Skip to content

Data processing

Data Processing Addendum

For white-label partners and business customers who need a written processor agreement covering roles, sub-processors, security, breach notification and deletion.

Effective
21 August 2026
Last updated
21 August 2026
Applies to
[Legal Entity Name, a Texas company] and the MyVesta service

Draft pending legal review

This document is a working draft written in plain language to describe how MyVesta actually operates. It has not yet been reviewed by counsel and is not legal advice. Wording may change before it becomes binding. The operating company is still being formed in Texas, so the entity name shown as [Legal Entity Name, a Texas company] is a placeholder and will be replaced once formation completes. Texas law will govern. If anything here matters to a decision you are making, write to privacy@myvesta.io and we will tell you exactly where the draft stands.

1. Scope and relationship to other terms

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and [Legal Entity Name, a Texas company] (“MyVesta”) for the provision of the MyVesta service. It applies wherever MyVesta processes personal data on the Customer's behalf, and it governs in the event of a conflict with the Terms of Service on data protection matters.

“Applicable Data Protection Law” means the UK GDPR, the EU GDPR, the Data Protection Act 2018, and any other data protection or privacy law that applies to the processing. Terms such as controller, processor, data subject, personal data and processing carry the meanings given in that law.

To execute this DPA, download the copy from this page, sign it, and return it to partnerships@myvesta.io. We will countersign and return an executed copy. Customers who need it on their own paper are welcome to send that instead.

2. Roles of the parties

  • Where an organization deploys MyVesta to its own client households under a white-label agreement, the Customer is the controller and MyVesta is the processor.
  • Where MyVesta sells a household subscription directly to a consumer, MyVesta is the controller for that relationship and this DPA does not apply to it.
  • MyVesta is an independent controller for a narrow set of its own purposes: billing records, security and fraud prevention, aggregate service telemetry, and complying with its own legal obligations.
  • Each party is responsible for its own compliance with Applicable Data Protection Law in respect of the processing it controls.

Details of processing

ItemDetail
Subject matterProvision of the MyVesta household information hub
DurationThe term of the agreement, plus the deletion period in section 8
Nature and purposeHosting, storage, retrieval, transmission, backup, access control and deletion of household records and files
Categories of data subjectCustomer's client household owners and members, and the individuals whose details those households record
Categories of personal dataIdentity and contact details, account credentials, household records across insurance, medical, financial, property, vehicle, inventory, contact, estate and legal, and pet categories, uploaded files, and activity logs
Special category dataHealth information may be recorded by households at their own initiative. MyVesta does not require it and applies the same controls to all vault content

3. Processing instructions

  • MyVesta processes personal data only on the Customer's documented instructions, which include the agreement itself and the Customer's use of the service's configuration options.
  • MyVesta will tell the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may pause that instruction until resolved.
  • Where a law requires MyVesta to process beyond the Customer's instructions, MyVesta will inform the Customer before doing so unless that law forbids it on important grounds of public interest.
  • MyVesta does not sell personal data, does not use it for its own advertising, and does not use Customer vault content to train machine-learning models.

4. Confidentiality and personnel

  • Access to personal data is limited to personnel who need it to deliver or support the service.
  • All personnel are bound by written confidentiality obligations that survive the end of their engagement.
  • Personnel receive data protection and security training appropriate to their role, refreshed at least annually.
  • Production access is individually provisioned, logged, reviewed quarterly, and revoked promptly when no longer needed.

5. Security measures

MyVesta implements appropriate technical and organizational measures under Article 32, including at least the following.

Technical measures

  • Encryption of personal data in transit using TLS, and at rest at the storage layer.
  • File attachments stored in a private bucket that is never publicly readable, served only through short-lived signed URLs.
  • Household isolation enforced by database-level row security, so one household cannot read another's data; isolation is verified by automated tests on every deployment, not by policy alone.
  • Authentication controls: verified email addresses, a twelve-character minimum password policy with complexity requirements, secure password reset, and optional app-based two-factor authentication.
  • An activity log recording who viewed, created, changed or deleted each record.
  • Network-layer protection against denial of service and automated abuse.
  • Encrypted, access-controlled backups with tested restore procedures.

Organizational measures

  • Least-privilege access control with individual accounts and multi-factor authentication for administrative access.
  • Change management with peer review and automated security checks before deployment.
  • Dependency and vulnerability scanning, with remediation targets by severity.
  • A documented incident response plan, rehearsed and reviewed at least annually.
  • A responsible disclosure program reachable at security@myvesta.io.
  • Vendor review before any new sub-processor handles personal data.

