Legal

Data Processing Addendum

Effective as of the date signed by Vero and Customer

This Data Processing Addendum (“DPA”) supplements the Master Services Agreement (or other such written agreement addressing the same subject matter for accessing Vero’s Subscription Services) (the “Agreement”) entered into by and between the entity accessing the Subscription Services (as well as on behalf of its Affiliate) and Vero Finance Technologies, Inc. (“Vero”) (each individually, a “Party” and collectively, the “Parties”). This Data Processing Addendum to the Agreement (this “Addendum”) is entered into by Vero and Customer and supplements the Agreement. This Addendum will be effective as of the date on which Vero and Customer sign this Addendum.

1. Introduction.

This Addendum sets out the data protection and privacy provisions relating to the services being provided to Customer pursuant to the Agreement. The Parties agree to comply with applicable federal and state privacy laws as set forth in this Addendum, including their respective obligations in Sections 3.2 and 3.3.

This Addendum reflects the Parties’ agreement on the processing of Customer’s personal information pursuant to the Agreement in connection with the Applicable Privacy Laws (as defined below) and is effective solely to the extent each Applicable Privacy Laws applies.

The Parties acknowledge and agree that with regard to the processing of personal data, Customer acts as a controller and Vero acts as a processor, except as otherwise expressly set forth in this Addendum or the Agreement.

The subject matter, nature, purpose, and duration of processing, as well as the types of personal data collected, and categories of data subjects, are described in Exhibit A to this Addendum.

2. Definitions and Interpretation.

2.1. “Applicable Privacy Laws” means, as applicable: (a) the CCPA; (b) Virginia’s Consumer Data Protection Act, Va. Code Ann. § 59.1-571 et seq.; (c) the Colorado Privacy Act, Colo. Rev. Stat. § 6-1-1301 et seq., together with all implementing regulations; (d) Connecticut’s Act Concerning Data Privacy and Online Monitoring, Pub. Act No. 22015; (e) the Utah Consumer Privacy Act, Utah Code Ann. § 13-61-101 et seq.; (f) the Gramm-Leach-Bliley Act 15 U.S.C. §§ 6801-6809, §§ 6821-6827 and its implementing regulations; (g) and all other privacy statutes and regulations which affect the relationship between the Parties in affect as of the date of the signing of this Addendum and as such similar laws that may hereinafter become applicable.

2.2. “CCPA” means California Consumer Privacy Act of 2018, as amended, including as amended by the California Privacy Rights Act of 2020, together with all implementing regulations.

2.3. “Data Security Incident” means any confirmed, unauthorized access to, or confirmed unauthorized acquisition of, Customer personal data stored on Vero’s systems that compromises the security, confidentiality, or integrity of such personal data and results in a legal obligation to notify affected individuals or regulators under Applicable Privacy Laws. For clarity, “Data Security Incident” does not include (a) unsuccessful attempts to penetrate computer networks or servers maintained by Vero, (b) immaterial incidents that do not materially compromise the security or privacy of personal data, (c) pings on firewalls, port scans, unsuccessful log-on attempts, denial of service attacks, or similar incidents, (d) any incident involving data that was encrypted at the time of access or acquisition and for which the encryption key was not also accessed or acquired, (e) any access or acquisition of personal data that was authorized by Customer, (f) any incident arising from Customer’s acts, omissions, or instructions, including Customer’s failure to implement adequate security measures for Customer’s own systems, or (g) any incident caused by Customer’s Authorized Users or Customer’s third-party service providers not under Vero’s control.

2.4. “Deidentified Data” means data information that is “deidentified” (as that term is defined by the CCPA) and “de-identified data” (as defined by other Applicable State Privacy Laws), when disclosed by one Party to the other.

2.5. The terms “business”, “consumer”, “controller”, “data subject”, “personal data”, “personal information”, “process”, “processing”, “sale(s)”, and “sell”, as used in this Addendum have the meanings given in the Applicable Privacy Laws.

2.6. “Services” will have the meaning set forth in the Agreement.

2.7. Capitalized terms used but not defined in this Addendum will have the meanings given in the Agreement unless otherwise defined within this Addendum.

