Roles and scope
The customer controls the table data it connects. Venture VD processes it solely on the customer's behalf to fetch the chosen source — a public sheet, a private sheet via read-only Google OAuth, a CSV upload, or manually entered rows — cache it as a last-known-good snapshot, render it on the customer's Wix site, log sync outcomes, support the service, secure it, and delete data. Data subjects are whoever the customer's connected table content concerns. Data may include the connected sheet or CSV content, table configuration, and Google OAuth tokens for private sheets. Special-category data is prohibited without prior agreement.
Processor obligations
Venture VD processes only documented instructions, binds authorized personnel to confidentiality, maintains the measures below, controls subprocessors, assists with rights requests and impact assessments, and notifies the Controller without undue delay and within 72 hours after confirming a breach. The Controller warrants a lawful basis, adequate notices, and lawful instructions for any personal data placed in a connected source.
Subprocessors and deletion
Subprocessors are listed in the Privacy Notice. Material changes receive advance notice and a 30-day objection period. Venture VD remains responsible for their obligations. Snapshots are retained while a table exists and are replaced only by a successful re-sync; account data is deleted 30 days after uninstall.
Territory
The service is offered only to Controllers established in the United States or Canada and processes data in Fly.io's Chicago region. The parties do not adopt EU SCCs, the UK Addendum, or an Article 27 representative. Canadian Controllers acknowledge US processing and lawful-access exposure under PIPEDA accountability.
Audit, liability, and acceptance
Venture VD will answer one written security questionnaire per twelve months within 30 days. Legally required on-site audits are scoped in advance, normally limited to once yearly, and paid by the Controller. Liability follows the Terms except where law forbids that limitation. This Addendum is accepted electronically with the Terms; a countersigned copy is available from support@venturevd.com.
Schedule A: security measures
- AES-256-GCM encryption of Google credentials at rest.
- Certificate-verified TLS on all database connections.
- Separated runtime and purge database roles; the runtime role cannot delete account data.
- Append-only sync history enforced by database permissions.
- Signature-verified Wix requests.
- Structured, redacted logs that exclude sheet identifiers and secrets.
- Managed PostgreSQL backups and point-in-time recovery.