Data Processing Addendum
Last updated September 27, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Vendor”) and VowRally. It applies when VowRally processes personal data on your behalf. It applies automatically; no signature is needed. If you need a countersigned copy, email support@vowrally.com.
1. Roles
For personal data about your clients and contacts (“Client Data”) you are the controller (or “business”) and VowRally is your processor (or “service provider”). VowRally is a separate controller only for your own account and billing data, as described in our Privacy Policy.
2. Scope of processing
- Subject matter and purpose: providing the VowRally service — storing CRM records, drafting replies, sending agreements and payment links, recording e-signatures, sending reminders and reports.
- Data subjects: your prospective and current clients (for example couples), people who pay on their behalf (for example parents), and other contacts you add.
- Categories of data: names, emails, phone numbers, event details (date, venue, guest count), messages, questionnaire answers, signed agreements and e-signature logs (IP address, user agent, timestamps), and payment metadata. No full card or bank numbers — those are handled by Stripe.
- Duration: for the term of your account plus the retention periods in section 8.
3. Our commitments as processor
- Process Client Data only on your documented instructions — which include your use of the service and these terms — and tell you if we believe an instruction breaks the law.
- Not sell or share Client Data, not use it for advertising, and not combine it with data from other customers except as needed to run the service.
- Not use Client Data to train AI models, and require the same of our AI provider.
- Make sure everyone with access is bound by confidentiality.
- Help you respond to data subject requests (access, correction, deletion, portability) through in-app tools or on request.
- Help you with security, breach notification and data protection impact assessments where reasonably needed.
- Make available the information needed to show compliance with this DPA, and allow reasonable audits (normally satisfied by written answers and third-party reports of our subprocessors), with 30 days' notice and no more than once a year unless there is a breach.
4. Subprocessors
You authorize us to use the subprocessors below. We have written agreements with each that protect Client Data at least as well as this DPA. We will give at least 14 days' notice (by email or on this page) before adding or replacing a subprocessor that handles Client Data. If you object on reasonable data-protection grounds and we can't address it, you may cancel and receive a refund of prepaid fees for the unused period.
- Supabase — Database, authentication, file storage
- Stripe — Payments on the vendor's connected account; subscription billing
- Resend — Transactional and inbound email
- OpenAI — AI drafting via API (no training on customer data)
- Inngest — Background jobs and scheduled reminders
- Vercel — Application hosting
- Google — Calendar free/busy (only if connected)
- Twilio — SMS (only if enabled)
- Meta — Instagram messaging (only if connected)
5. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Tenant isolation enforced in the database with row-level security; each studio sees only its own data.
- Passwordless sign-in by emailed link; least-privilege access for staff, with access logged.
- Secrets and integration tokens stored encrypted; payment card data never touches our servers.
- Tamper-evident e-signature records (document hash, timestamps, audit log).
- Managed backups by our database provider, dependency updates, and monitoring for errors and abuse.
- A written incident-response plan.
6. Personal data breaches
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Data, we will notify you without undue delay and within 72 hours of becoming aware of it. The notice will describe what happened, the data and people likely affected, likely consequences, and what we are doing about it, and we will update you as we learn more. We will not notify your clients directly unless you ask us to or the law requires it.
7. International transfers
VowRally and its subprocessors store and process data in the United States. VowRally is built for US businesses, but if you store Client Data about people in the EU, EEA, UK or Switzerland, the EU Standard Contractual Clauses (Module 2, controller to processor, and the UK Addendum where relevant) are incorporated into this DPA by reference, with you as data exporter and VowRally as data importer. [COUNSEL TO CONFIRM SCC ANNEX DETAILS AND GOVERNING LAW/FORUM ELECTIONS.]
8. Return and deletion
- You can export your data at any time while your account is active and for 30 days after it ends.
- After that 30-day period we delete Client Data from active systems. Backups roll off on their normal schedule (typically within 30 more days).
- E-signature audit records are kept for the life of the account plus 7 years so signed agreements can be proven, unless you instruct deletion and the law allows it. We keep them only for that purpose.
9. US state privacy laws
Where the California Consumer Privacy Act (as amended) or similar state laws apply, VowRally acts as a service provider/processor: we will not sell or share Client Data, retain, use or disclose it outside our direct business relationship with you, or combine it with other data except as those laws permit, and we will notify you if we can no longer meet these obligations.
10. Order of precedence
If this DPA conflicts with the Terms of Service on the processing of Client Data, this DPA controls. If the Standard Contractual Clauses apply and conflict with this DPA, the Clauses control. Liability under this DPA is subject to the limits in the Terms of Service to the extent the law allows.
Contact
Privacy and data protection questions: support@vowrally.com