Legal
Data Processing Addendum
dotracompliance.com
Last Updated: July 15, 2026
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Terms of Service between VisionaryV LLC ("Dotra") and the Customer. This DPA applies to the extent Dotra processes Personal Data on behalf of the Customer in connection with the Services.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Dotra on behalf of Customer.
- "Processing" means any operation performed on Personal Data.
- "Data Subject" means the individual to whom Personal Data relates.
- "Applicable Data Protection Law" means any applicable law relating to the processing of Personal Data, including U.S. state privacy laws.
- "Customer Data" has the meaning given in the Terms of Service.
2. Roles of the Parties
Customer is the controller of Personal Data contained in Customer Data. Dotra is the processor of such Personal Data, processing it only on Customer's behalf and in accordance with Customer's instructions.
3. Dotra's Obligations
Dotra will:
- Process Personal Data only on documented instructions from Customer.
- Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures (encryption in transit and at rest, access controls, regular security assessments).
- Assist Customer in responding to Data Subject rights requests to the extent technically feasible.
- Notify Customer without undue delay upon becoming aware of a Personal Data breach affecting Customer Data.
- Delete or return Customer Data upon termination as set forth in the Terms of Service.
- Make available information necessary to demonstrate compliance with this DPA.
4. Customer's Obligations
Customer will:
- Ensure a lawful basis for processing Personal Data under Applicable Data Protection Law.
- Provide all necessary notices to and obtain all necessary consents from Data Subjects.
- Ensure Personal Data is accurate, complete, and up to date.
- Be responsible for the security of Personal Data in transit to the Services.
5. Sub-Processors
Customer authorizes Dotra to engage the following sub-processors:
- Supabase Inc. (database hosting) — United States
- Vercel Inc. (application hosting and analytics) — United States
- SendGrid / Twilio Inc. (email and SMS communications) — United States
- Anthropic PBC (AI document scanning and compliance assistant) — United States
- Stripe Inc. (payment processing) — United States
Dotra will notify Customer of any changes to sub-processors by updating this DPA and posting notice on the Site. Customer may object to new sub-processors within 30 days of notice.
6. Data Transfers
All sub-processors listed in Section 5 are located in the United States. Customer acknowledges that Personal Data may be transferred to and processed in the United States.
7. Security
Dotra implements and maintains commercially reasonable technical and organizational measures to protect Personal Data, including encryption of data in transit (TLS) and at rest, role-based access controls, multi-factor authentication, regular security assessments, and incident response procedures.
8. Data Subject Rights
Dotra will assist Customer in fulfilling Data Subject rights requests (access, correction, deletion, portability) to the extent technically feasible and within Dotra's control. Customer is responsible for responding to Data Subject requests.
9. Term and Termination
This DPA remains in effect for the duration of the Terms of Service. Upon termination, Dotra will delete or return Customer Data as set forth in the Terms of Service and Privacy Policy.
10. Contact
For questions about this DPA:
This DPA is a draft and has been provided for informational purposes. Customers requiring a countersigned DPA for compliance purposes should contact support@visionaryv.net.