Data Processing Addendum
Last updated: August 15, 2026
This page describes how to put a Data Processing Addendum (“DPA”) in place with Valarn. A DPA governs Valarn's processing of personal data on your behalf and is offered to customers who require one to meet their obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), or similar laws.
Roles
For personal data you submit to the service, you (the customer) act as the data controller (or “business” under CCPA) and Valarn acts as the data processor (or “service provider”), processing personal data only on your documented instructions and as necessary to provide the service.
What the DPA covers
- Subject-matter, duration, nature, and purpose of processing, and categories of data and data subjects.
- Confidentiality, security measures, and breach-notification commitments.
- Use of subprocessors and prior notice of changes — see our Subprocessors list.
- Assistance with data-subject requests and with your data-protection impact assessments.
- International-transfer mechanisms, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable.
- Deletion or return of personal data at the end of the service.
Requesting a signed DPA
To execute a countersigned DPA for your organization, email legal@valarn.com with your legal entity name and address. We will return an executable copy. If your purchase includes a signed DPA, its terms control over this summary. This page is a summary for convenience and is not itself the binding agreement.
See also our Privacy Policy, EU / UK Privacy Notice, and Subprocessors list.