Data Processing Addendum
This Addendum forms part of the Terms of Service and governs Vallum's processing of personal data on your behalf when you use the hosted service. You are the controller of that data and Vallum is the processor. Where a signed data processing agreement exists between you and Vallum Security, Inc., that agreement controls.
Scope and roles
This Addendum applies to personal data contained in traffic Vallum processes for your protected domains, and to the console records created when your users administer the service. You determine the purposes and means of that processing. Vallum processes it only to provide, secure, and support the service, and only on your documented instructions — of which this Addendum and your configuration are the primary ones. Vallum acts as an independent controller for its own business records, such as billing, sales correspondence, and marketing subscriptions.
What Vallum processes
Vallum does not retain request or response payloads. Protected responses are transformed in memory and forwarded. What Vallum stores is metadata: session state in which the source address, user agent, and authenticated identity are held as keyed hashes rather than values; security telemetry describing route, method, hashed request path, response status, latency, and risk; policy and domain configuration you author; and an audit trail with hashed actors. Console identity, meaning names, work email addresses, and organization membership, is held by our identity provider. The complete inventory, including the form each item takes at rest and how long it is kept, is published on the Data retention page and is incorporated here by reference.
Instructions and legal compliance
Vallum will not process personal data for any purpose other than providing the service, and will not sell it, share it for cross-context behavioural advertising, or use it to train models. If Vallum believes an instruction from you infringes applicable data protection law, it will inform you and may pause the affected processing. If law requires Vallum to process data beyond your instructions, Vallum will tell you before doing so unless that law prohibits the notice.
Confidentiality and personnel
Access to customer data is limited to personnel who need it to operate or support the service, is bound by confidentiality obligations that survive employment, and is granted on the least privilege required for the task. Administrative access is authenticated, logged in the audit trail, and reviewed.
Security measures
Vallum maintains technical and organizational measures appropriate to the risk, including encryption in transit, keyed hashing of session fingerprints so identifying values are not stored in recoverable form, tenant isolation enforced at the routing layer, secrets held outside the database as environment or secret-store references, least-privilege administrative access, and an auditable record of configuration changes. Measures evolve as the service does; Vallum will not materially reduce the overall level of security during your subscription.
Subprocessors
You authorize Vallum to engage the subprocessors listed on the Service providers page, which identifies each one, what it supplies, the region in which it operates, and the categories of data it handles. Vallum imposes data protection obligations on each subprocessor no less protective than this Addendum and remains responsible for their performance. Vallum will give at least thirty days' notice before a new subprocessor begins processing your data. You may object on reasonable data protection grounds within that period, and if the objection cannot be resolved you may terminate the affected service without penalty for the remainder of the prepaid term.
Data subject requests
The service is designed so that most requests can be satisfied without Vallum's involvement: the console exposes deletion and export for an application's history, and identifying values are stored as keyed hashes rather than values. Where a data subject contacts Vallum directly, Vallum will refer them to you unless legally required to respond. Where you need assistance that the console cannot provide, Vallum will give reasonable cooperation, taking into account the nature of the processing.
Personal data breach
Vallum will notify you without undue delay, and in any event within seventy-two hours, after becoming aware of a personal data breach affecting your data. The notice will describe what is known of the nature of the breach, the categories and approximate volume of data concerned, the likely consequences, and the measures taken or proposed. Vallum will provide further information as the investigation develops and will cooperate with your own notification obligations.
International transfers
Vallum and its subprocessors may process personal data outside the country in which it was collected, including in the United States. Where a transfer requires a lawful mechanism, the parties rely on the Standard Contractual Clauses or another approved mechanism, which are incorporated by reference and completed with the parties, categories, and processing described in this Addendum and on the Data retention page.
Audits and assurance
On reasonable written request, no more than once in twelve months unless required by a supervisory authority, Vallum will make available the information reasonably necessary to demonstrate compliance with this Addendum, including responses to a security questionnaire and any current third-party reports. Where an on-site or hands-on audit is required by law, the parties will agree scope, timing, and cost in advance so that the audit does not compromise the security of other customers.
Deletion and return
On termination, Vallum will delete customer data within ninety days, including from backups as they age out on their ordinary cycle. Deleting an application removes the telemetry, sessions, decoy activity, policy, and audit records scoped to it. You may export your data through the console before termination, and on request Vallum will confirm deletion in writing.
Liability and precedence
Each party's liability under this Addendum is subject to the limitation of liability in the Terms of Service. Where this Addendum conflicts with the Terms of Service on the processing of personal data, this Addendum controls; where it conflicts with a signed data processing agreement, that agreement controls.