← Back to ValidVantage
DPA

Data Processing Addendum (DPA)

Summary (enterprise-ready). Full DPA available upon request.

ValidVantage supports workforce compliance monitoring (registers, alerts, exports). By design, documents remain in customer-owned storage (e.g., Drive/SharePoint), and ValidVantage stores only the minimum metadata required to run monitoring and reporting.

Contact
Request the full DPA: contact@validvantage.com

What’s included (key terms)

1) Roles

Customer acts as Controller. ValidVantage acts as Processor when processing personal data on the Customer’s behalf to deliver the service.

2) Processing scope

Purposes: readiness monitoring, expiry alerts, compliance exports (“Compliance Packs”), and service support. Categories of data may include: workforce identifiers, credential status, expiry dates, role/site assignments, and proof links.

3) Data minimization & document custody

Documents remain in Customer-owned storage. ValidVantage stores minimal metadata (status, expiry, references/links) required for monitoring, plus operational logs needed to produce audit-ready outputs.

4) Security measures
  • Encrypted transport (HTTPS/TLS) for web traffic and operational access.
  • Least-privilege access (only the registers/folders required for delivery).
  • Operational logging for key activities (e.g., exports, updates) where applicable.
  • Data minimization by design (customer-owned storage as default).
5) Subprocessors

ValidVantage uses the following subprocessors to operate the website and service infrastructure:

  • Namecheap (Hosting / cPanel) — hosting infrastructure and related services.
  • cPanel mail (Email) — transactional and operational email delivery.

Customer-selected storage providers (e.g., Google Drive / Microsoft SharePoint) remain under Customer control and are chosen by the Customer.

6) Retention & deletion

Customer controls retention of source documents in Customer-owned storage. ValidVantage retains Customer Data for the contract term and a limited period thereafter for operational continuity, security, and dispute resolution, and deletes/returns data according to the agreed DPA and applicable law.

7) International transfers & incident response

Where data is transferred outside the EEA, ValidVantage applies appropriate safeguards (e.g., Standard Contractual Clauses) as applicable. ValidVantage will notify the Customer without undue delay after becoming aware of a relevant personal data breach, and will provide reasonable assistance.

Request the full DPA

Email: contact@validvantage.com