MyVesta may update these measures as technology develops, provided the level of protection is not reduced.

6. Sub-processors

The Customer grants general authorization for MyVesta to engage sub-processors, subject to the conditions in this section. Each sub-processor is bound by a written contract imposing data protection obligations no less protective than this DPA, and MyVesta remains fully liable for their performance.

Sub-processorPurposeData handledLocation
Supabase (database, authentication and file storage)Hosts the application database, account credentials and file attachmentsAccount data, vault records, uploaded files, activity logsEuropean Union / United States
Cloudflare (application hosting and network)Serves the application and protects it from abuseIP address, request metadata, transport-level dataGlobal edge network
Stripe (payments)Processes subscription payments and stores card detailsName, email, billing address, payment card details, invoicesUnited States / European Union
Managed email delivery (notify.myvesta.io)Sends account, security and transactional emailName, email address, message content of transactional emailEuropean Union / United States
  • MyVesta gives the Customer at least 30 days' written notice by email before a new sub-processor begins processing personal data.
  • The Customer may object on reasonable data protection grounds within that period. The parties will work in good faith to find an alternative; if none is available, the Customer may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees.
  • In an emergency — for example replacing a failed provider — MyVesta may engage a sub-processor immediately and notify the Customer without undue delay.

7. International transfers and data subject rights

Transfers

Where personal data is transferred outside the UK or the EEA, the parties rely on an adequacy decision where one covers the destination, and otherwise on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, both of which are incorporated into this DPA by reference. MyVesta carries out and documents a transfer risk assessment for each such transfer.

Data subject rights

  • The service gives the Customer self-service tools to access, correct, export and delete household data, which will satisfy most requests without MyVesta's involvement.
  • If a data subject contacts MyVesta directly, MyVesta will not respond substantively but will forward the request to the Customer without undue delay, and in any case within 5 business days.
  • MyVesta will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to it.

8. Personal data breach notification

  • MyVesta will notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Customer's personal data.
  • The notification will describe, as far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a named contact for further information.
  • Where the full picture is not available at first, MyVesta will send an initial notification within the same window and follow up in phases as facts are established.
  • MyVesta will assist the Customer in meeting its own notification obligations to supervisory authorities and data subjects, and will not notify the Customer's data subjects directly unless the Customer asks or the law requires it.
  • MyVesta maintains an internal record of all personal data breaches and makes the relevant entries available to the Customer on request.

9. Audit and demonstration of compliance

  • MyVesta makes available the information reasonably necessary to demonstrate compliance with this DPA, including its security documentation and any third-party assessment reports it holds.
  • The Customer may audit no more than once in any twelve-month period, on 30 days' written notice, during business hours, and without unreasonable disruption. A supervisory authority may audit at any time as the law allows.
  • An additional audit may be conducted following a confirmed personal data breach affecting the Customer's data.
  • Each party bears its own audit costs unless the audit reveals material non-compliance, in which case MyVesta bears the reasonable cost.
  • Audit findings and any documentation shared are confidential to the parties.

10. Return and deletion on termination

  1. On termination or expiry, the Customer may export all personal data in a structured, machine-readable format for 30 days. Export is self-service and available throughout.
  2. At the end of that period, or earlier at the Customer's written request, MyVesta deletes all personal data from live systems, including database records and files in object storage.
  3. Encrypted backups containing the data expire on their normal cycle, within 35 days of deletion. Until they expire they remain encrypted, access-controlled, and are not used for any purpose other than disaster recovery.
  4. MyVesta retains only what a law requires it to keep — principally billing and tax records — plus a minimal deletion receipt recording that deletion occurred, its date, and the household identifier. The receipt contains no personal content.
  5. MyVesta will certify deletion in writing on request.

11. Liability, term and signature

  • Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service or the parties' signed agreement, except where Applicable Data Protection Law provides otherwise.
  • This DPA takes effect on the earlier of signature or the start of processing, and continues for as long as MyVesta processes personal data on the Customer's behalf.
  • Obligations of confidentiality, deletion and audit survive termination for as long as they are relevant.

Signature blocks for both parties are included in the downloadable copy. Return the signed document to partnerships@myvesta.io; we countersign and return an executed copy, usually within two business days.

Questions about this document? Write to privacy@myvesta.io or post to [Registered address], Texas, United States.