Data Processing Agreement
Contractual terms governing how Velintis processes personal data when delivering evidence-based synergy intelligence services for a client engagement.
1. Parties and definitions
This Data Processing Agreement (“DPA”) is entered into between:
- Controller: The client engaging Velintis and determining the purposes and means of processing personal data, to the extent applicable (“Client”).
- Processor: Velintis, when processing personal data on behalf of the Client to deliver the agreed Enterprise M&A intelligence services.
- Engagement terms: The applicable engagement letter, statement of work, order form, or other written agreement governing the services.
- Client documents: Transaction and operating materials provided by or on behalf of the Client for the engagement.
This DPA governs Velintis’s processing of personal data on behalf of the Client. Confidential business information is also handled in accordance with the confidentiality provisions in the applicable engagement terms.
2. Scope of processing
The nature and extent of processing depend on the materials supplied and the scope of the engagement. Personal data processed may include:
- +Business contact and account information
- +Personal data contained in transaction, financial, organisational, contractual, or operating documents
- +Document and engagement metadata, including file names, timestamps, review activity, and processing status
- +Security and access information required to operate and protect the service
- +Findings, supporting evidence, and engagement communications that contain personal data
The categories of data subjects may include Client personnel, target-company personnel, customers, suppliers, advisors, and other individuals referenced in Client documents.
3. Purpose of processing
Velintis processes personal data on documented instructions from the Client and for the purpose of delivering the services described in the engagement terms. This may include reviewing source materials, identifying and validating value creation opportunities, supporting quantification, maintaining traceability to evidence, and preparing reviewed outputs.
AI may support selected parts of document review and analysis. Human expertise and review remain important to the validation of findings and outputs. Velintis will not process Client personal data for unrelated purposes unless instructed by the Client or required by applicable law.
4. Processor obligations
Velintis will:
- +Process personal data in accordance with documented Client instructions and the engagement terms
- +Ensure that authorised personnel are subject to appropriate confidentiality obligations
- +Maintain technical and organisational measures appropriate to the nature of the processing
- +Use subprocessors in accordance with this DPA and applicable engagement terms
- +Provide reasonable assistance with data-subject requests and applicable compliance obligations
- +Provide information reasonably required to demonstrate compliance with this DPA
- +Notify the Client if an instruction appears to conflict with applicable data-protection law
5. Security measures
Velintis maintains technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures include:
- Encryption: Encryption in transit, including TLS-protected transfers, and encryption at rest for stored Client information.
- Access controls: Role-appropriate access controls intended to limit access to authorised personnel and approved service providers.
- Engagement separation: Logical controls designed to separate documents and engagement information between clients.
- Confidentiality: Appropriate confidentiality obligations for personnel and service providers handling Client information.
- Activity records: Logging and monitoring appropriate to the operation, security, and review of the service.
- Responsible AI usage: AI may support analysis within the agreed engagement workflow. Findings remain subject to evidence, traceability, and human review.
6. Subprocessors
The Client provides general authorisation for Velintis to use the subprocessors listed below for the stated purposes. Velintis will manage subprocessor access according to the services they provide and the applicable contractual terms.
Velintis will address material changes to the subprocessor list in accordance with the applicable engagement terms and data-protection requirements.
7. Data retention and deletion
Client documents are used solely for the engagement and are deleted after engagement completion unless otherwise agreed.
Engagement records and outputs are managed in accordance with applicable engagement terms. At the Client’s direction, personal data will be returned or deleted as specified in those terms, subject to applicable legal obligations.
Where applicable law requires limited information to be retained, that information will remain protected and will be used only for the legally required purpose.
8. Personal data breach notification
If Velintis becomes aware of a personal data breach affecting personal data processed on behalf of the Client, Velintis will notify the Client without undue delay and in accordance with the applicable engagement terms.
Notifications will include information reasonably available to Velintis about the nature of the incident, the information affected, likely consequences, and mitigation measures. Velintis will provide reasonable cooperation to support the Client’s response obligations.
9. Governing terms
This DPA forms part of the applicable engagement terms. If there is a conflict concerning the processing of personal data, this DPA will take precedence unless the parties expressly agree otherwise in writing.
The governing law and dispute-resolution provisions specified in the engagement terms apply to this DPA.
This is a draft DPA pending legal review. It should not be relied upon as final legal documentation until reviewed and approved by qualified legal counsel. For questions, contact contact@velintis.ai.