Legal
Data Processing Addendum
This DPA governs Virali's processing of personal data on behalf of a Customer and includes a security and subprocessor schedule.
Publication date: August 25, 2026 · Version 2026.08.31
1. Scope and incorporation
This Data Processing Addendum (“DPA”) forms part of the Virali Terms of Service, an order form, or another written agreement that references it (the “Agreement”) between the Customer identified in the Agreement (“Customer”) and Life Development LLC, doing business as Virali (“Virali”). It applies only to Virali's Processing of Customer Personal Data on Customer's behalf where Data Protection Law requires processor or service provider terms.
This DPA becomes effective when Customer accepts the Agreement or when both parties sign an order that references it. A signature is not otherwise required. If Customer needs a countersigned copy, it may contact support@tryvirali.com.
2. Definitions and roles
“Customer Personal Data” means personal data, personal information, or an equivalent term protected by Data Protection Law that Virali Processes on Customer's behalf through the Service. “Data Protection Law” means privacy, data-protection, and data-security laws applicable to the Processing, including, where applicable, the GDPR, UK GDPR, and U.S. state privacy laws. “GDPR” means Regulation (EU) 2016/679. “Process,” “Controller,” “Processor,” and “Data Subject” have the meanings given by applicable Data Protection Law. “Security Incident” means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
Customer is the Controller or business and Virali is the Processor, service provider, or contractor for Customer Personal Data. If Customer is itself a Processor, Virali is Customer's subprocessor. Each party will comply with the obligations that Data Protection Law assigns to its role.
3. Documented instructions and compliance
Virali will Process Customer Personal Data only on Customer's documented instructions, including as necessary to provide, secure, support, and improve the Service under the Agreement; prevent abuse; comply with law; and perform the activities in Schedule 1. The Agreement, Customer's use and configuration of the Service, support requests, and lawful written directions are documented instructions.
Virali will inform Customer if, in Virali's reasonable opinion, an instruction violates Data Protection Law, unless law prohibits notice. We may suspend the affected Processing until the parties resolve the issue. Customer is responsible for the lawfulness of its instructions, notices, lawful bases, Data Subject communications, and the accuracy and minimization of Customer Personal Data.
U.S. service-provider commitments
To the extent U.S. state privacy law applies, Virali will not: sell or share Customer Personal Data; retain, use, or disclose it outside the specific business purposes in the Agreement or as otherwise permitted by law; retain, use, or disclose it outside the direct business relationship with Customer; or combine it with personal information received from another person except as legally permitted to perform the Service. Virali will notify Customer if it determines it can no longer meet these obligations. Customer may take reasonable and appropriate steps to verify and remediate compliance as set out in Section 11.
4. Confidentiality and personnel
Virali will limit access to Customer Personal Data to personnel and contractors who need access to perform the Agreement. They will be subject to appropriate confidentiality obligations and receive privacy and security direction appropriate to their responsibilities. Virali remains responsible for their compliance with this DPA.
5. Security measures
Taking into account the state of the art, implementation cost, and the nature, scope, context, and purposes of Processing and risk to individuals, Virali will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Personal Data. Current measures are described in Schedule 2.
Customer is responsible for securely configuring the Service, managing Authorized Users and permissions, protecting credentials and endpoints, reviewing integrations, and using available security controls. Customer acknowledges that no security program eliminates all risk.
6. Security incidents
Virali becomes aware when designated security or privacy personnel have a reasonable degree of certainty that a Security Incident occurred. Virali will notify Customer without undue delay and within any shorter period required by applicable law. Notification will include, to the extent known and legally permitted, the nature of the incident, affected data and individuals, likely consequences, mitigation taken or proposed, and a contact for follow-up. Virali may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the incident.
Notification is not an admission of fault or liability. Customer is responsible for determining whether to notify regulators, Data Subjects, or others, and Virali will provide reasonable assistance considering the nature of Processing and available information. Unsuccessful attempts or events that do not compromise Customer Personal Data—such as blocked scans, failed login attempts, and denial-of-service attempts—are not Security Incidents.
7. Data Subject requests and compliance assistance
Taking into account the nature of Processing, Virali will provide reasonable assistance through available Service functionality and support so Customer can respond to verified requests to access, correct, delete, restrict, or export Customer Personal Data. If Virali receives a request directly and can identify Customer, Virali will direct the requester to Customer unless law requires otherwise.
