Third Party Index

Snapshot 18816

Document
Data processing addendum
URL
https://www.salesvu.com/dpa/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
64394 bytes
SHA-256 (raw)
a93813ea1220605c52f56f62165044406f201d85e7ace95e526b5d83d29cb635
SHA-256 (normalized text)
c2dbb7c391b4727590924c0a35524eebbc096495d23c90443733637a1bdc0ae5

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Legal
Data Processing Agreement
Last updated: November 2025
On this page
Privacy PolicyCookie PolicyData Processing AgreementTrust Center
1. Definitions
'Customer' means the entity that has entered into the SalesVu Terms of Service or a master subscription agreement. 'Processor' means SalesVu, Inc.
'Personal Data', 'Data Subject', 'Controller', 'Processor', and 'Processing' have the meanings given in applicable Data Protection Laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA).
'Sub-processor' means any third party engaged by SalesVu to Process Personal Data on behalf of Customer.
2. Scope and Roles
This Data Processing Agreement ('DPA') applies to SalesVu's Processing of Personal Data on behalf of Customer in connection with the Services.
Customer is the Controller (or Processor on behalf of its own controllers) of Personal Data submitted to the Services. SalesVu acts as Processor (or Sub-processor) and Processes Personal Data only on Customer's documented instructions.
3. Customer Instructions
SalesVu will Process Personal Data only to provide and improve the Services as described in the Terms of Service, the SalesVu documentation, and the Customer's configuration of the Services (including AI agents Customer enables).
If SalesVu believes an instruction violates applicable Data Protection Laws, it will notify Customer without undue delay.
4. Customer Obligations
Customer represents that it has obtained all necessary consents and provided all required notices to enable lawful Processing of Personal Data through the Services, including for any AI agent that interacts with end customers (such as Customer Service or Recommendations).
5. Processor Obligations
SalesVu will (a) Process Personal Data only on documented instructions from Customer; (b) ensure persons authorized to Process Personal Data are bound by confidentiality; (c) implement the technical and organizational measures described in Annex II; and (d) assist Customer in responding to Data Subject requests and security incidents.
6. Sub-processors
Customer authorizes SalesVu to engage Sub-processors to Process Personal Data, subject to written agreements imposing data protection obligations no less protective than this DPA.
An up-to-date list of Sub-processors is maintained on the Trust Center at /trust. SalesVu will notify Customer of changes and provide a reasonable opportunity to object on legitimate data protection grounds.
7. International Data Transfers
Where Personal Data is transferred from the EEA, UK, or Switzerland to a country not deemed adequate, the parties incorporate the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor; Module 3: Processor-to-Processor) and the UK International Data Transfer Addendum, as applicable.
Customer agrees that the SCCs apply to the Processing described in Annex I of this DPA.
8. Security Measures
SalesVu maintains a written information security program designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Specific safeguards are described in Annex II.
9. Personal Data Breach Notification
SalesVu will notify Customer without undue delay (and in any event within 72 hours where feasible) after becoming aware of a Personal Data breach affecting Customer's Personal Data, and will provide information reasonably necessary to enable Customer to meet its own notification obligations.
10. Audits
SalesVu will make available to Customer information necessary to demonstrate compliance with this DPA, including by providing third-party audit reports such as SOC 2 (when available) or independent assessments.
Where required by Data Protection Laws, Customer may conduct, at its own cost and on reasonable advance notice, an audit of SalesVu's relevant Processing facilities, subject to confidentiality and security restrictions.
11. Data Subject Rights
Taking into account the nature of the Processing, SalesVu will provide reasonable assistance to Customer in responding to requests from Data Subjects to exercise their rights under applicable Data Protection Laws.
12. Return and Deletion of Personal Data
Within thirty (30) days following termination of the Services, SalesVu will, at Customer's option, return or delete Personal Data Processed under this DPA, unless retention is required by law.
13. Term and Termination
This DPA is effective for the duration of the Services and survives until SalesVu has returned or deleted all Personal Data in accordance with Section 12.
Annex I — Description of Processing
Categories of Data Subjects: Customer's end customers, employees, vendors, and other individuals whose Personal Data is submitted to the Services.
Categories of Personal Data: identifiers, contact details, transaction history, loyalty activity, reservations, communications, device and usage data, and any additional Personal Data Customer chooses to submit.
Nature and purpose of Processing: providing and improving the SalesVu commerce platform and AI agents (including Customer Service, Recommendations, Smart Upselling, Email Automation, Personal Rewards, Churn Prediction, and the Analyst Agent suite).
Duration: for the term of the Services and as required by Section 12.
Annex II — Technical and Organizational Measures
Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
Network segmentation, principle-of-least-privilege access controls, and multi-factor authentication for administrative access.
Continuous monitoring, logging, and alerting on production systems.
Secure software development lifecycle including code review, dependency scanning, and pre-release security testing.
Personnel security: background checks (where lawful), confidentiality obligations, and annual security and privacy training.
Business continuity and disaster recovery procedures, including regular backups and recovery testing.
Annex III — Authorized Sub-processors
The current list of authorized Sub-processors — including the entity, the Processing they perform, and their location — is maintained on the SalesVu Trust Center at /trust.
Need a signed DPA?
Enterprise customers can request a counter-signed DPA and security review through their account team.
Talk to salesTrust Center
Hi, how can we help you?
We use cookies to personalize content and analyze our website traffic. Additionally, we share information about your site usage with our analytics partners to improve performance and user experience. Additional details are available in our Cookie Policy.
Accept All Cookies Choose Cookies
Cookie Preferences
Privacy Preference Centre for cookies
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies.
Manage Consent Preferences
Strictly Necessary Cookies Always Active
These cookies are essential for the Website to function properly.
These cookies collect information about how visitors use the Website.
These cookies allow the Website to remember choices you make.
These cookies track browsing habits and are used to deliver relevant advertisements.