1. Parties and roles
The customer is the organization that controls a Vanteloq workspace. LexEdge Consulting, operating as Vanteloq, processes Customer Data to provide the service. Depending on the applicable law and activity, the customer may be the organization responsible for the information and Vanteloq may act as its service provider or processor. Each party remains responsible for obligations that apply directly to it.
2. Documented instructions and purpose
Vanteloq processes Customer Data only to provide, secure, support, maintain, and improve the contracted service; follow lawful workspace instructions; prevent misuse; and comply with law. The Terms of Service, product controls, connected service choices, support requests, and an applicable order are the customer's documented instructions.
The customer must have lawful authority for the information and instructions it provides. Vanteloq will notify the customer if an instruction appears unlawful unless law prohibits notice.
3. Processing details
- People: workspace users, customer contacts, suppliers, employees, and other individuals represented in business records selected by the customer.
- Information: account, contact, commerce, payment reference, inventory, purchasing, financial, document, operational, support, security, and integration information described in the Privacy Policy.
- Activities: hosting, authentication, importing, organization, reconciliation, calculation, reporting, storage, support, security, deletion, and customer-directed connected service processing.
- Duration: the customer's use of Vanteloq and the limited retention period described in the Privacy Policy and applicable order.
The customer must not submit sensitive personal information that is unnecessary for these purposes or use Vanteloq for high risk decisions about an individual unless a written order expressly authorizes that processing.
4. Confidentiality and safeguards
People authorized to process Customer Data are subject to confidentiality obligations and receive access according to their duties. Vanteloq maintains technical and organizational safeguards appropriate to the information, including authenticated access, multifactor authentication for protected functions, organization scoped authorization, encrypted transport, managed encryption at rest, application level encryption for supported provider credentials, secrets kept outside source code and browser responses, logging controls, change review, and incident response procedures.
5. Subprocessors and connected services
The customer authorizes the subprocessors listed in the Subprocessor and Connected Service Notice. Vanteloq requires subprocessors to protect personal information through appropriate contractual obligations. Vanteloq remains responsible for its own obligations when a subprocessor performs processing on its behalf.
Vanteloq may update that list to operate or improve the service. A customer may object to a new subprocessor on reasonable data protection grounds by using our private contact form promptly after notice. The parties will work in good faith on a reasonable solution; if none is available, the affected feature or service may be ended.
6. Processing outside Canada
Customer Data may be processed outside Canada where a listed provider operates. Vanteloq uses contractual, technical, and organizational safeguards appropriate to the service and will provide available information about relevant locations and safeguards on request. Where an applicable law requires a specific transfer mechanism, the parties will cooperate to put that mechanism in place.
7. Individual requests and compliance assistance
Taking account of the nature of the processing, Vanteloq will provide reasonable assistance so the customer can respond to verified requests for access, correction, deletion, or consent withdrawal. If Vanteloq receives a request about Customer Data controlled by the customer, Vanteloq may direct the requester to that customer unless law requires a direct response.
Vanteloq will also provide reasonable information needed for the customer's privacy assessments, regulator inquiries, and compliance obligations, subject to confidentiality, security, proportionality, and the protection of other customers.
8. Security incidents
Vanteloq will investigate a confirmed unauthorized access, use, disclosure, alteration, loss, or destruction of Customer Data. It will notify the affected customer without undue delay when the incident affects Customer Data and notice is required or reasonably needed for the customer to meet its obligations. Notice will include available information about the nature, affected data, likely consequences, containment, and remediation. Notice is not an admission of fault.
9. Return, deletion, and retention
Available controls let authorized users export records, disconnect services, delete scoped information, remove their account, or let an owner delete the workspace. A verified workspace deletion cancels the Vanteloq Stripe subscription before removing active workspace data, files, local integration credentials and memberships. The requesting person's sign-in identity is removed only when it is not needed by another workspace or separate service. Other members' independent identities are preserved. Interrupted cleanup remains pending until completion is confirmed.
Vanteloq may retain information required by law, a documented legal hold, security need, or the customer's recordkeeping instruction. Such information is protected and deleted or anonymized when the reason ends. A pseudonymous deletion receipt may be retained for 24 months. Processing records and retry-session handling are described in the Privacy Policy. Provider records retained independently under a provider's agreement or law are controlled by that provider.
10. Review and contact
On reasonable written request, Vanteloq will provide available policies, test summaries, or other evidence relevant to this addendum. Any audit must avoid unreasonable disruption and exposure of another customer's information or protected security details. Questions and requests can be sent through our private contact form.
™