Legal
Effective as of the date signed by Vero and Customer
This Data Processing Addendum (“DPA”) supplements the Master Services Agreement (or other such written agreement addressing the same subject matter for accessing Vero’s Subscription Services) (the “Agreement”) entered into by and between the entity accessing the Subscription Services (as well as on behalf of its Affiliate) and Vero Finance Technologies, Inc. (“Vero”) (each individually, a “Party” and collectively, the “Parties”). This Data Processing Addendum to the Agreement (this “Addendum”) is entered into by Vero and Customer and supplements the Agreement. This Addendum will be effective as of the date on which Vero and Customer sign this Addendum.
This Addendum sets out the data protection and privacy provisions relating to the services being provided to Customer pursuant to the Agreement. The Parties agree to comply with applicable federal and state privacy laws as set forth in this Addendum, including their respective obligations in Sections 3.2 and 3.3.
This Addendum reflects the Parties’ agreement on the processing of Customer’s personal information pursuant to the Agreement in connection with the Applicable Privacy Laws (as defined below) and is effective solely to the extent each Applicable Privacy Laws applies.
The Parties acknowledge and agree that with regard to the processing of personal data, Customer acts as a controller and Vero acts as a processor, except as otherwise expressly set forth in this Addendum or the Agreement.
The subject matter, nature, purpose, and duration of processing, as well as the types of personal data collected, and categories of data subjects, are described in Exhibit A to this Addendum.
2.1. “Applicable Privacy Laws” means, as applicable: (a) the CCPA; (b) Virginia’s Consumer Data Protection Act, Va. Code Ann. § 59.1-571 et seq.; (c) the Colorado Privacy Act, Colo. Rev. Stat. § 6-1-1301 et seq., together with all implementing regulations; (d) Connecticut’s Act Concerning Data Privacy and Online Monitoring, Pub. Act No. 22015; (e) the Utah Consumer Privacy Act, Utah Code Ann. § 13-61-101 et seq.; (f) the Gramm-Leach-Bliley Act 15 U.S.C. §§ 6801-6809, §§ 6821-6827 and its implementing regulations; (g) and all other privacy statutes and regulations which affect the relationship between the Parties in affect as of the date of the signing of this Addendum and as such similar laws that may hereinafter become applicable.
2.2. “CCPA” means California Consumer Privacy Act of 2018, as amended, including as amended by the California Privacy Rights Act of 2020, together with all implementing regulations.
2.3. “Data Security Incident” means any confirmed, unauthorized access to, or confirmed unauthorized acquisition of, Customer personal data stored on Vero’s systems that compromises the security, confidentiality, or integrity of such personal data and results in a legal obligation to notify affected individuals or regulators under Applicable Privacy Laws. For clarity, “Data Security Incident” does not include (a) unsuccessful attempts to penetrate computer networks or servers maintained by Vero, (b) immaterial incidents that do not materially compromise the security or privacy of personal data, (c) pings on firewalls, port scans, unsuccessful log-on attempts, denial of service attacks, or similar incidents, (d) any incident involving data that was encrypted at the time of access or acquisition and for which the encryption key was not also accessed or acquired, (e) any access or acquisition of personal data that was authorized by Customer, (f) any incident arising from Customer’s acts, omissions, or instructions, including Customer’s failure to implement adequate security measures for Customer’s own systems, or (g) any incident caused by Customer’s Authorized Users or Customer’s third-party service providers not under Vero’s control.
2.4. “Deidentified Data” means data information that is “deidentified” (as that term is defined by the CCPA) and “de-identified data” (as defined by other Applicable State Privacy Laws), when disclosed by one Party to the other.
2.5. The terms “business”, “consumer”, “controller”, “data subject”, “personal data”, “personal information”, “process”, “processing”, “sale(s)”, and “sell”, as used in this Addendum have the meanings given in the Applicable Privacy Laws.
2.6. “Services” will have the meaning set forth in the Agreement.
2.7. Capitalized terms used but not defined in this Addendum will have the meanings given in the Agreement unless otherwise defined within this Addendum.
3.1. Deidentified Data. Each Party will comply with the requirements for processing Deidentified Data set out in the Applicable Privacy Laws, with respect to any Deidentified Data it receives from the other Party pursuant to the Agreement, if any.
3.2. Vero’s Obligations. With respect to Customer’s personal information, and to the extent that Applicable Privacy Laws apply to the processing of Customer’s personal information:
3.3. Customer Obligations.
4.1. Customer acknowledges and agrees that Vero may (1) engage the authorized subprocessors listed on Exhibit B to this Addendum to access and process personal data in connection with the Services, and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of personal data.
