All legal documents

Data Processing Addendum

Terms for business customers who use Privasim to process personal data on their behalf.

Last updated: August 3, 2026

1. Effective Date and Scope

This Data Processing Addendum (“DPA”) is effective as of August 3, 2026 and applies to customers who use Privacy, Visually Simplified | Privasim to process personal data on behalf of their own users (e.g., Teams plan customers acting as controllers or business users). It is incorporated into our Terms of Service and supplements our Privacy Policy.

2. Roles and Definitions

You are the Controller (or Business under CCPA) of personal data you upload to the Service. Privacy, Visually Simplified | Privasim is the Processor (or Service Provider under CCPA) that processes that data on your behalf, on your documented instructions, to provide the Service.

3. Processing Purposes

We process your personal data only to provide, maintain, and secure the Service as described in the Terms and this DPA. We do not process personal data for our own commercial purposes and will not sell or share it (under CCPA definitions).

4. Subprocessors

We engage subprocessors to deliver the Service. A current list is maintained at Subprocessors. We provide at least 30 days' notice of material changes to subprocessors via email or our website. You may object to a new subprocessor on reasonable data-protection grounds by notifying us within 30 days.

5. Security Measures

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, regular security reviews, and staff training. A summary of our security practices is available on request to contact@privasim.com.

6. Data Subject Rights Assistance

We will assist you in responding to data subject requests (access, rectification, erasure, portability, objection) where we process data on your behalf, to the extent technically and legally possible. Contact us at contact@privasim.com.

7. Data Breach Notification

In the event of a personal data breach, we will notify you without undue delay and provide the information needed for you to meet your own breach-notification obligations.

8. International Transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms approved by the European Commission.

9. Audit Rights

You may audit our compliance with this DPA, at your expense, no more than once per year and upon reasonable notice. Alternatively, we may provide a third-party audit report (e.g., SOC 2) to satisfy your assurance needs.

10. Deletion on Termination

Upon termination of the Service, we will delete your personal data within 90 days, except where retention is required by law. You may also request earlier deletion via your account settings.

11. Contact

For DPA inquiries, contact contact@privasim.com.