Data Processing Addendum - VeLens
Version: 1.0
Last updated: September 27, 2026
Applies to: VeLens Cloud, and VeLens for Marketing Cloud (the Chrome extension).
1. Introduction and how this Addendum applies
This Data Processing Addendum ("Addendum") forms part of the VeLens Terms of Service (the "Terms") between VeLens, Inc. ("VeLens") and the customer that has agreed to the Terms ("Customer").
It applies automatically, without signature, to every Customer whose use of the Service involves personal data protected by the GDPR, the UK GDPR or the Swiss FADP, and on request to any other Customer. Agreeing to the Terms is agreeing to this Addendum. Customers whose procurement process needs a countersigned copy can email info@velens.cloud.
This Addendum takes precedence over the Terms for the subject matter it covers. If this Addendum conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses take precedence. Capitalised terms not defined here have the meaning given in the Terms.
2. Definitions
- Data Protection Law - all laws on the processing of personal data that apply to a party's processing of Customer Data under the Terms, including Regulation (EU) 2016/679 (the "GDPR"), the GDPR as it forms part of UK law (the "UK GDPR") together with the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection (the "FADP").
- Personal Data - any information relating to an identified or identifiable natural person, as defined in Data Protection Law.
- Customer Data - Personal Data that VeLens processes on Customer's behalf in providing the Service, as described in Annex I.
- Controller, Processor, Data Subject, Processing and Supervisory Authority have the meanings given in the GDPR.
- Sub-processor - a third party that VeLens engages to process Customer Data.
- SCCs - the standard contractual clauses for transfers of personal data to third countries approved by the European Commission in Implementing Decision (EU) 2021/914.
- UK Addendum - the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022).
- Security Incident - a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data.
3. Roles of the parties
For Customer Data, Customer is the Controller (or a Processor acting for its own Controller) and VeLens is the Processor. Customer Data covers the data VeLens reads from Customer's Salesforce Marketing Cloud account through the Service, and the content Customer's users submit to AI features.
VeLens is an independent Controller for the account data described in sections 5 and 10 of the Privacy Policy, such as user identity, Terms acceptance records, security logs and VeLens's own emails to users. This Addendum does not cover that data; the Privacy Policy does.
Customer is responsible for having a lawful basis for the processing it instructs, for giving any notices Data Protection Law requires to its Data Subjects, and for the accuracy of Customer Data.
4. Processing on documented instructions
VeLens processes Customer Data only on Customer's documented instructions, unless the law that applies to VeLens requires otherwise, in which case VeLens will tell Customer before processing unless that law prohibits it.
Customer's documented instructions are the Terms, this Addendum, and Customer's configuration and use of the Service, including the role and feature settings its administrators choose and each write to Marketing Cloud that one of its users confirms. Additional instructions need VeLens's written agreement.
VeLens will inform Customer if, in its opinion, an instruction infringes Data Protection Law.
VeLens does not process Customer Data for its own purposes. In particular, VeLens does not use Customer Data to train AI models, and it routes AI requests through its gateway with zero data retention enabled, configured to fail closed (Privacy Policy section 6).
5. Confidentiality
VeLens ensures that everyone it authorises to process Customer Data is bound by an obligation of confidentiality, and limits that access to what operating, supporting and securing the Service requires.
6. Security
VeLens implements the technical and organisational measures in Annex II, which are designed to protect Customer Data against Security Incidents. VeLens may update those measures as the Service and the threat landscape change, provided the update does not lower the overall level of protection.
Customer is responsible for the security of its own accounts, for its users' use of the Service, and for the role and feature settings its administrators choose.
7. Sub-processors
Customer gives VeLens general written authorisation to engage Sub-processors. The current Sub-processors are listed in Annex III and in section 6 of the Privacy Policy.
VeLens will give notice at least 30 days before it adds or replaces a Sub-processor, by updating the Privacy Policy and by email or in-product notice. Customer may object within 30 days of the notice on reasonable grounds relating to data protection. The parties will discuss the objection in good faith. If it is not resolved, Customer may terminate the Terms and delete its account, and that is Customer's remedy for the objection.
VeLens imposes data protection obligations on each Sub-processor by written contract that are no less protective than those in this Addendum, to the extent they apply to the service that Sub-processor provides. VeLens remains liable to Customer for the performance of its Sub-processors' obligations.
