Data Processing Addendum (DPA)
Summary (enterprise-ready). Full DPA available upon request.
ValidVantage supports workforce compliance monitoring (registers, alerts, exports). By design, documents remain in customer-owned storage (e.g., Drive/SharePoint), and ValidVantage stores only the minimum metadata required to run monitoring and reporting.
What’s included (key terms)
Customer acts as Controller. ValidVantage acts as Processor when processing personal data on the Customer’s behalf to deliver the service.
Purposes: readiness monitoring, expiry alerts, compliance exports (“Compliance Packs”), and service support. Categories of data may include: workforce identifiers, credential status, expiry dates, role/site assignments, and proof links.
Documents remain in Customer-owned storage. ValidVantage stores minimal metadata (status, expiry, references/links) required for monitoring, plus operational logs needed to produce audit-ready outputs.
- Encrypted transport (HTTPS/TLS) for web traffic and operational access.
- Least-privilege access (only the registers/folders required for delivery).
- Operational logging for key activities (e.g., exports, updates) where applicable.
- Data minimization by design (customer-owned storage as default).
ValidVantage uses the following subprocessors to operate the website and service infrastructure:
- Namecheap (Hosting / cPanel) — hosting infrastructure and related services.
- cPanel mail (Email) — transactional and operational email delivery.
Customer-selected storage providers (e.g., Google Drive / Microsoft SharePoint) remain under Customer control and are chosen by the Customer.
Customer controls retention of source documents in Customer-owned storage. ValidVantage retains Customer Data for the contract term and a limited period thereafter for operational continuity, security, and dispute resolution, and deletes/returns data according to the agreed DPA and applicable law.
Where data is transferred outside the EEA, ValidVantage applies appropriate safeguards (e.g., Standard Contractual Clauses) as applicable. ValidVantage will notify the Customer without undue delay after becoming aware of a relevant personal data breach, and will provide reasonable assistance.
Email: contact@validvantage.com