Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") supplements the Ventrexs AI Terms of Service and applies where GDPR, UK GDPR, CCPA/CPRA, or global privacy legislation governs the processing of personal data.
1. Scope & Definitions
This DPA applies to the processing of Personal Data by Desynthic on behalf of the Customer ("Customer", "Controller", "You") in connection with the provision of the Ventrexs AI Accounts Receivable SaaS Platform.
- "Controller" means the entity that determines the purposes and means of processing Personal Data (The Customer).
- "Processor" means Desynthic, which processes Personal Data strictly on behalf of and pursuant to instructions from Controller.
- "Data Subject" means identified or identifiable natural persons whose personal data is uploaded or processed (e.g., Customer representatives, end-client billing contacts).
- "Subprocessor" means any third-party data processor engaged by Ventrexs AI to deliver technical infrastructure services.
2. Roles & Processing Instructions
Desynthic agrees to process Personal Data exclusively in accordance with documented instructions from Customer, including regarding transfers of Personal Data to third countries, unless required to do so by applicable Union or Member State law.
• Confidentiality: Desynthic ensures that all personnel authorized to process Customer Personal Data have committed themselves to strict confidentiality obligations.
• Purpose Limitation: Desynthic shall not process, sell, retain, or monetize Customer data for any purpose other than providing the agreed SaaS invoicing and collection operations.
3. Authorized Subprocessors
Customer grants general authorization for Desynthic to engage the following infrastructure subprocessors:
| Subprocessor | Entity & Location | Processing Scope | Transfer Mechanism |
|---|---|---|---|
| Supabase Inc. | USA / EU | Managed Postgres Database, Row Level Security, Auth Engine | Standard Contractual Clauses (SCCs) |
| Stripe Inc. | USA | Payment processing, merchant settlement, card tokenization | SCCs / DPF Compliant |
| Resend Inc. | USA | Transactional billing email delivery | SCCs |
| Twilio Inc. | USA | SMS reminder transmission & TCPA opt-out management | SCCs |
| Meta Platforms Ireland | Ireland / USA | WhatsApp Cloud API reminder delivery | EU DPA / SCCs |
| Google LLC (Gemini API) | USA | Read-only AR copilot draft generation (Zero public model training) | SCCs |
4. Technical & Organizational Security Measures (TOMs)
Ventrexs AI maintains rigorous technical and organizational measures pursuant to GDPR Article 32:
- Tenant Isolation: Database-level Row Level Security (RLS) guaranteeing absolute logical segregation between different merchant tenants.
- Encryption: Enforced TLS 1.3 encryption for all data in transit; AES-256 encryption for database storage and backups at rest.
- Cryptographic Webhook Signatures: Inbound payment webhooks validated using HMAC SHA-256 signatures to reject replay or tampering attacks.
- Deterministic Ethical Guardrails: Mathematical balance validation rejecting interest or unauthorized balance modification.
5. Security Incident Management & Notification
In the event of a confirmed Security Incident resulting in unlawful destruction, loss, alteration, or unauthorized disclosure of Customer Personal Data, Desynthic shall:
- Notify affected Customers without undue delay and, where feasible, within 72 hours of becoming aware of the incident.
- Provide relevant details describing the nature of the breach, categories of data subjects impacted, and remedial actions undertaken.
6. Return & Deletion of Customer Personal Data
Upon termination of Services or receipt of a deletion instruction from Customer, Desynthic shall delete or return all Customer Personal Data within 30 days, in accordance with our Data Retention Policy, retaining only records required under applicable commercial tax and financial auditing laws.
© 2026 Desynthic. All rights reserved.