Counsel-approved standard form

Virali Data Processing Addendum

Scope and roles

This DPA applies when Virali processes Customer Personal Data for a customer under the Terms or an order form. Customer is the controller or processor that determines the instructions, and Virali is the processor or subprocessor for that Customer Personal Data. Virali remains an independent controller for its own account administration, billing, security, fraud-prevention, legal-compliance, and business operations.

Instructions and purpose

Virali processes Customer Personal Data only on documented customer instructions, including providing, securing, supporting, and improving the customer-directed Services, and as required by applicable law. Customer is responsible for lawful instructions and required notices and rights.

Data and data subjects

Processing may include account and team data, creator and contact data, public social content, campaign and onboarding information, communications, files, contracts, payout and subscription records, integration settings, and service logs concerning workspace users, creators, customer contacts, signers, and other people represented in Customer Data.

Confidentiality and security

Virali limits access to personnel and contractors with an appropriate need and confidentiality obligations, and maintains technical and organizational safeguards designed to protect Customer Personal Data. Current control descriptions are available on the Security page; Virali does not promise a certification unless separately documented.

Subprocessors

Customer authorizes the subprocessors listed at /subprocessors. Virali will provide at least 30 days' notice before a new subprocessor begins processing Customer Personal Data and allow 15 days for a reasonable data-protection objection. Virali remains responsible for required subprocessor obligations and propagates applicable deletion instructions.

Security incidents

A Customer Personal Data Security Incident is a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data. Unsuccessful scans, blocked login or phishing attempts, firewall events, pings, attempted attacks without unauthorized access, and vulnerabilities without evidence of compromise are not incidents unless Customer Personal Data was actually compromised.

Incident notification

Virali becomes aware when designated security or privacy personnel have a reasonable degree of certainty that a Customer Personal Data Security Incident occurred. Virali will notify Customer without undue delay and within any shorter period required by applicable law, provide information reasonably available at the time, and provide staged updates as the investigation progresses. The contractual commitment is not a fixed 24-, 48-, or 72-hour guarantee.

Data-subject requests

Taking into account the nature of processing, Virali will reasonably assist Customer with verified access, correction, deletion, portability, objection, and consent-withdrawal requests involving Customer Personal Data. Virali will not independently respond as controller for Customer Data unless legally required or authorized.

Return and deletion

At termination, Customer may request export during an ordinary 30-day window; otherwise Virali defaults to deletion. After that period, Virali begins production deletion and completes active-system deletion within 30 additional days. Formal erasure instructions may override the export period. Backups expire through a rolling 30-day schedule. Legally retained data remains isolated and used only for the applicable legal purpose. Virali will provide written confirmation of deletion on reasonable request.

International transfers

For transfers from the EEA, Virali will use an applicable adequacy decision, a verified Data Privacy Framework certification where available and applicable, or the European Commission Standard Contractual Clauses. For United Kingdom transfers, Virali will use an adequacy regulation, the UK Addendum, or the IDTA as applicable. Virali does not promise data residency unless an executed agreement expressly provides it.

Audit cooperation

On reasonable request and subject to confidentiality and security limits, Virali will provide information reasonably necessary to demonstrate compliance with this DPA. Reviews should first use existing documentation and avoid exposing other customers' data, secrets, or sensitive security material.

Order of precedence and contact

An executed customer-specific DPA or order form controls over conflicting online terms. Virali is Life Development LLC. Privacy and security questions may be sent to support@tryvirali.com. Publication date: August 25, 2026.