# Clavenar Data Processing Addendum

Version 1.0.0 · Vanteguard Labs LLC

This Data Processing Addendum (“DPA”) applies when an executed Order Form
incorporates version 1.0.0 and Vanteguard Labs LLC processes personal data for
Customer. “Data Protection Law” means the privacy and data-protection law
applicable to that processing. Terms such as controller, processor, data
subject, and personal data have the meanings in applicable law.

## 1. Roles, scope, and instructions

The Order Form identifies whether Customer is controller and Vanteguard is
processor, or Customer is processor and Vanteguard is subprocessor. Customer
controls the purposes and lawful instructions. Vanteguard will process
Customer Personal Data only to provide, secure, support, and delete the
services under the agreement, on documented Customer instructions, or as
required by law after notice when lawful.

The subject matter, duration, nature, purpose, data subjects, and data
categories are in Annex I below and the completed Order Form. Customer is
responsible for lawful instructions, notices, legal bases, and required
consents. Vanteguard will promptly inform Customer if an instruction appears
to violate Data Protection Law and may pause the affected processing while the
parties resolve it.

## 2. Personnel and confidentiality

Vanteguard will limit access to authorized personnel with a need to know,
binding confidentiality duties, and appropriate security and privacy training.
Access is removed when no longer needed and reviewed periodically.

## 3. Security

Vanteguard will maintain the technical and organizational measures in the
Security and Data Schedule. It will not materially reduce those measures
during an active Order Form. Customer acknowledges that secure configuration,
least-privilege customer access, supported clients, and the
customer-controlled secure exchange are shared responsibilities.

## 4. Subprocessors

Customer gives general written authorization for the subprocessors listed in
the current processor inventory incorporated by the Order Form. Vanteguard
will impose data-protection duties no less protective than this DPA, remain
responsible for their performance to the extent required by law, and give at
least thirty days’ notice before a new subprocessor processes Customer
Personal Data. Customer may object on reasonable data-protection grounds
during that period. The parties will seek a reasonable alternative; if none is
available, either party may terminate only the affected service with a
pro-rata refund of prepaid unused fees.

## 5. Data-subject and regulatory assistance

Taking account of the processing and information available, Vanteguard will
reasonably assist Customer with data-subject requests, security obligations,
impact assessments, consultations, and regulator inquiries. Vanteguard will
not respond directly for Customer unless instructed or legally required.
Customer will reimburse reasonable extraordinary assistance agreed in
advance, except where caused by Vanteguard’s breach.

## 6. Personal-data incidents

Vanteguard will notify Customer without undue delay after confirming a breach
of security leading to accidental or unlawful destruction, loss, alteration,
unauthorized disclosure of, or access to Customer Personal Data. The initial
notice will provide known nature, affected data and subjects, likely
consequences, mitigation, and a response contact, with updates as facts become
available. Notice is not an admission of fault. The Security and Data Schedule
defines operational targets and coordinated communications.

## 7. Return, deletion, and evidence

On Customer’s verified request or termination, Vanteguard will return
Customer Personal Data in an agreed supported format or delete it, then delete
remaining active copies within thirty days unless law requires retention.
Customer-controlled source copies and private keys remain Customer’s
responsibility. Restores enforce current tenant-erasure dispositions before
workload access; encrypted backup objects age out under the Order Form’s
retention schedule, which must not exceed 180 days absent a documented legal
hold. Vanteguard may retain minimized commitments, security evidence, billing
records, and legal records that do not permit reconstruction of deleted
Customer content.

## 8. Demonstration and audit

Vanteguard will make available information reasonably necessary to demonstrate
compliance, including the Procurement Response, Security and Data Schedule,
independent reports if available, and scoped evidence under confidentiality.
No certification is implied. No more than annually, unless required by a
regulator or a material incident, Customer may request a reasonable remote
audit. On-site work requires advance agreement, protects other customers and
security, avoids production disruption, and is at Customer’s cost unless it
finds a material Vanteguard breach.

## 9. International transfers

Neither party will make a restricted transfer without a lawful mechanism. When
selected in the Order Form, the SCC Election incorporates the official
European Commission clauses and completed appendices. For a UK restricted
transfer, the parties must attach and complete the then-current official ICO
Addendum or another valid mechanism. The exporter remains responsible for any
required transfer assessment; Vanteguard will provide reasonably available
information and agreed supplementary measures.

## 10. Conflict and termination

This DPA controls a conflict about processing Customer Personal Data. The
official SCCs or mandatory transfer instrument controls to the extent required
for the relevant transfer. A material DPA breach is a material MSA breach.

## Annex I — processing description

| Item | Default; completed Order Form controls |
|---|---|
| Subject matter | Governance, policy, approval, identity, evidence, support, and security processing for the selected Clavenar service |
| Duration | Active Order Form plus bounded return, deletion, security, and legal retention |
| Nature and purpose | Receive authorized requests; enforce policy; obtain approvals; execute permitted actions; produce audit/security evidence; support and secure the service |
| Data subjects | Customer workforce, contractors, authorized users, and people represented in Customer-authorized agent inputs |
| Personal-data categories | Business identity/contact, tenant/account identifiers, authorization and security metadata, customer-selected payloads, and support correspondence |
| Special or regulated data | Prohibited unless expressly listed and protected in the Order Form |
| Frequency | As initiated by Customer and its authorized workloads |

## Annex II — security measures

The incorporated Security and Data Schedule version 1.0.0 is Annex II.

## Annex III — subprocessors

The executed Order Form must identify the reviewed processor inventory version
and any customer-specific subprocessors before production approval.