Virali will also provide reasonable information available to it to assist Customer with security, breach, data-protection impact assessment, and prior consultation obligations applicable to Customer's use of the Service. Assistance beyond standard functionality or documentation may be subject to reasonable fees and a mutually agreed scope, except where the need results from Virali's breach of this DPA.
8. Subprocessors
Customer gives Virali general written authorization to use the subprocessors in Schedule 3 and to appoint replacements. Virali will impose data-protection obligations materially consistent with this DPA on each subprocessor to the extent it Processes Customer Personal Data and will remain responsible for the subprocessor's performance of those obligations.
Virali will post an updated subprocessor list and, for a new subprocessor that materially Processes Customer Personal Data, provide notice to the account owner's email at least 30 days before the new subprocessor begins Processing where reasonably practicable. Customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected Service, and Virali will refund prepaid fees for the unused terminated period. This is Customer's exclusive remedy for a subprocessor objection.
Customer-directed third-party services are not Virali subprocessors. Those services are engaged by Customer and governed by Customer's agreements with them, even when the Service facilitates a connection.
9. International transfers
Customer authorizes Processing in the United States and other locations where approved subprocessors operate. Restricted EEA transfers use, in order of availability, an applicable adequacy decision, Virali's verified Data Privacy Framework certification where available and applicable, or the European Commission Standard Contractual Clauses. Where the EU SCCs apply, the parties incorporate the European Commission Standard Contractual Clauses in Decision (EU) 2021/914 (“EU SCCs”) as follows: Module Two applies when Customer is a Controller and Virali is a Processor; Module Three applies when Customer is a Processor and Virali is a subprocessor; the optional docking clause applies; Option 2 and a 30-day notice period apply in Clause 9; the optional language in Clause 11 does not apply; the governing law and courts will be those of Ireland; and Schedules 1 through 3 complete the applicable annexes. Where required, the parties will complete the applicable transfer assessment and implement supplementary safeguards appropriate to the transfer risk.
For restricted transfers subject to the UK GDPR, the parties use an applicable adequacy regulation, the then-current UK International Data Transfer Addendum to the EU SCCs, or the UK International Data Transfer Agreement, as appropriate, with this DPA completing required tables and the parties completing any required transfer assessment. For transfers subject to Swiss law, references in the EU SCCs will be adapted as legally required. If a conflicting lawful transfer mechanism is agreed in an order form, that mechanism controls.
10. Return and deletion
During the subscription term, Customer may use available export and deletion features. On termination and a verified request made within 30 days, Virali will provide a reasonable opportunity to export Customer Personal Data in a commonly used format where technically supported. Unless Customer requests export, Virali defaults to deletion. After the 30-day export period, Virali begins production deletion and completes active-system deletion within 30 additional days. A formal erasure instruction may override the normal export window.
Customer Personal Data may remain in backups until overwritten through the 30-day rolling backup schedule, during which it remains protected and isolated from ordinary use. Legally retained data remains isolated and is processed only for the applicable legal purpose. Virali will propagate applicable deletion instructions to subprocessors and, on reasonable written request, confirm completion of deletion subject to these exceptions.
11. Information and audits
Virali will make available information reasonably necessary to demonstrate compliance with this DPA, such as security summaries, relevant policies, and third-party reports that Virali is permitted to share. Customer must first review that information before requesting an audit.
If the information is insufficient and Data Protection Law requires an audit, Customer may conduct one audit per 12-month period on at least 30 days' notice, during normal business hours, through an independent auditor bound by confidentiality and not a Virali competitor. Audits must avoid disruption and must not access another customer's data, security testing details that create risk, or third-party confidential information. Customer bears audit costs unless the audit identifies a material breach by Virali. Additional audits are permitted after a material Security Incident or where a regulator legally requires them.
12. Liability, term, and conflict
This DPA remains in effect while Virali Processes Customer Personal Data. The limitations of liability, exclusions of damages, indemnities, and dispute terms in the Agreement apply to this DPA and all privacy, security, confidentiality, regulatory, and cyber-incident claims between the parties to the maximum extent permitted by law. Nothing in this DPA limits a Data Subject's rights or a regulator's authority.
