Draft, pending legal review
This document has not yet been reviewed by counsel and is not offered for signature. If you need an executed DPA now, email [email protected] and we will handle it directly.
Data Processing Agreement
Draft of August 5, 2026
1. Roles
Where you submit personal data relating to other people (for example the records of a company you are valuing, or the details of your colleagues), you are the controller and Felpel Ventures LLC d/b/a Value Alpha is your processor. Where we decide our own purposes, such as billing you or securing the Service, we act as an independent controller and the Privacy Policy governs instead.
2. Scope and instructions
We process customer personal data only to provide the Service and only on your documented instructions, which your use of the Service constitutes. We tell you if an instruction appears to breach applicable data-protection law. We do not sell customer personal data and we do not use it to train machine-learning models.
3. Subject matter, duration, nature and purpose
- Subject matter: provision of business-valuation software.
- Duration: for as long as your account is active, plus the retention periods in the Privacy Policy.
- Categories of data subject: your personnel, and natural persons named in the financial or corporate records you upload.
- Categories of personal data: names, business contact details, roles and shareholdings, and any personal data contained in documents you upload.
- Special categories: none requested; do not upload them.
4. Confidentiality
Everyone we authorise to process customer personal data is bound by confidentiality obligations and is granted access only where needed.
5. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, row-level access controls that isolate each customer’s data, least-privilege administrative access, audit logging of privileged actions, and backups. We do not run session replay inside the authenticated application.
6. Subprocessors
You give general authorisation for the subprocessors listed at valuealpha.ai/subprocessors. We impose data-protection obligations on each of them no less protective than those in this Agreement, and we remain liable for their performance. We update that page before a new subprocessor starts, and you may object on reasonable data-protection grounds.
7. Assisting you
Taking into account the nature of the processing, we assist you with data-subject requests, security, breach notification, data-protection impact assessments and prior consultation. If a data subject contacts us directly about data you control, we refer them to you rather than acting on it ourselves.
8. Personal data breaches
We notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting customer personal data, with the information available to us at the time and updates as the picture develops.
9. Deletion and return
On termination, or on request, we delete customer personal data within 30 days, except where retention is required by law. Encrypted backups may persist for up to 35 days after the corresponding production record is deleted, and remain subject to this Agreement until they expire. Export is available at any time from your account settings.
10. Audits
We make available the information needed to demonstrate compliance and will respond to reasonable written security questionnaires no more than once a year, or after a breach affecting your data.
11. International transfers
We are established in the United States. Where you are in the EEA or the UK, transfers rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies. Those clauses are incorporated by reference and prevail over this Agreement in the event of conflict.
12. Order of precedence
This Agreement forms part of the Terms of Service. Where they conflict on the processing of personal data, this Agreement prevails.