4.2. Vero will provide Customer with at least thirty (30) days’ prior written notice before engaging any new subprocessor. Notwithstanding the foregoing, Customer shall have no right to object to (a) any subprocessor that is an Affiliate of Vero, (b) any subprocessor that is replacing a previously approved subprocessor and providing substantially similar services, or (c) any subprocessor engaged on an emergency basis to maintain service continuity, provided that Vero notifies Customer of such emergency engagement as soon as reasonably practicable. Customer may object to Vero’s use of a new subprocessor by notifying Vero in writing within fifteen (15) days of receipt of Vero’s notice; provided that any such objection must be based on reasonable, documented grounds relating to the subprocessor’s data protection capabilities and must include specific evidence supporting Customer’s concerns. If Customer does not object within such fifteen (15) day period, Customer shall be deemed to have accepted the new subprocessor. If Customer timely objects and the Parties cannot resolve the objection within thirty (30) days through good faith negotiations, Vero may, in its sole discretion, either (ay) elect not to engage the new subprocessor for processing Customer’s personal data, or (bz) proceed with the new subprocessor engagement, in which case Customer’s sole remedy shall be to terminate, upon thirty (30) days’ written notice, only those specific sServices that require the use of such subprocessor, and Customer shall pay Vero for all sServices provided through the termination date. For clarity, Customer shall have no right to terminate the entire Agreement or any sServices that do not require the use of the objected-to subprocessor. Vero will refund any prepaid, unused fees for the terminated portion of the affected sServices only.
4.3. Vero will enter into a written agreement with each subprocessor imposing data protection obligations substantially similar to those set forth in this Addendum. Vero will remain liable for the acts and omissions of its subprocessors to the same extent Vero would be liable if performing the sServices of each subprocessor directly, subject to the limitations of liability set forth in Section 7 of this Addendum.
Personal data may be transferred to and processed in India (where authorized subprocessor Vedhas Technology Solution Pvt. Ltd. Operates) and other countries where Vero or its authorized subprocessors operate. Customer consents to such transfers for purposes of providing the Services under the Agreement.
Vero will notify Customer without undue delay, and in any event within ten (10) Business Days, after becoming aware of any confirmed Data Security Incident that affects Customer Data. Vero’s notification will include, to the extent known at the time: (a) a description of the nature of the Data Security Incident; (b) the categories and approximate number of data subjects and personal data records affected; (c) the likely consequences of the Data Security Incident; (d) measures taken or proposed to address the Data Security Incident and mitigate its potential adverse effects; and (e) contact information for Vero’s representative who can provide further information. Vero will reasonably cooperate with Customer and provide such assistance as Customer may reasonably require to enable Customer to comply with its obligations under Applicable Privacy Laws with respect to the Data Security Incident, including assisting with any investigation, notifications to data subjects or regulators, and remediation efforts, provided that Customer shall reimburse Vero for its reasonable out-of-pocket costs incurred in providing such assistance to the extent the Data Security Incident did not result from Vero’s breach of its obligations under this Addendum. Notwithstanding the foregoing, Vero’s obligation to provide assistance under this Section 6 shall be limited to providing information and cooperation that is reasonably within Vero’s control and does not require Vero to incur material expense or disrupt its operations or services to other customers. Vero shall have no obligation to provide legal advice, forensic investigation services, or direct communications with Customer’s regulators or data subjects. Vero shall have no obligation to participate in any legal proceedings, regulatory hearings, audits, or investigations, or to provide testimony, declarations, or evidence on Customer’s behalf, unless separately agreed in writing and subject to Customer’s payment of Vero’s then-current Professional Services rates plus reimbursement of all costs and expenses. Customer shall bear all costs and expenses associated with any Data Security Incident, including notification costs, credit monitoring, forensic investigation, and legal fees, except to the extent a Data Security Incident is finally determined by a court of competent jurisdiction to have resulted solely and directly from Vero’s gross negligence or willful misconduct in breach of its express obligations under this Addendum, subject in all cases to the limitations of liability set forth in the Agreement.
The limitations of liability set forth in Section 121 of the Agreement shall apply to this Addendum and all claims arising out of or relating to the processing of personal data hereunder, including any claims for data breaches, privacy violations, or regulatory fines or penalties. In no event shall Vero’s aggregate liability under this Addendum, whether in contract, tort, or otherwise, exceed the limitation of liability set forth in Section 121 of the Agreement. Customer acknowledges and agrees that the fees charged by Vero reflect the allocation of risk set forth in this Addendum and the Agreement, including the limitations of liability, and that Vero would not enter into this Addendum without such limitations. Notwithstanding anything to the contrary in this Addendum, Vero shall have no liability for: (a) any claims arising from Customer’s instructions, Customer Data, or Customer’s breach of this Addendum or Applicable Privacy Laws; (b) any indirect, consequential, special, incidental, or punitive damages; (c) any regulatory fines or penalties imposed on Customer; or (d) any claims by data subjects against Customer.