3. Applicable State Privacy Law Terms.

3.1. Deidentified Data. Each Party will comply with the requirements for processing Deidentified Data set out in the Applicable Privacy Laws, with respect to any Deidentified Data it receives from the other Party pursuant to the Agreement, if any.

3.2. Vero’s Obligations. With respect to Customer’s personal information, and to the extent that Applicable Privacy Laws apply to the processing of Customer’s personal information:

  • a)Vero will process such personal information only for the purposes as described in the Agreement and supporting documentation, or as otherwise permitted under Applicable Privacy Laws (including with respect to transfers of personal data to a third country), unless otherwise required to do so by applicable law, and the Parties agree that Customer is making such personal information available to Vero for such purposes. Vero shall not retain, use, or disclose such personal information for any other purpose. Customer hereby instructs Vero to process personal data in accordance with the foregoing and as part of any processing initiated by Customer in its use of the Services. Customer represents, warrants, and covenants that the processing of personal data in accordance with Customer’s instructions will not cause Vero to be in breach of any Applicable Privacy Laws. Customer shall defend, indemnify, and hold harmless Vero and its officers, directors, employees, agents, successors, and assigns from and against any and all claims, demands, losses, liabilities, damages, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to: (i) Customer’s instructions regarding the processing of personal data, (ii) Customer’s breach of any Applicable Privacy Laws, (iii) Customer’s failure to obtain necessary consents or authorizations for the collection or processing of personal data, (iv) any inaccuracy in or breach of Customer’s representations, warranties, or obligations under this Addendum, or (v) any claims by data subjects or regulators relating to Customer’s collection, use, or disclosure of personal data. This indemnification obligation shall survive termination or expiration of this Addendum and the Agreement;
  • b)Except as may be permitted by the CCPA and other Applicable Privacy Laws, Vero shall not combine the personal information that it receives from Customer with personal information that it receives on or on behalf of another person or persons, or that it collects from its own interaction with the consumer.
  • c)Vero will notify Customer if Vero makes a determination that it can no longer meet its obligations under the CCPA or any other Applicable Privacy Laws;
  • d)If Customer reasonably believes that Vero is processing or utilizing personal information in an unauthorized manner, Customer has the right to notify Vero of such belief via the methods described the Agreement, and the Parties will work together in good faith to remediate the allegedly violative activities, if necessary;
  • e)Vero will comply with applicable obligations under CCPA and will provide the same level of privacy protection as is required by CCPA. Vero certifies that it understands the Agreement’s, this Addendum’s and the CCPA’s restrictions and prohibitions on selling or sharing personal information and retaining, using, or disclosing personal information outside of the Parties’ direct business relationship, and it will comply with them;
  • f)Vero will reasonably cooperate and assist Customer with meeting the Customer’s CCPA and other privacy compliance obligations and responding to CCPA-related inquiries, including responding to verifiable consumer requests, taking into account the nature of the Vero’s processing and the information available to the Vero;
  • g)Vero must notify Customer as soon as practicable if it receives any complaint, notice, or communication that directly or indirectly relates to either Party’s compliance with the CCPA. Specifically, Vero must notify Customer within fifteen (15) Business Days if it receives a verifiable consumer request under the CCPA, provided that Customer acknowledges that Vero’s ability to identify and route such requests depends on Customer providing Vero with accurate and complete information regarding Customer’s data subjects and the scope of personal data processed on Customer’s behalf;
  • h)Vero agrees that Customer’s personal information shall be encrypted at rest and in transit when being transmitted;
  • i)Vero agrees that it shall securely dispose of personal information upon termination or expiration of the Agreement, except as necessary to comply with legal or regulatory obligations, resolve disputes, or enforce this Agreement, provided that Vero continues to comply with Applicable Privacy Laws, the Agreement confidentiality and information security obligations, and this DPA, for so long as Vero has Customer personal information in its possession or control; and
  • j)Vero agrees that, in the course of its engagement with Customer, Vero may receive or have access to personal information. Vero shall comply with the terms and conditions set forth in the Agreement and this Addendum in its collection, receipt, transmission, storage, disposal, use and disclosure of such personal information and be responsible for ensuring its employees and subcontractors comply with the authorized collection, receipt, transmission, access, storage, disposal, use and disclosure of personal information under its control or in its possession, and will use commercially reasonable efforts to prevent unauthorized access to or disclosure of such personal information; provided, however, that Vero shall not be responsible for any unauthorized access, disclosure, or breach resulting from: (i) Customer’s acts, omissions, or instructions; (ii) Customer’s failure to implement adequate security measures for Customer’s own systems or networks; (iii) actions of Customer’s Authorized Users; (iv) security vulnerabilities in Customer’s systems or third-party systems not controlled by Vero; or (v) circumstances beyond Vero’s reasonable control, including sophisticated cyber attacks that could not reasonably have been prevented by industry-standard security measures.

