
You are controller
End User data in VartaDesk is processed on your instructions.
The roles, responsibilities, and safeguards that apply when VartaDesk processes personal data on your behalf as your data processor.
This Data Processing Addendum (DPA) is a summary and overview of our data processing practices. For enterprise customers requiring a fully executed DPA with custom terms, please contact us at info@sevendmobility.com.
At a glance

You are controller
End User data in VartaDesk is processed on your instructions.

We are processor
We do not use that data to market our own products to your customers.

Sub-processors
Hosting and messaging vendors we use are listed separately.
This Data Processing Addendum (“DPA”) supplements the VartaDesk Terms of Service and Privacy Policy. It describes the roles, responsibilities, and safeguards applicable when SevenD Mobility Solutions LLC (“VartaDesk,” “we,” or “Processor”) processes personal data on behalf of our customers (“Controller”) in the provision of the VartaDesk platform.
This DPA is designed to meet the requirements of the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.

As the Controller, you are responsible for:
As the Processor, VartaDesk will:
You authorize VartaDesk to engage third-party Sub-Processors to process Personal Data on your behalf, provided that VartaDesk:
VartaDesk currently engages the following categories of Sub-Processors to deliver the Service:
The named list is on our Sub-processors page.
We will notify you of any intended changes to Sub-Processors (new Sub-Processors or replacement of existing Sub-Processors) at least 30 days in advance. If you object to a new Sub-Processor on reasonable data protection grounds, you may terminate your subscription without penalty, provided you notify us within 30 days of the change notice.
Data Subjects (your End Users) have the right to access, correct, delete, restrict, or port their Personal Data, and to object to or withdraw consent for processing, as applicable under data protection laws.
As the Controller, you are responsible for responding to Data Subject requests. VartaDesk will provide reasonable assistance (e.g., by providing tools to export or delete data) upon your request, to the extent feasible and in accordance with applicable law. If we receive a Data Subject request directly, we will forward it to you without undue delay.
VartaDesk implements industry-standard technical and organizational security measures to protect Personal Data, including:
The specific measures implemented are appropriate to the risk presented by the processing and the nature of the Personal Data being processed. See our Security page for more detail.
In the event of a personal data breach affecting Personal Data processed on your behalf, VartaDesk will:
You remain responsible for determining whether the breach must be reported to data protection authorities or Data Subjects under applicable law.
VartaDesk is operated from the United States, and Personal Data may be transferred to, stored, and processed in the U.S. or other countries where our Sub-Processors operate. To the extent that Personal Data is transferred from the European Economic Area (EEA), United Kingdom (UK), or other jurisdictions with data localization or transfer restrictions, VartaDesk will implement appropriate safeguards, such as:
Upon request, we will provide a copy of the applicable data transfer mechanism in effect.
VartaDesk will retain Personal Data only for as long as necessary to provide the Service or as instructed by you. You control the retention of Customer Data and may delete it at any time via the VartaDesk platform.
Upon termination or expiration of your subscription, VartaDesk will delete or return all Personal Data within a reasonable period (typically 30–90 days), unless:
Upon reasonable written notice (and no more than once per year, unless required by a data protection authority or in response to a suspected breach), you may request information or documentation to verify VartaDesk's compliance with this DPA. We will provide reasonable cooperation, including access to relevant records, security reports, or compliance certifications.
For large-scale enterprise customers, we may accommodate on-site audits or third-party audits subject to mutual agreement on scope, timing, and confidentiality terms.
Each party's liability under this DPA is subject to the limitation of liability provisions set forth in the VartaDesk Terms of Service.
This DPA is governed by the laws of the State of Delaware, United States, except where data protection laws require otherwise (e.g., GDPR-specific provisions are governed by EU law as applicable).
We may update this DPA from time to time to reflect changes in legal requirements, our practices, or Sub-Processors. Material changes will be communicated to you via email or account notification, and the updated DPA will be posted on this page with a revised “Last updated” date.
For questions about this DPA, data processing practices, or to request a fully executed custom DPA (for enterprise customers), please contact us:
SevenD Mobility Solutions LLCSee also: Sub-processors and Security.