8. Data Subject requests
If VeLens receives a request from a Data Subject about Customer Data, it will forward the request to Customer without undue delay. VeLens will not respond to the Data Subject itself, except to direct them to Customer, unless Customer authorises it.
Taking into account the nature of the processing, VeLens assists Customer in responding to Data Subject requests through the Service's own tools, including disconnecting the Marketing Cloud connection and the in-product account and organization deletion flows, and, where those are not enough, on request.
9. Assistance
Taking into account the nature of the processing and the information available to VeLens, VeLens will reasonably assist Customer with its obligations under Articles 32 to 36 of the GDPR (and the equivalent provisions of the UK GDPR and the FADP): security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with a Supervisory Authority.
Where the assistance Customer asks for goes beyond what the Service, this Addendum and VeLens's published documentation provide, Customer will pay VeLens's reasonable costs, agreed in advance.
10. Security Incidents
VeLens will notify Customer without undue delay, and no later than 72 hours after becoming aware of it, of a Security Incident affecting Customer Data. The notice will include, as far as it is then known, the information Article 33(3) of the GDPR requires: the nature of the incident, including the categories and approximate number of Data Subjects and records concerned; a contact point; the likely consequences; and the measures taken or proposed. Where the information is not yet available, VeLens will provide it in phases as the investigation proceeds.
VeLens will take reasonable steps to contain and investigate the Security Incident and to reduce its effects. Notice is sent to the email address associated with Customer's account owner or administrators.
VeLens's notification of or response to a Security Incident is not an acknowledgement of fault or liability.
11. Deletion and return of Customer Data
Customer can export data through the Service where the Service offers an export, and can delete its data at any time through the in-product deletion flow described in section 11 of the Privacy Policy.
When the Terms end, or when Customer deletes its account or organization, VeLens deletes Customer Data from the live Service within the retention periods in section 5 of the Privacy Policy. Copies inside encrypted backups expire within 30 days. This is subject to any retention the law requires of VeLens, in which case VeLens keeps the data confidential and processes it only for that purpose.
A deletion receipt, which records that an erasure took place and contains no personal data, is available on request.
12. Audits
VeLens makes available the information reasonably necessary to demonstrate its compliance with this Addendum. That information is the security page, this Addendum, the Sub-processor list, and, on request and under a confidentiality agreement, summaries of VeLens's internal security policies.
VeLens does not hold a SOC 2 report or an ISO 27001 certificate.
If that information is not enough, Customer may audit VeLens's compliance with this Addendum once in any 12-month period, on at least 30 days' written notice, during business hours and at Customer's own cost. An audit begins with a written questionnaire. Where the questionnaire is not sufficient, or where a Supervisory Authority requires it, the audit may be carried out by an independent auditor that both parties agree on, is bound by confidentiality, and does not compete with VeLens. Audits must not unreasonably interfere with VeLens's operations or compromise the security or confidentiality of other customers' data. Nothing here limits an audit that a Supervisory Authority is entitled to carry out, or Customer's rights under the SCCs.
13. International transfers
Customer Data is processed in the United States. VeLens is not certified under the EU-US Data Privacy Framework.
EEA. Where the transfer of Customer Data to VeLens is a restricted transfer under the GDPR, the SCCs are incorporated into this Addendum by reference and apply as follows:
- Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor;
- Clause 7 (docking clause) is not included;
- in Clause 9(a), Option 2 (general written authorisation) applies, with the notice period set out in section 7 of this Addendum;
- in Clause 11(a), the optional language is not included;
- in Clause 13, the competent Supervisory Authority is determined by Customer's establishment, as set out in that Clause;
- in Clause 17, Option 1 applies, and the SCCs are governed by the law of Ireland;
- in Clause 18(b), disputes are resolved before the courts of Ireland; and
- Annexes I, II and III of the SCCs are completed by Annexes I, II and III of this Addendum.
United Kingdom. Where the transfer is a restricted transfer under the UK GDPR, the UK Addendum is incorporated into this Addendum by reference. Its Part 1 tables are completed with the parties' details in Annex I, the selected modules and clauses of the SCCs above, and Annexes I, II and III of this Addendum. For Table 4, neither party may end the UK Addendum when the approved addendum changes.