3.3. Customer Obligations.

  • a)Customer is solely responsible for the accuracy, quality, and legality of (i) the personal data provided to Vero by or on behalf of Customer, (ii) the means by which Customer acquired any such personal data, and (iii) the instructions it provides to Vero regarding the processing of personal data. Customer will not provide or make available to Vero any personal data in violation of the Agreement or that is otherwise not necessary for Vero to provide the Services. Customer shall defend, indemnify, and hold harmless Vero from and against any regulatory fines, penalties, assessments, or enforcement actions imposed on Vero by any governmental or regulatory authority to the extent arising from or relating to Customer’s acts, omissions, instructions, Customer Data, or Customer’s breach of Applicable Privacy Laws or this Addendum.
  • b)Customer will ensure that it has obtained all necessary consents and authorizations or legitimate business interests required under Applicable Privacy Laws to disclose personal data to Vero and to permit Vero to process such personal data as contemplated by this Addendum and the Agreement.
  • c)Customer will ensure that its instructions to Vero regarding the processing of personal data comply with Applicable Privacy Laws, and will promptly notify Vero if Customer becomes aware that its instructions may violate Applicable Privacy Laws.

4. Authorized Employee and Authorized Subprocessors.

4.1. Customer acknowledges and agrees that Vero may (1) engage the authorized subprocessors listed on Exhibit B to this Addendum to access and process personal data in connection with the Services, and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of personal data.

4.2. Vero will provide Customer with at least thirty (30) days’ prior written notice before engaging any new subprocessor. Notwithstanding the foregoing, Customer shall have no right to object to (a) any subprocessor that is an Affiliate of Vero, (b) any subprocessor that is replacing a previously approved subprocessor and providing substantially similar services, or (c) any subprocessor engaged on an emergency basis to maintain service continuity, provided that Vero notifies Customer of such emergency engagement as soon as reasonably practicable. Customer may object to Vero’s use of a new subprocessor by notifying Vero in writing within fifteen (15) days of receipt of Vero’s notice; provided that any such objection must be based on reasonable, documented grounds relating to the subprocessor’s data protection capabilities and must include specific evidence supporting Customer’s concerns. If Customer does not object within such fifteen (15) day period, Customer shall be deemed to have accepted the new subprocessor. If Customer timely objects and the Parties cannot resolve the objection within thirty (30) days through good faith negotiations, Vero may, in its sole discretion, either (ay) elect not to engage the new subprocessor for processing Customer’s personal data, or (bz) proceed with the new subprocessor engagement, in which case Customer’s sole remedy shall be to terminate, upon thirty (30) days’ written notice, only those specific sServices that require the use of such subprocessor, and Customer shall pay Vero for all sServices provided through the termination date. For clarity, Customer shall have no right to terminate the entire Agreement or any sServices that do not require the use of the objected-to subprocessor. Vero will refund any prepaid, unused fees for the terminated portion of the affected sServices only.

4.3. Vero will enter into a written agreement with each subprocessor imposing data protection obligations substantially similar to those set forth in this Addendum. Vero will remain liable for the acts and omissions of its subprocessors to the same extent Vero would be liable if performing the sServices of each subprocessor directly, subject to the limitations of liability set forth in Section 7 of this Addendum.

