Legal
Data processing agreement
A summary of the agreement we sign when we handle personal data inside a system we build, host, or maintain for you, and how to get the signed copy.
DCI Brands LLC, trading as Vavus Business Solutions, 312 W 2nd Street, Casper, WY 82601, United States. Effective 3 September 2026 · Version 2.0.
1. This page is a summary
This page describes our standard data processing agreement so you can review it before you ask for it. It is not itself an agreement and creates no obligations. The executed DPA, with its annexes, is what controls, and where this page differs from it, the executed DPA wins.
2. When a DPA applies
Whenever we build, host, maintain, or support a system holding personal data belonging to you or your users. You are the controller (or business); DCI Brands LLC is the processor (or service provider). The DPA forms part of the engagement agreement. Where protected health information is involved, a Business Associate Agreement is signed as well and, for that data, its terms control.
3. What the executed DPA contains
Everything Article 28(3) of the GDPR requires, and the equivalents under the UK GDPR and the Swiss FADP:
- The processing description: subject matter, duration, nature and purpose, types of personal data, and categories of data subjects, in an annex specific to your engagement.
- Processing only on your documented instructions, including for transfers, and our commitment to tell you if we think an instruction breaches data protection law.
- Confidentiality: everyone we authorize to process your data is bound by a written confidentiality obligation.
- Security: the technical and organizational measures in the annex, meeting Article 32. We may update them provided protection is not materially reduced.
- Sub-processors: your general written authorization, our written flow-down of equivalent obligations, and our responsibility for their performance.
- Assistance with data subject rights: access, correction, deletion, portability, restriction, and objection, taking into account the nature of the processing.
- Assistance with Articles 32 to 36: security, breach notification, data protection impact assessments, and prior consultation, taking into account what we know.
- Deletion or return at the end of the engagement, at your choice.
- Information and audits, as described in section 8.
- Transfer terms: the standard contractual clauses, the UK Addendum, and the Swiss amendments, with the annexes completed.
- US state terms: we act as a service provider or processor, we do not sell or share your data, we do not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the engagement, and we do not combine it with data from other sources.
- Your warranties: that you have a lawful basis, have given the notices and obtained the consents your users are owed, and that your instructions are lawful.
4. What we do with your data
We process it only on your documented instructions and only to deliver the engagement: building, testing, deploying, hosting, monitoring, backing up, and supporting the system. We do not use it for our own purposes and we do not sell it.
We do not use your personal data to train, fine-tune, or improve any model, and our sub-processors are contractually configured not to either. We may generate aggregated statistics about system operation only where they cannot be linked to you, your users, or any individual.
5. Sub-processors
We use sub-processors only where the engagement needs them, under written terms at least as protective as the DPA, and we remain responsible for what they do. Categories: cloud infrastructure in the region your quote names, transactional email delivery, and speech, language, and model providers where a feature requires one and the quote names it. The executed DPA lists the specific providers for your engagement.
We give 30 days' notice before adding one. You may object within that period on reasonable data-protection grounds, we will work with you in good faith, and if we cannot resolve it, either party may terminate the affected service with a pro-rata refund of prepaid unused fees. That is the sole remedy. On-premise and air-gapped deliveries remove the infrastructure sub-processor entirely.
6. Security
Delivered systems ship with the measures set out in the security annex: at minimum, encryption in transit and at rest, role-based access control, structured audit logging, and secure deletion of temporary files. Staff access is limited to named people who need it and is logged. Regulated engagements add the controls named in your annex.
7. Incidents
We notify you without undue delay after we confirm a personal data breach affecting your data, and in any event within 72 hours of that confirmation. The notice sets out what we know, what we have done, and what we recommend; a first notice may be preliminary and we supplement it as we learn more. We do not report unsuccessful access attempts, scans, or pings, and a notice is not an admission of fault or liability.
8. Your requests, and audits
We help you answer access, correction, deletion, and portability requests within the time the law gives you.
Audits start with documents. On request, once in any 12 months, we provide our security documentation, our measures annex, and a completed security questionnaire. Where that is genuinely insufficient, or after a confirmed breach affecting your data, or where a supervisory authority requires it, you may audit us on 30 days' written notice, once in any 12 months, during business hours, at your cost, under confidentiality, without disrupting our operations or other clients' data, and using an auditor who is not our competitor.
9. Transfers and residency
Production data at rest stays in the region named in your quote. Administrative access from other locations, and any unavoidable transfer out of the EEA, the UK, or Switzerland, is covered by the standard contractual clauses and the applicable addenda.
10. End of the engagement
We return or delete your personal data, at your choice, and certify deletion. Copies in encrypted backups are deleted on the ordinary backup cycle and stay protected until then. We keep only what the law requires us to keep.
11. Getting the DPA
Write to constantine@vavusai.com with your quote reference. We send it for signature alongside the engagement agreement. We will review your own DPA and sign it where its terms are materially consistent with ours; otherwise ours controls.