Last updated: January 9, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", "Data Controller") and DueVault.ai ("Processor", "we", "us") and governs the processing of personal data in accordance with GDPR, CCPA, and other applicable data protection laws.
Subject Matter: Security questionnaire automation and compliance management services
Duration: For the term of the service agreement
Nature and Purpose:
Types of Personal Data:
Categories of Data Subjects:
DueVault.ai shall:
Technical Measures:
Organizational Measures:
The Customer authorizes DueVault.ai to engage the following sub-processors:
Amazon Web Services (AWS)
Purpose: Cloud infrastructure and hosting
Location: United States, EU
Stripe, Inc.
Purpose: Payment processing
Location: United States
SendGrid (Twilio)
Purpose: Email delivery
Location: United States
DueVault.ai will notify the Customer of any intended changes concerning the addition or replacement of sub-processors, giving the Customer the opportunity to object to such changes within 30 days.
DueVault.ai will assist the Customer in fulfilling data subject requests, including:
Requests should be sent to: bd@dtrasglobal.com
In the event of a data breach, DueVault.ai will:
Notification will be sent to the Customer's registered email address and dashboard notification.
Personal data may be transferred to and processed in countries outside the European Economic Area (EEA). DueVault.ai ensures adequate protection through:
Retention Periods:
Deletion:
Upon termination or expiration of services, DueVault.ai will delete or return all personal data within 30 days, unless longer retention is required by law.
The Customer has the right to audit DueVault.ai's compliance with this DPA, subject to:
DueVault.ai may provide SOC 2 Type II reports in lieu of on-site audits.
Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service.
DueVault.ai will indemnify the Customer against claims arising from DueVault.ai's breach of this DPA, subject to the Customer:
This DPA remains in effect for the duration of the service agreement. Upon termination:
For DPA-related inquiries:
Enterprise customers can request a signed DPA by contacting our legal team.
Request Signed DPA →