speech synthesis, translation, and AI models
  • Stripe - payments
  • Resend - email delivery
  • Self-hosted Postal on our own infrastructure - email delivery

Transfer impact assessment - summary

United States law permits public authorities to compel disclosure of personal data held by service providers in defined circumstances (notably Section 702 of FISA and Executive Order 12333). Before agreeing to these Clauses we assessed the transfer against those laws and practices as Clause 14 requires, taking into account the specific circumstances of the transfer: business-support data (identifiers, conversation content, booking records, technical session data), a short processing chain (the tenant, us, and the sub-processors in Annex III), our assessment that in providing Concierge we do not act as an electronic communication service provider for this traffic, and the contractual, technical, and organisational safeguards in place. We keep that assessment under review, document it, and make it available to the competent supervisory authority on request.

Supplementary measures: the technical and organisational measures in Annex II, minimisation through tenant-configured collection, the audit rights in Section 10, and the obligations we accept under Clauses 14 and 15 - to notify the tenant of a legally binding disclosure request where the law permits, to seek a waiver of any notification prohibition and provide aggregate information at regular intervals, to review the legality of a request and challenge it where there are reasonable grounds to consider it unlawful, and to disclose the minimum information permissible. If we conclude we can no longer comply with the Clauses, we will notify the tenant promptly, and the tenant may suspend the transfer as the Clauses provide. If an adequacy decision comes to cover a transfer (for example, if we become certified under the EU-US Data Privacy Framework), the Clauses apply to that transfer only to the extent the adequacy decision does not.

Contact

DCI Brands LLC, 312 W 2nd Street, Casper, WY 82601, United States. For legal, privacy, billing, or deletion requests, email constantine@vavusai.com.