Legal
Data processing addendum.
This forms part of the agreement wherever we process personal data on your behalf. It is signable as-is; most customers do not need to redline it.
Last updated 18 September 2026
01Roles
For personal data inside agent sessions, you are the controller and Velone is the processor. For account and billing data we are the controller and our privacy policy applies.
In BYOC and air-gapped deployments our processing is limited to scheduling metadata, policy versions, and evidence chain heads. We do not process tool arguments, file contents, prompts, or model output in those deployments.
02Subject matter and duration
We process personal data for as long as you use the service, plus the retention periods in the agreement. Processing ends when the account is closed and the export window has passed.
03Nature and purpose
- Scheduling and running isolated sandboxes
- Evaluating policy against tool calls and arguments
- Minting scoped, short-lived credentials
- Routing approvals to nominated humans
- Writing, storing, and serving evidence entries
- Billing, support, and platform security
04Categories of data
Determined by you. Typically: identifiers of the humans an agent acts for, approver identities, and whatever personal data your agents encounter in the systems you connect. Special category data should only be processed in BYOC or air-gapped deployments, and we will say so during onboarding.
05Our obligations
- Process personal data only on your documented instructions
- Keep it confidential and bind personnel to confidentiality
- Apply the technical and organisational measures below
- Assist you with data subject requests, DPIAs, and regulator enquiries
- Notify you without undue delay, and within 24 hours of confirmation, of a personal data breach
- Delete or return personal data on termination
- Make available the information needed to demonstrate compliance
06Security measures
- Hardware-level isolation between tenants using microVMs with separate guest kernels
- TLS 1.3 in transit, AES-256 at rest, per-session workspace keys, customer-managed keys available
- No standing production access for personnel; break-glass requires a second approver and is recorded in the customer-readable evidence chain
- Default-deny egress with per-session allowlists and pinned resolution
- Zero standing credentials in sandboxes; tokens minted per call and scoped
- SSO, SCIM, role-based access, and mandatory MFA for approver roles
- Continuous dependency scanning, quarterly external penetration testing, signed builds with SBOMs
- Documented incident response with defined severities and customer notification
07Subprocessors
You authorise the subprocessors listed on our subprocessors page. We impose data protection terms on each that are no less protective than this addendum, and we remain responsible for their performance.
We give 30 days' notice before adding or replacing a subprocessor. If you reasonably object on data protection grounds we will work with you on an alternative, and if none exists you may terminate the affected service with a pro-rata refund.
Air-gapped deployments have no subprocessors.
08International transfers
Where personal data leaves the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and a transfer impact assessment we will share on request.
Region pinning is available and enforced: a session pinned to an EU region does not schedule, snapshot, or log outside the EU.
09Data subject requests
If we receive a request directly from one of your data subjects we will not respond to it substantively, and will refer them to you and tell you within five business days. We will help you respond, including locating data through the evidence chain.
10Audits
We will provide our SOC 2 Type II report, ISO 27001 certificate, and penetration test summary on request. Enterprise customers may audit once a year on 30 days' notice, at their cost, under confidentiality, without disrupting other customers.
11Deletion and return
On termination you have 90 days to export. After that we delete or irreversibly anonymise personal data within 30 days, except where law requires retention, in which case we tell you what and why.
Evidence chains under legal hold are retained until you release the hold.
12Precedence
Where this addendum conflicts with the agreement, this addendum governs for personal data processing. Where it conflicts with the Standard Contractual Clauses, the Clauses govern.
Questions about this document: legal@velone.in