artaDeskConversation OS
ProductSolutionsPricingResourcesBlog
Start free
← Back to VartaDesk

Data Processing Addendum

The roles, responsibilities, and safeguards that apply when VartaDesk processes personal data on your behalf as your data processor.

Last updated: July 2026

This Data Processing Addendum (DPA) is a summary and overview of our data processing practices. For enterprise customers requiring a fully executed DPA with custom terms, please contact us at info@sevendmobility.com.

Contract pages — the DPA is the processor agreement for your customer data

At a glance

People records

You are controller

End User data in VartaDesk is processed on your instructions.

Careful work

We are processor

We do not use that data to market our own products to your customers.

Handshake

Sub-processors

Hosting and messaging vendors we use are listed separately.

On this page
  • 1. Introduction
  • 2. Definitions
  • 3. Scope and Roles
  • 4. Sub-Processors
  • 5. Data Subject Rights
  • 6. Data Security
  • 7. Data Breach Notification
  • 8. International Data Transfers
  • 9. Data Retention and Deletion
  • 10. Audit Rights
  • 11. Limitation of Liability
  • 12. Governing Law
  • 13. Changes to This DPA
  • 14. Contact Us

On this page

  • 1. Introduction
  • 2. Definitions
  • 3. Scope and Roles
  • 4. Sub-Processors
  • 5. Data Subject Rights
  • 6. Data Security
  • 7. Data Breach Notification
  • 8. International Data Transfers
  • 9. Data Retention and Deletion
  • 10. Audit Rights
  • 11. Limitation of Liability
  • 12. Governing Law
  • 13. Changes to This DPA
  • 14. Contact Us

1.Introduction#

This Data Processing Addendum (“DPA”) supplements the VartaDesk Terms of Service and Privacy Policy. It describes the roles, responsibilities, and safeguards applicable when SevenD Mobility Solutions LLC (“VartaDesk,” “we,” or “Processor”) processes personal data on behalf of our customers (“Controller”) in the provision of the VartaDesk platform.

This DPA is designed to meet the requirements of the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.

Team discussion
Need a signed DPA for a security review? Use the contact details at the bottom of this page.

2.Definitions#

  • “Personal Data”means any information relating to an identified or identifiable natural person (a “Data Subject”), including but not limited to names, email addresses, phone numbers, contact information, and message content processed by the Controller through the VartaDesk platform.
  • “Processing” means any operation performed on Personal Data, including collection, storage, transmission, retrieval, use, disclosure, and deletion.
  • “Controller” means the Customer (you) who determines the purposes and means of processing Personal Data.
  • “Processor” means VartaDesk, which processes Personal Data on behalf of the Controller.
  • “Sub-Processor” means a third-party service provider engaged by VartaDesk to process Personal Data on behalf of the Controller.

3.Scope and Roles#

3.1. Controller Responsibilities

As the Controller, you are responsible for:

  • Determining the lawful basis for processing Personal Data and ensuring that you have obtained all necessary consents, authorizations, and disclosures from Data Subjects.
  • Complying with all applicable data protection laws (including GDPR, CCPA, and other regulations) in your collection and use of Personal Data.
  • Providing clear privacy notices to Data Subjects explaining how their Personal Data is collected, used, and shared.
  • Responding to Data Subject requests (e.g., access, deletion, correction) and cooperating with data protection authorities as required by law.

3.2. Processor Responsibilities (VartaDesk)

As the Processor, VartaDesk will:

  • Process Personal Data only on your documented instructions (as set forth in your use of the VartaDesk platform and these Terms) and for the purpose of providing the Service.
  • Implement appropriate technical and organizational measures to protect Personal Data from unauthorized access, disclosure, alteration, and destruction.
  • Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.
  • Assist you in responding to Data Subject requests as reasonably required.
  • Notify you without undue delay upon becoming aware of a personal data breach affecting Personal Data processed on your behalf.
  • Delete or return Personal Data upon termination of the Service, unless retention is required by law.
  • Make available to you information necessary to demonstrate compliance with data protection obligations.

4.Sub-Processors#

4.1. Authorization

You authorize VartaDesk to engage third-party Sub-Processors to process Personal Data on your behalf, provided that VartaDesk:

  • Enters into a written agreement with each Sub-Processor imposing data protection obligations no less protective than those in this DPA.
  • Remains fully liable to you for the performance of each Sub-Processor's obligations.

4.2. List of Sub-Processors

VartaDesk currently engages the following categories of Sub-Processors to deliver the Service:

  • Object storage: Amazon Web Services (Amazon S3) for customer-uploaded documents and media.
  • Messaging service providers: Meta Platforms (WhatsApp Business Platform), AiSensy, Fast2SMS, and Twilio, when you connect the matching channel.
  • AI providers: OpenAI and Anthropic when you enable AI features.
  • Payment processors: Razorpay, and Stripe when that gateway is enabled.
  • Website analytics: Google Analytics 4 when you connect the Website pulse pack.

The named list is on our Sub-processors page.

4.3. Sub-Processor Changes

We will notify you of any intended changes to Sub-Processors (new Sub-Processors or replacement of existing Sub-Processors) at least 30 days in advance. If you object to a new Sub-Processor on reasonable data protection grounds, you may terminate your subscription without penalty, provided you notify us within 30 days of the change notice.