Switzerland. Where the transfer is subject to the FADP, the SCCs apply as above with these changes: the Federal Data Protection and Information Commissioner (FDPIC) is the competent Supervisory Authority; references to the law of a Member State are read as references to Swiss law where the FADP applies; and "Member State" in Clause 18(c) includes Switzerland, so that Data Subjects habitually resident there may bring proceedings there.
VeLens will provide a summary of its transfer impact assessment on request. VeLens will notify Customer if it becomes unable to comply with the SCCs, and handles any request from a public authority for access to Customer Data as set out in Clause 15 of the SCCs.
14. Liability
Each party's liability arising out of or relating to this Addendum is subject to the limitation of liability in the Terms, applied in aggregate across the Terms and this Addendum. Nothing in this Addendum limits liability that cannot be limited under Data Protection Law or under the SCCs, including each party's liability to Data Subjects under the SCCs.
15. Term, precedence and changes
This Addendum applies for as long as VeLens processes Customer Data, and survives the end of the Terms until that processing ends.
VeLens may update this Addendum to reflect changes in Data Protection Law or in the Service. Updates are published at velens.cloud/dpa with notice given as for the Terms. An update will not lower the protection this Addendum gives Customer Data, except where the law requires it.
This Addendum is governed by the law that governs the Terms, except where the SCCs or the UK Addendum specify otherwise.
Annex I - Details of processing
A. The parties
Data exporter: Customer, as identified by its account in the Service. Contact: the account owner or administrator email address held in the Service. Role: Controller (or Processor on behalf of its own Controller). Activities: use of the Service with its Salesforce Marketing Cloud account. Signature and date: agreeing to the Terms is treated as signature of this Addendum and the SCCs, on the date of that agreement.
Data importer: VeLens, Inc., 131 Continental Dr Ste 305, Newark, DE 19713-4324, United States. Contact: info@velens.cloud. Role: Processor. Activities: providing the Service. Signature and date: as for the data exporter.
B. Description of the processing
Categories of Data Subjects
- Customer's users and administrators of the Service.
- Customer's Marketing Cloud subscribers and contacts, to the limited extent described below.
Categories of Personal Data
- Customer's users: name, email address, Salesforce Marketing Cloud user and enterprise identifiers, Business Unit identifiers, role in the Service, conversations with AI features, and content submitted to AI features, including any images a user attaches to an AI Chat message.
- Customer's subscribers and contacts: Marketing Cloud metadata only, such as Data Extension and field names, counts, schemas, send and journey names, statuses and dates. Subscriber keys, email addresses, list memberships and event history are retrieved only when a user runs a subscriber lookup, and are not sent to an AI model. Only if a Customer owner or administrator switches it on (it is off by default), the AI can check a single subscriber's engagement history, looked up by a SubscriberKey or ContactKey that the user types in. That result contains email, journey and list names, dates, statuses and bounce categories only, with no email addresses, no profile attributes and no Data Extension row values, and the identifier itself is masked in everything sent to the model.
The Service is designed so that subscriber contact details and Data Extension row values are not sent to VeLens's AI Sub-processors (Privacy Policy section 7).
Special categories of data: none intended. Customer must not direct VeLens to process special categories of Personal Data or data relating to criminal convictions and offences.
Frequency of the transfer: continuous, for as long as Customer's Marketing Cloud account is connected to the Service.
Nature and purpose of the processing: providing the Service as described in sections 2, 3, 5 and 7 of the Privacy Policy: reading Marketing Cloud metadata and send data at a user's direction, answering users' questions with AI features, drafting content, and making changes in Marketing Cloud that a user confirms.
Subject matter and duration: the Personal Data above, for the term of Customer's account.
Retention: as set out in section 5 of the Privacy Policy. Encrypted backups expire within 30 days.
Transfers to Sub-processors: as listed in Annex III, for the purposes stated there and for the duration of the processing.
C. Competent Supervisory Authority
The Supervisory Authority determined in accordance with Clause 13 of the SCCs. For the UK, the Information Commissioner's Office; for Switzerland, the FDPIC.
Annex II - Technical and organisational measures
Encryption
- TLS on every network boundary: browser to API, API to Marketing Cloud, API to the database, and API to the AI gateway.
- Marketing Cloud access and refresh tokens are encrypted at rest with AES-256-GCM, using a key held only in the hosting provider's encrypted environment store, outside the database. No Marketing Cloud credential is stored in plaintext, and the browser never holds the refresh token.
- The rest of the database is protected by the database provider's managed disk encryption.
