U.S. edition · Draft v0.1
When Veilleur.studio operates a first-response workflow for a customer, the customer is the controller/business and Veilleur.studio is the processor/service provider for the lead data processed in that workflow. This DPA supplements the customer agreement.
Veilleur.studio processes customer data only to provide the configured service and on the customer’s documented instructions, unless a legal requirement provides otherwise.
Personnel with access are bound by confidentiality. Security controls are described on the Security page and configured per deployment.
The customer authorizes the subprocessors listed on the current Subprocessor list. We remain responsible for their processing and will give notice of material changes as provided in the agreement.
We assist the customer, taking into account the nature of processing, in responding to verified access, correction and deletion requests to the extent the customer cannot fulfill them itself.
On termination or on instruction, we delete or return customer data per the agreed retention configuration, subject to legal retention requirements.
We notify the customer of a confirmed security incident affecting customer data without undue delay and cooperate on required communications.