5.Data Subject Rights#

Data Subjects (your End Users) have the right to access, correct, delete, restrict, or port their Personal Data, and to object to or withdraw consent for processing, as applicable under data protection laws.

As the Controller, you are responsible for responding to Data Subject requests. VartaDesk will provide reasonable assistance (e.g., by providing tools to export or delete data) upon your request, to the extent feasible and in accordance with applicable law. If we receive a Data Subject request directly, we will forward it to you without undue delay.

6.Data Security#

VartaDesk implements industry-standard technical and organizational security measures to protect Personal Data, including:

  • Encryption: Encryption of Personal Data in transit (TLS/SSL) and at rest (database-level encryption).
  • Access controls: Role-based access control (RBAC), multi-factor authentication (MFA), and least-privilege access principles.
  • Monitoring and logging: Continuous monitoring for security threats, audit logging, and intrusion detection.
  • Incident response: A documented incident response plan for detecting, investigating, and mitigating security breaches.
  • Regular assessments: Periodic security reviews, vulnerability scans, and penetration testing.
  • Staff training: Security awareness and data protection training for all personnel with access to Personal Data.

The specific measures implemented are appropriate to the risk presented by the processing and the nature of the Personal Data being processed. See our Security page for more detail.

7.Data Breach Notification#

In the event of a personal data breach affecting Personal Data processed on your behalf, VartaDesk will:

  • Notify you without undue delay (and in any event within 72 hours of becoming aware of the breach, where feasible).
  • Provide reasonable information about the nature of the breach, the categories and approximate number of Data Subjects affected, and the measures taken or proposed to address the breach.
  • Cooperate with you in investigating the breach and mitigating its effects, as reasonably required.

You remain responsible for determining whether the breach must be reported to data protection authorities or Data Subjects under applicable law.

8.International Data Transfers#

VartaDesk is operated from the United States, and Personal Data may be transferred to, stored, and processed in the U.S. or other countries where our Sub-Processors operate. To the extent that Personal Data is transferred from the European Economic Area (EEA), United Kingdom (UK), or other jurisdictions with data localization or transfer restrictions, VartaDesk will implement appropriate safeguards, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent authorities.
  • Reliance on adequacy decisions (where applicable) or other legally recognized transfer mechanisms.

Upon request, we will provide a copy of the applicable data transfer mechanism in effect.

9.Data Retention and Deletion#

VartaDesk will retain Personal Data only for as long as necessary to provide the Service or as instructed by you. You control the retention of Customer Data and may delete it at any time via the VartaDesk platform.

Upon termination or expiration of your subscription, VartaDesk will delete or return all Personal Data within a reasonable period (typically 30–90 days), unless:

  • You request earlier deletion or extended retention.
  • Retention is required by applicable law or regulation.

10.Audit Rights#

Upon reasonable written notice (and no more than once per year, unless required by a data protection authority or in response to a suspected breach), you may request information or documentation to verify VartaDesk's compliance with this DPA. We will provide reasonable cooperation, including access to relevant records, security reports, or compliance certifications.

For large-scale enterprise customers, we may accommodate on-site audits or third-party audits subject to mutual agreement on scope, timing, and confidentiality terms.

11.Limitation of Liability#

Each party's liability under this DPA is subject to the limitation of liability provisions set forth in the VartaDesk Terms of Service.

12.Governing Law#

This DPA is governed by the laws of the State of Delaware, United States, except where data protection laws require otherwise (e.g., GDPR-specific provisions are governed by EU law as applicable).

13.Changes to This DPA#

We may update this DPA from time to time to reflect changes in legal requirements, our practices, or Sub-Processors. Material changes will be communicated to you via email or account notification, and the updated DPA will be posted on this page with a revised “Last updated” date.

14.Contact Us#

For questions about this DPA, data processing practices, or to request a fully executed custom DPA (for enterprise customers), please contact us:

SevenD Mobility Solutions LLC
501 Silverside Road, Suite 105, #5140
Wilmington, DE 19809, USA
Email: info@sevendmobility.com (Support) | info@sevendmobility.com (Enterprise DPA requests)
Phone: +1 (302) 590-0442

See also: Sub-processors and Security.

artaDeskConversation OS

VartaDesk is the conversation OS for WhatsApp, SMS, RCS and Email. One inbox, people, pipelines and journeys — with industry packs for the records you already run, and Insights that keep store downloads, ads spend and WhatsApp conversion as different questions.

Product

ProductSolutionsInsightsPricingHelp & GuidesHow it worksBlog

Company

AboutContactFAQSevenD DigitalStoreWatcher

Legal

Privacy PolicyTerms & ConditionsCookie PolicyAcceptable UseDPASecurityRefund PolicySub-processors

Part of the SevenD Mobility network

StoreWatcher — E-commerce Uptime & Incident Monitoring

© 2026 VartaDesk. Built for teams that ship.

A product by SevenD Digital · 501 Silverside Road, Suite 105, #5140, Wilmington, DE 19809, USA · +1 (302) 590-0442