8.1. In addition to any language contained in the Agreement, either Party may propose changes to this Addendum if the change is reasonably required to comply with applicable law, applicable regulation, or a court or government order. Any such change must be made by a written amendment to this Addendum signed by both Parties. Notwithstanding the foregoing, if any change in Applicable Privacy Laws, regulatory guidance, or enforcement practices materially increases Vero’s obligations, costs, or liability exposure under this Addendum, Vero may, upon sixty (60) days’ prior written notice to Customer: (a) propose amendments to this Addendum to address such changes, which Customer shall consider in good faith; or (b) if the Parties cannot agree on amendments within such sixty (60) day period, terminate this Addendum and the affected portions of the Agreement without penalty or liability to Customer. Vero shall have no liability for any termination undertaken pursuant to this Section 8.1.
8.2. If a Party proposes an amendment pursuant to this Section 8 and the other Party reasonably objects to such amendment within thirty (30) days of receiving the proposed amendment, the objecting Party may terminate the Agreement upon sixty (60) days’ written notice if the Parties are unable to reach mutual agreement on alternative terms that satisfy the legal or regulatory requirement. During such notice period, the Parties will negotiate in good faith to reach an acceptable resolution. Notwithstanding anything to the contrary herein, if Customer terminates pursuant to this Section 8.2, Customer shall not be entitled to any refund of prepaid Fees, and all Fees for the remainder of the then-current Term shall become immediately due and payable.
To the extent the language in this Addendum is in conflict with any language in the Agreement, the language in this Addendum will control with respect to matters relating to data privacy, data security, and the processing of personal data. For all other matters, the Agreement will control.
Subject Matter: IT support for Vero’s Services, systems, and applications.
Duration: Term of the Agreement.
Nature and Purpose: Technical support, system maintenance, troubleshooting, and related IT services.
Categories of Data Subjects: Customer’s customers and Authorized Users.
Types of Personal Data:
| Data Fields | Documents |
|---|---|
| Dealership Name | Dealer License |
| DBA | Drivers License |
| Address - City, State, Zip - Biz / Personal | Financials |
| Dealership Website | Bank Statements |
| Ownership by Dealer Principal | Insurance COI |
| Date of Birth | Credit Report |
| SSN | ACH Form - Bank Details |
| Dealership property ownership | KYB Report -- i.e. Middesk |
| Leasing Contact Name | Business License |
| Leasing Contact Phone Number | Dealer Bond |
| Leasing Company | Bills of Sale |
| Leasing End Date | Asset Titles |
| Dealer Code | Tax Returns |
| Insurance Provider | |
| Insurance Expiration Date | |
| User Name | |
| Lead Source | |
| Primary Email | |
| Phone Number - Biz / Personal | |
| Years in Business | |
| Auction Access Number (if applicable) | |
| Primary Bank | |
| Bank Account Number (for ACH) | |
| Secondary Bank |
| Legal Name of Subcontractor | Address | Services Provided | Data Handled / Access to Data |
|---|---|---|---|
| Docusign | 221 Main Street San Francisco, CA 94105 | Digital Signatures | PII in the completed agreements, but Vero resources don’t have access |
| Microsoft Azure | One Microsoft Way Redmond, WA 98052 | Infrastructure Services | Data is transmitted and stored but Vero will not have access to it |
| Mongo DB | 1633 Broadway, 38th Floor New York, NY 10019 | Database Services | PII Data is stored and processed but Vero will not have access to data. In case of any production support or critical issues Vero resources will guide the solution. |
| Plaid | 1098 Harrison Street San Francisco, CA 94103 | Bank Connectivity | Bank Data is not stored but transmitted. Vero resources will not have access. |
| SBS | Tour Trinity, 1bis Place de la Défense, Paris, Courbevoie 92400 | Loan Management System | PII Data is stored and processed, Vero resources provide production support and have limited access |
| Vedhas Technology Solutions Pvt. Ltd. | H.No.6-3-1090/2, 4th Floor, Vithaldas Chambers, Rajbhavan Road, Somajiguda, Hyderabad, Telangana, India - 500082 | Software Development Services | Dealer License, Driver’s License, Financial Statements, Bank Statements, Certificates of Insurance, Credit Reports, ACH Forms, KYB Forms, Business Licenses, Dealer Bonds, Bills of Sale, Asset Titles, Tax Returns |