If this DPA conflicts with the Agreement on Processing Customer Personal Data, this DPA controls. The EU SCCs control over conflicting terms for a transfer governed by them. All other Agreement terms remain effective.
Schedule 1 — Processing details
| Subject matter | Providing Virali's creator and influencer marketing operations platform, integrations, support, security, and related services. |
|---|---|
| Duration | The subscription term plus the deletion and backup periods described in this DPA. |
| Nature and purpose | Collection, recording, organization, storage, retrieval, consultation, analysis, synchronization, transmission, generation, support, security monitoring, export, and deletion as instructed by Customer. |
| Data subjects | Customer personnel and Authorized Users; creators, influencers, applicants, contractors, signers, and contacts; support contacts; and other individuals whose data Customer submits. |
| Personal data | Names, business contact details, social handles and public social content, onboarding answers, campaign and content records, communications, contracts and signature metadata, payout and transaction records, integration identifiers, account and device data, logs, and Customer-defined fields. |
| Sensitive data | The Service does not support protected health information or other regulated health data, full payment-card data, bank-account credentials, government-issued identifiers, biometric identifiers or templates, genetic data, precise geolocation, children's data, or other highly sensitive or specially regulated information. Customer must not submit that data unless Virali expressly agrees in a signed order and confirms that the applicable feature supports it. Limited business payout and contract information may be processed only through designated fields and with appropriate access controls. |
| Frequency | Continuous or as initiated by Customer during the subscription term. |
| Controller contact | The Customer account owner or contact identified in the order form or workspace. |
| Processor contact | Life Development LLC, 801 Spring Wood St, Thousand Oaks, CA 91320; support@tryvirali.com. |
Schedule 2 — Security measures
Virali's security program is designed to include:
- Access control: role-based access, scoped production roles, and tenant-aware server-side authorization.
- Authentication: provider-managed authentication, protected sessions, and administrative control over workspace membership.
- Tenant isolation: immutable organization identifiers, server-side authorization, database row-level security, and scoped runtime roles.
- Encryption: HTTPS/TLS for data in transit; provider-supported encryption at rest; and authenticated encryption for supported stored integration credentials.
- Secrets: provider-managed secret storage, restrictions against client exposure and logging, and documented rotation procedures.
- Logging and monitoring: application and security logs, synthetic health monitoring, and audit records for sensitive administrative actions where supported.
- Resilience: provider backup capabilities, documented encrypted logical-backup procedures, recovery documentation, and incident and rollback runbooks.
- Secure development: automated testing, dependency and secret scanning, environment separation, and documented production deployment procedures.
- Incident response: documented triage, containment, evidence preservation, credential rotation, tenant-isolation response, provider escalation, and recovery procedures.
- Vendor management: a maintained provider inventory and documented review requirements for providers that Process Customer Personal Data.
- Data handling: retention and deletion procedures, restricted production access, and prohibition on using production data in unsecured environments.
Virali may update safeguards as technology and risks evolve, provided the overall level of protection is not materially reduced during a subscription term.
Schedule 3 — Authorized subprocessors
| Provider | Purpose | Data involved | Status |
|---|---|---|---|
| Render | Application hosting, runtime, CDN, and operational logging | Customer workspace data, account data, request and application logs, configuration metadata | Active |
| Supabase | Database, authentication, file storage, and backups | Customer Personal Data stored in the Service, authentication data, files, logs, and backups | Active |
| Resend or configured email provider | Transactional and account email delivery | Email addresses, message content selected by Customer or Virali, and delivery metadata | When configured |
| Bright Data | Customer-directed public creator and social-content analytics workflows | Public profile or content URLs, public social data, and provider job metadata | When enabled |
| Google APIs / Gmail | User-authorized email sending, reply synchronization, and connected-account functionality | Connected mailbox identity, OAuth credentials, and message/thread content and metadata used for the enabled workflow | When connected by Customer |
| OpenAI API | Customer-enabled AI drafting, classification, and workflow assistance | Minimum relevant creator, campaign, prospect, or conversation context for the requested output | When AI features are enabled |
| Stripe | Subscription checkout, payment processing, invoicing, and billing portal | Billing contact and transaction data; payment details are collected directly by Stripe | When paid billing is enabled |
| GitHub | Source control, deployment integration, and limited operational evidence | Operational metadata; Customer Content is not intentionally stored in source control | Active |