Data Processing Addendum
Last updated: June 25, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Tnorx Solutions Ltd. (“ventrolic”, “Processor”) and the customer (“Customer”, “Controller”) for use of the ventrolic service (the “Service”). It governs ventrolic’s processing of Personal Data on Customer’s behalf and reflects the requirements of the EU GDPR, UK GDPR, and similar laws.
1. Definitions
“Personal Data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in applicable Data Protection Law. “Customer Personal Data” means Personal Data within the data Customer connects to or submits to the Service.
2. Roles and scope
Customer is the controller and ventrolic is the processor of Customer Personal Data. ventrolic processes Customer Personal Data only to provide the Service and on Customer’s documented instructions, including as set out in Annex I.
3. Customer instructions
Customer’s instructions are this DPA, the agreement, and use of the Service’s features. ventrolic will inform Customer if, in its opinion, an instruction infringes Data Protection Law (without obligation to provide legal advice).
4. Confidentiality
ventrolic ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and process it only as instructed.
5. Security measures
ventrolic implements appropriate technical and organizational measures as described in Annex II, including encryption in transit and at rest, encrypted connector credentials, role-based access control, tenant isolation, least-privilege access, and private database networking.
6. Sub-processing
Customer authorizes ventrolic to engage the sub-processors listed in Annex III. ventrolic imposes data protection obligations on each sub-processor no less protective than this DPA and remains liable for their performance. ventrolic will give Customer reasonable prior notice of any new or replacement sub-processor and an opportunity to object on reasonable grounds.
7. Data subject requests
Taking into account the nature of the processing, ventrolic will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to data subject requests. If ventrolic receives such a request directly, it will refer the data subject to Customer.
8. Personal data breach
ventrolic will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to help Customer meet its notification obligations.
9. Data protection impact assessments
ventrolic will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of processing and information available to ventrolic.
10. Return and deletion
Upon termination of the Service, ventrolic will, at Customer’s choice, delete or return Customer Personal Data and delete existing copies, except where retention is required by law.
11. Audits
ventrolic will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality and scheduling controls.
12. International transfers
Where ventrolic processes Customer Personal Data originating in the EEA, UK, or Switzerland in a country without an adequacy decision, the parties agree the EU Standard Contractual Clauses (and the UK Addendum, as applicable) are incorporated by reference, with the relevant modules and annexes completed by reference to Annex I and II.
Annex I — Details of processing
- Subject matter & duration: provision of the Service for the term of the agreement.
- Nature & purpose: ingesting and normalizing AI cost/usage, cloud audit, and identity metadata to provide cost governance and shadow-AI discovery.
- Types of Personal Data: business contact identifiers (names, work emails), user/account identifiers, API key owners, and identity/OAuth grant metadata. The Service is not intended to process special-category data or the content of AI prompts/responses.
- Categories of data subjects: Customer’s personnel and authorized users.
Annex II — Technical & organizational measures
- Encryption in transit (TLS) and at rest.
- Connector credentials encrypted with AES-256-GCM; secrets in AWS Secrets Manager with KMS.
- Role-based access control and tenant data isolation.
- Least-privilege IAM and private database networking (no public exposure).
- Read-only, metadata-level access — no inline interception of AI traffic.
- Logging and access controls for administrative operations.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (compute, RDS, Secrets Manager, KMS) | Hosting, database, encrypted secrets | US (us-west-2) |
| Amazon SES | Transactional & notification email | US (us-west-2) |
| Resend | Transactional email delivery | US |
To request a signed copy of this DPA, contact privacy@ventrolic.com.