Skip to main content

Legal

Data Processing Addendum

Last updated: July 25, 2026 · VendorCAD · VendorCAD

1. Parties and incorporation

This Data Processing Addendum (“DPA”) forms part of the agreement between VendorCAD (“Processor,” “we”) and the customer entity that subscribes to VendorCAD (“Controller,” “you”) under the Terms of Service, Order Form, or SOW (the “Agreement”).

If you require a signed PDF DPA for procurement, email us and we will provide a countersignable version. This online DPA applies when incorporated by reference or accepted as part of onboarding.

2. Roles

For Customer Content (tenant data, CAD-related inputs, configurations, exports metadata, buyer quote submissions collected via your published experiences, and related logs), you are the controller (or a processor for your own customers) and we are the processor.

For our own account, billing, website analytics (as controller), and marketing lead data submitted directly to us, we act as an independent controller as described in the Privacy Policy.

3. Processing instructions

We will process Customer Personal Data only: (a) to provide the Service; (b) per your documented instructions in the Agreement and product configuration; and (c) as required by law (in which case we will notify you unless legally prohibited).

You instruct us to process Customer Personal Data for hosting, transmission, storage, security, backup, support (when you open a ticket), and features you enable (including share links and quote delivery).

4. Details of processing

Subject matter: provision of VendorCAD. Duration: term of the Agreement plus deletion/return period. Nature: collection, storage, retrieval, transmission, erasure. Purpose: operate multi-tenant configure-to-order SaaS.

  • Data subjects: your employees/contractors; buyers or sales contacts who use your published configurators; other individuals whose data you choose to upload.
  • Categories of data: identity and contact data; commercial inquiry data; technical logs; product configuration data; optional CAD identifiers you supply. We do not seek special-category data; you must not upload it unless we agree in writing.

5. Security

We implement appropriate technical and organizational measures, including access controls, encryption in transit, password hashing, tenant isolation controls, and monitoring proportionate to the Service. Details may be provided under NDA for security reviews.

6. Confidentiality of personnel

Personnel authorized to process Customer Personal Data are bound by confidentiality obligations.

7. Subprocessors

You authorize us to engage subprocessors listed on our Subprocessors page. We will impose data-protection obligations no less protective than this DPA. We remain responsible for subprocessors’ performance.

We will post material subprocessor changes on that page and, for enterprise customers who subscribe to notices, email advance notice when practicable so you may object on reasonable grounds related to data protection.

8. Data subject rights and assistance

Taking into account the nature of processing, we will assist you with data subject requests, DPIAs, and consultations with supervisory authorities by providing self-serve tools where available and reasonable cooperation for the remainder.

9. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to help you meet notification obligations.

10. Return and deletion

Upon termination, at your choice we will delete or return Customer Personal Data (excluding archived backups retained for a limited period under security policies, which are then deleted), unless law requires retention.

11. Audits

Upon reasonable written request no more than once annually (unless a breach or regulator requires more), we will provide security documentation and, where needed, allow an audit under confidentiality, during business hours, without disrupting operations. You may use a mutually agreed independent auditor.

12. International transfers

Where Customer Personal Data is transferred from the EEA/UK/Switzerland to a country without an adequacy decision, the parties will rely on Standard Contractual Clauses (and UK/Swiss addenda as applicable) or another lawful transfer mechanism. SCCs are incorporated by reference upon request for covered transfers.

13. Liability

Liability under this DPA is subject to the limitations in the Agreement, except where prohibited by applicable data-protection law.

14. Contact

Privacy / DPA requests: contact@vendorcad.com.

These documents are provided for transparency and operational compliance. For signed enterprise paper (DPA, security questionnaire, or custom terms), contact contact@vendorcad.com.