Data Processing Addendum

Effective date: September 19, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the business using Vaam (“Customer”, the controller) and [Company Legal Name] (“Vaam”, the processor). It applies to personal data of the Customer's own customers that Vaam processes to provide the Service. It is accepted when the Customer accepts the Terms; Compliance-plan customers may request a countersigned copy from support@vaam.app.

1. Subject matter, nature and purpose

Vaam processes Customer Personal Data to answer the Customer's customers on the channels the Customer connects, book and manage appointments, capture enquiries and cases, send confirmations and reminders, and show the Customer transcripts and reports — only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's configuration of the Service.

2. Categories of data and data subjects

  • Data subjects: the Customer's customers and prospective customers, and the Customer's staff users.
  • Personal data: names, email addresses, phone numbers, messaging identifiers, message content, appointment details, order numbers and anything else a customer chooses to write.
  • Special categories: the Service is not designed for special-category or medical records. The Customer must not instruct Vaam to collect them and must configure its assistant accordingly.

3. Duration and retention

Processing lasts for the term of the Customer's subscription. Conversation transcripts that are inactive longer than the retention period the Customer sets (30–3,650 days, default 90) are deleted automatically. On workspace closure all Customer Personal Data is deleted after seven days, except where law requires otherwise. The Customer can export its data at any time from Account settings.

4. Processor obligations

  • Process personal data only on the Customer's documented instructions, and inform the Customer if an instruction appears to infringe data-protection law.
  • Ensure people authorised to process the data are bound by confidentiality. Vaam staff can read a Customer's conversations only with a stated reason, and every access is written to a tamper-evident audit log.
  • Implement appropriate technical and organisational measures (section 6).
  • Assist the Customer, taking into account the nature of processing, in responding to data-subject requests and with security, breach notification, impact assessments and prior consultation.
  • Notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
  • Make available the information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, by the Customer or its mandated auditor on reasonable notice, at most once a year unless a breach has occurred.

5. Sub-processors

The Customer authorises Vaam to use the sub-processors listed in the Privacy Policy(hosting, database, AI inference, email, payments, and the messaging and voice providers for channels the Customer enables). Vaam imposes data-protection terms on each that are no less protective than this DPA, remains responsible for them, and gives notice of new sub-processors so the Customer can object on reasonable grounds. Providers the Customer connects with its own account (for example its own Twilio, Meta app, HubSpot or Shopify) are engaged by the Customer, not by Vaam.

6. Security measures

  • Encryption in transit (TLS) and at rest; credentials such as channel tokens and API keys are additionally encrypted with AES-256-GCM.
  • Strict tenant isolation: every query is scoped to the Customer's workspace on the server.
  • Role-based access for Customer staff; mandatory two-factor authentication, IP restriction and a hash-chained audit log for Vaam operators.
  • Signed and verified webhooks from messaging, voice and payment providers.
  • Rate limiting and spend caps on public endpoints; monitored job queues with retries.
  • Backups operated by the database provider; documented incident and key-rotation procedures.

7. International transfers

Where Customer Personal Data is transferred outside the UK or EEA, Vaam relies on an adequacy decision or on the Standard Contractual Clauses (and the UK Addendum), incorporated by reference, together with supplementary measures where appropriate.

8. Deletion and return

At the end of the Service the Customer may export its data; Vaam then deletes Customer Personal Data as described in section 3, and confirms deletion on request.

9. Contact

Questions about this DPA: support@vaam.app.