Access control and tenant isolation
- Row-level security is enabled on every database table, and a database trigger enables it automatically on any new table. Server code filters every query by the user and organization resolved from the authenticated session; identifiers supplied by a client are never trusted.
- Every Business Unit a request names is checked against the Business Units the organization's connection is allowed to reach before any Marketing Cloud call.
- Organization roles (owner, admin, editor, reviewer, viewer), and administrator settings that switch features and AI tool categories off for the whole organization or per role.
- Least privilege and named accounts for VeLens's own production access, with multi-factor authentication required on every account with production access, and periodic access reviews.
Secrets management
- No secret is committed to source control; secrets are held in the hosting and CI providers' encrypted stores and are redacted from error records.
- Secrets are rotated on a schedule, and any secret immediately on suspected exposure.
Protecting subscriber data from AI
- Subscriber lookup tools and the subscriber status tool are on a denylist applied to every AI surface, checked again when a write is confirmed; any tool that returns subscriber row data is removed from every AI surface by a second, independent check.
- Identifiers that a permitted tool can still surface, such as an email address inside a bounce reason, are masked in VeLens's backend before a tool result is sent to a model or stored.
- AI requests are routed only through the AI gateway, with zero data retention enabled and configured to fail closed: if a zero-retention route is not available, the request errors rather than falling back.
Change safety
- Nothing changes in Customer's Marketing Cloud account from an AI feature without a person's confirmation of the exact tool and arguments shown to them.
Logging and monitoring
- Every tool execution that reaches Marketing Cloud is recorded in an audit log (who, what, where, status), kept for 30 days, with email addresses redacted.
- Unhandled server errors are recorded in redacted form and reviewed regularly, with separate alerts for credential failures; AI spend is capped at the gateway.
Retention and deletion
- A daily scheduled job deletes data when its retention period ends (Privacy Policy section 5).
- In-product deletion of an account or organization, with a deletion receipt that contains no personal data.
Backups and recovery
- Database backups twice a day, encrypted with
ageby the backup job before upload. The job holds only the public key; the private key is held by VeLens in a password manager protected by multi-factor authentication, and not by the backup storage provider or the CI provider. - Backups are deleted automatically after 30 days, and restoring from a backup is tested periodically.
Abuse prevention
- Per-organization rate limiting of Marketing Cloud calls, per-IP rate limiting on the sign-in and session endpoints, and schema validation of every tool input.
Secure development
- Every change passes continuous integration: linting, the automated test suite, a syntax check of every shipped script, and a blocking dependency audit for high-severity advisories. Dependency alerts are monitored.
- Database changes are made only through versioned migrations.
- Dynamic application security testing of the production API.
Incident response
- A documented incident response process: prompt triage, containment, recovery, notification as in section 10 of this Addendum, and a written post-incident review.
- A published security contact, security@velens.cloud, for vulnerability reports.
Endpoint security
- The workstation used to administer the Service has full-disk encryption, an automatic screen lock and current security updates.
Certifications
- VeLens does not hold a SOC 2 report or an ISO 27001 certificate.
Annex III - Sub-processors
The live list is section 6 of the Privacy Policy. This annex is updated with it.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel, Inc. | Hosts the VeLens web app and API | United States |
| Supabase, Inc. | Database and authentication | United States (AWS us-east-2, Ohio) |
| Cloudflare, Inc. | Stores the twice-daily encrypted backups; Cloudflare holds no key to them | Eastern North America |
| GitHub, Inc. (a Microsoft company) | Runs the scheduled backup job, which reads the database and encrypts each backup before upload; the runner is ephemeral and the key that decrypts the backups is not stored on GitHub | United States |
| Vercel, Inc. (AI Gateway) | Routes requests from AI features to the model providers below, with zero data retention enabled and configured to fail closed | United States |
| Model providers: OpenAI, Inc.; Anthropic, PBC; Google LLC (Google Cloud); Microsoft Corporation (Azure); Amazon Web Services, Inc. (Amazon Bedrock) | Run the AI models behind the AI features, bound to zero data retention; the gateway selects the provider for each request | United States; the gateway selects the provider per request |
Salesforce, Inc. also appears in the Privacy Policy's list, as the provider of VeLens's own CRM and email accounts. It processes only account data for which VeLens is the Controller, not Customer Data, so it is not a Sub-processor under this Addendum.