VURAOS Privacy
Español English
Legal · Data

Data Processing Agreement

Data Processing Agreement — sets out the conditions under which VuraOs LLC acts as Processor of personal data on behalf of the Customer.

Version: 1.0  ·  Effective from: May 2026  ·  VuraOs LLC

1. Definitions

  • Customer / Controller: the company or organization that contracts VURAOS services and determines the purposes and means of personal data processing.
  • VURAOS / Processor: VuraOs LLC, which processes personal data on behalf of and under the Customer's instructions to provide the Service.
  • Personal Data: any information relating to an identified or identifiable natural person under applicable regulations (GDPR, LGPD, Argentina's Law 25.326 and equivalents).
  • Processing: any operation performed on personal data, such as collection, storage, use, transmission, or deletion.
  • Sub-processor: a third party engaged by VURAOS to carry out part of the processing, subject to the same obligations as those set out in this DPA.
  • Security Incident: unauthorized access to, or loss, alteration, or disclosure of, personal data.

2. Roles of the parties

Data controller

The Customer

Determines the purposes and means of processing. Defines which data is processed, who the data subjects are, and what the information is used for.

Data processor

VURAOS

Processes data solely according to the Customer's documented instructions in order to provide the Service. It makes no decisions of its own about the Customer's data.

3. Subject matter and nature of processing

VURAOS processes personal data to provide the communication automation, AI agent management, CRM, and analytics services included in the VURAOS platform contracted by the Customer.

Categories of data processed

  • Contact data: name, email address, phone number, messaging identifiers (WhatsApp, Telegram).
  • Interaction data: conversation content, message history, inquiries, and generated responses.
  • Business data: lead information, opportunities, CRM notes entered by the Customer.
  • Technical metadata: timestamps, communication channels, session identifiers.

Categories of data subjects

  • The Customer's end customers (consumers, leads, users of its services).
  • Employees, collaborators, or representatives of the Customer who use the platform.

4. Processing instructions

VURAOS processes personal data solely according to the Customer's documented instructions, as configured in the platform, automation flows, and service contracts. The Customer guarantees that its instructions comply with applicable regulations.

If VURAOS considers that an instruction infringes data protection regulations, it will notify the Customer immediately in writing.

5. Confidentiality

VURAOS guarantees that the persons authorized to process the Customer's data are bound by confidentiality obligations and only access the data necessary for their duties. VURAOS employees and contractors with access to Customer data have signed non-disclosure agreements.

6. Technical and organizational measures (TOM)

VURAOS implements and maintains the following security measures:

  • Encryption in transit: TLS 1.3 on all communications.
  • Encryption at rest: AES-256 for stored data.
  • Access control: multi-factor authentication, least-privilege access, quarterly permission reviews.
  • Audit: data access logs retained for 12 months.
  • Backups: automatic daily encrypted backups retained for 7 days.
  • Segregation: each Customer's data stored in logically isolated spaces.
  • Vulnerability management: security patches applied within 72 hours for critical vulnerabilities.
  • Testing: periodic security assessments of the infrastructure.

7. Sub-processors

The Customer authorizes VURAOS to use the sub-processors listed below. VURAOS guarantees that each sub-processor is bound by contractual data protection obligations equivalent to those of this DPA.

Provider Service provided Processing country
Supabase Inc. Database, authentication, serverless functions US / EU (AWS us-east-1)
Amazon Web Services (AWS) Cloud infrastructure, AI models (Bedrock) US (us-east-1)
ElevenLabs Inc. AI voice synthesis (TTS) US
Google LLC Analytics (anonymized data), Tag Manager US / Global
Meta Platforms (WhatsApp Cloud API) WhatsApp message transmission US / Global
Stripe Inc. Payment processing US / EU

VURAOS will notify the Customer at least 30 days in advance of any change to the list of sub-processors, giving the Customer the opportunity to object to such change.

8. International data transfers

Data may be transferred to and processed outside the Customer's country of origin. VURAOS guarantees that such transfers are carried out with appropriate safeguards, including:

  • Standard Contractual Clauses (SCC) approved by the European Commission for transfers from the EEA.
  • Contracts with providers that comply with the EU–US Data Privacy Framework (DPF).
  • Transfer impact assessments (TIA) where required by applicable regulations.

9. Data subject rights

VURAOS will assist the Customer, insofar as technically possible, in responding to requests to exercise data subject rights (access, rectification, erasure, portability, objection, restriction). The Customer is responsible for managing these requests and for communicating them to VURAOS when they require technical actions on the stored data.

VURAOS will respond to the Customer's technical requests within 5 business days of receipt.

10. Security incident notification

If it detects a security incident involving the Customer's personal data, VURAOS will:

  • Notify the Customer within 72 hours of becoming aware of the incident.
  • Include in the notification: the nature of the incident, the categories and approximate volume of data affected, the measures taken and recommended, and the contact details of VURAOS's security lead.
  • Cooperate with the Customer in the investigation and in notifying supervisory authorities if necessary.

11. Audits

The Customer has the right to request information about VURAOS's security practices or to carry out compliance audits, with at least 30 days' prior notice and under mutually agreed terms so as not to interfere with the operation of the Service. The costs of audits requested by the Customer are borne by the Customer.

VURAOS may satisfy audit requests by providing third-party reports (penetration testing, security assessments) when available.

12. Data deletion and return

Upon expiration or termination of the service contract:

  • VURAOS will provide the Customer with a complete export of its data in a standard format (CSV/JSON) within 30 days of the request.
  • After that period, or upon the Customer's express request, VURAOS will securely delete all of the Customer's personal data from its systems, unless there is a legal obligation to retain it.
  • VURAOS will provide a written certificate of deletion if the Customer requests it.

13. Duration

This DPA has the same duration as the main service contract (Terms of Service or Enterprise MSA). Confidentiality and security obligations remain in force for an additional 5 years after termination of the contract.

14. Request a signed DPA

Enterprise customers and Partners who require a bilaterally signed DPA for their compliance processes can request one by contacting our team:

Email: enterprise@vuraos.com
Subject: "Signed DPA request — [your company name]"
Response time: 3 business days
Available formats: Electronically signed PDF (DocuSign / local digital signature)

Built with
Powered by AWSPowered by AWS ElevenLabs GrantsElevenLabs Grants MetaMetaVerified Tech Provider WhatsAppWhatsAppInstagramInstagramFacebookFacebook

© 2026 VuraOs LLC · Sheridan, WY · USA

Terms Privacy Refunds GDPR Cookies

VURAOS AI

We use essential cookies for site functionality and analytics cookies to improve your experience. By continuing to browse, you accept their use. Learn more →