VVenture VD
Attribution RelayPrivacyTerms

Effective August 25, 2026

Data Processing Addendum

This Addendum forms part of the Attribution Relay Terms between the customer as Controller and Venture VD LLC as Processor.

Roles and scope

The customer controls personal data submitted through connected forms. Venture VD processes it solely on the customer's behalf to ingest, capture attribution, evaluate bots, map fields, deliver, replay, display and export ledger records, support the service, secure it, and delete data. Data subjects are leads and form respondents. Data may include contact details, form answers, IP address, referrer, page and UTM context, and HubSpot cookie evidence. Special-category data is prohibited without prior agreement.

Processor obligations

Venture VD processes only documented instructions, binds authorized personnel to confidentiality, maintains the measures below, controls subprocessors, assists with rights requests and impact assessments, and notifies the Controller without undue delay and within 72 hours after confirming a breach. The Controller warrants a lawful basis, adequate notices, and lawful instructions.

Subprocessors and deletion

Subprocessors are listed in the Privacy Notice. Material changes receive advance notice and a 30-day objection period. Venture VD remains responsible for their obligations. Raw payloads are deleted after 90 days; ledger metadata remains while active; account data is deleted 30 days after uninstall.

Territory

The service is offered only to Controllers established in the United States or Canada and processes data in Fly.io's Chicago region. The parties do not adopt EU SCCs, the UK Addendum, or an Article 27 representative. Controllers are responsible for laws arising from an individual respondent's location. Canadian Controllers acknowledge US processing and lawful-access exposure under PIPEDA accountability.

Audit, liability, and acceptance

Venture VD will answer one written security questionnaire per twelve months within 30 days. Legally required on-site audits are scoped in advance, normally limited to once yearly, and paid by the Controller. Liability follows the Terms except where law forbids that limitation. This Addendum is accepted electronically with the Terms; a countersigned copy is available from support@venturevd.com.

Schedule A: security measures

  • Separated runtime, purge, and schema-owner database roles.
  • AES-256-GCM credential encryption and certificate-verified TLS.
  • Append-only delivery and audit records enforced by database permissions.
  • Signature verification over exact raw webhook bodies.
  • Account-scoped queries and tested tenant isolation.
  • Structured, redacted logs that exclude payload bodies.
  • Managed PostgreSQL backups, point-in-time recovery, and a completed restore drill.
  • Backward-compatible migrations and release-blocking verification.

© 2026 Venture VD LLC

PrivacyTermsSupport