This Data Processing Agreement ("DPA") forms part of the agreement between the customer organization ("Customer," "Controller") and VisionAtlas ("Processor") for the VisionAtlas Service. It applies when Processor processes personal data on behalf of Customer in connection with the Service.
If Customer has executed a separate DPA with VisionAtlas, that document controls in case of conflict.
1. Subject matter and duration
Processor processes personal data contained in Customer Content and account data solely to provide, secure, and support the Service for the term of the subscription and as needed thereafter for backup, billing, and legal obligations described in the Privacy Policy.
2. Nature and purpose of processing
Hosting, storage, display, collaboration, analytics, exports, notifications (email/SMS where enabled), optional AI-assisted features, and administrative operations scoped to Customer's workspace.
3. Categories of data subjects
Customer's employees, contractors, and other users Customer authorizes, and individuals whose data Customer chooses to include in workspace content.
4. Types of personal data
Names, work contact details, roles, usage logs, and any personal data Customer submits in goals, KPIs, initiatives, updates, comments, briefings, or uploads.
5. Processor obligations
Processor will:
- Process personal data only on documented instructions from Customer (including via Service configuration and these terms), unless required by law
- Ensure personnel with access are bound by confidentiality
- Implement appropriate technical and organizational measures (see security documentation)
- Assist Customer with data subject requests using in-app export and erasure tools where applicable
- Notify Customer without undue delay of personal data breaches affecting Customer Content where legally required
- Make available information necessary to demonstrate compliance and allow audits as agreed in enterprise contracts
- Use subprocessors under written terms; maintain an up-to-date subprocessor list (see in-app Privacy & data settings)
6. Customer obligations
Customer will:
- Not submit PHI or data requiring a HIPAA BAA to the Service
- Provide lawful instructions and notices to its users
- Configure roles, sharing, and integrations appropriately
- Not use public share links to disclose personal data unlawfully
7. Subprocessors
Customer authorizes Processor to engage subprocessors listed in the Service and security documentation. Processor will provide notice of material subprocessor changes as described in the Privacy Policy or enterprise agreement.
8. International transfers
Where personal data is transferred outside the EEA/UK, Processor will use appropriate safeguards (such as Standard Contractual Clauses or UK IDTA) as required by applicable law.
9. Deletion and return
Upon termination, Customer may export workspace data via admin tools. Upon confirmed workspace deletion, Processor deletes Customer Content from production systems subject to backup retention disclosed in the application. Processor may retain anonymized audit and billing records as permitted by law.
10. Contact
VisionAtlas Privacy: privacy@visionatlas.ai Legal: legal@visionatlas.ai