5. Transfers of Personal Data.

Personal data may be transferred to and processed in India (where authorized subprocessor Vedhas Technology Solution Pvt. Ltd. Operates) and other countries where Vero or its authorized subprocessors operate. Customer consents to such transfers for purposes of providing the Services under the Agreement.

6. Data Breach Notification.

Vero will notify Customer without undue delay, and in any event within ten (10) Business Days, after becoming aware of any confirmed Data Security Incident that affects Customer Data. Vero’s notification will include, to the extent known at the time: (a) a description of the nature of the Data Security Incident; (b) the categories and approximate number of data subjects and personal data records affected; (c) the likely consequences of the Data Security Incident; (d) measures taken or proposed to address the Data Security Incident and mitigate its potential adverse effects; and (e) contact information for Vero’s representative who can provide further information. Vero will reasonably cooperate with Customer and provide such assistance as Customer may reasonably require to enable Customer to comply with its obligations under Applicable Privacy Laws with respect to the Data Security Incident, including assisting with any investigation, notifications to data subjects or regulators, and remediation efforts, provided that Customer shall reimburse Vero for its reasonable out-of-pocket costs incurred in providing such assistance to the extent the Data Security Incident did not result from Vero’s breach of its obligations under this Addendum. Notwithstanding the foregoing, Vero’s obligation to provide assistance under this Section 6 shall be limited to providing information and cooperation that is reasonably within Vero’s control and does not require Vero to incur material expense or disrupt its operations or services to other customers. Vero shall have no obligation to provide legal advice, forensic investigation services, or direct communications with Customer’s regulators or data subjects. Vero shall have no obligation to participate in any legal proceedings, regulatory hearings, audits, or investigations, or to provide testimony, declarations, or evidence on Customer’s behalf, unless separately agreed in writing and subject to Customer’s payment of Vero’s then-current Professional Services rates plus reimbursement of all costs and expenses. Customer shall bear all costs and expenses associated with any Data Security Incident, including notification costs, credit monitoring, forensic investigation, and legal fees, except to the extent a Data Security Incident is finally determined by a court of competent jurisdiction to have resulted solely and directly from Vero’s gross negligence or willful misconduct in breach of its express obligations under this Addendum, subject in all cases to the limitations of liability set forth in the Agreement.

7. Limitation of Liability.

The limitations of liability set forth in Section 121 of the Agreement shall apply to this Addendum and all claims arising out of or relating to the processing of personal data hereunder, including any claims for data breaches, privacy violations, or regulatory fines or penalties. In no event shall Vero’s aggregate liability under this Addendum, whether in contract, tort, or otherwise, exceed the limitation of liability set forth in Section 121 of the Agreement. Customer acknowledges and agrees that the fees charged by Vero reflect the allocation of risk set forth in this Addendum and the Agreement, including the limitations of liability, and that Vero would not enter into this Addendum without such limitations. Notwithstanding anything to the contrary in this Addendum, Vero shall have no liability for: (a) any claims arising from Customer’s instructions, Customer Data, or Customer’s breach of this Addendum or Applicable Privacy Laws; (b) any indirect, consequential, special, incidental, or punitive damages; (c) any regulatory fines or penalties imposed on Customer; or (d) any claims by data subjects against Customer.

8. Changes to this Addendum.

8.1. In addition to any language contained in the Agreement, either Party may propose changes to this Addendum if the change is reasonably required to comply with applicable law, applicable regulation, or a court or government order. Any such change must be made by a written amendment to this Addendum signed by both Parties. Notwithstanding the foregoing, if any change in Applicable Privacy Laws, regulatory guidance, or enforcement practices materially increases Vero’s obligations, costs, or liability exposure under this Addendum, Vero may, upon sixty (60) days’ prior written notice to Customer: (a) propose amendments to this Addendum to address such changes, which Customer shall consider in good faith; or (b) if the Parties cannot agree on amendments within such sixty (60) day period, terminate this Addendum and the affected portions of the Agreement without penalty or liability to Customer. Vero shall have no liability for any termination undertaken pursuant to this Section 8.1.

8.2. If a Party proposes an amendment pursuant to this Section 8 and the other Party reasonably objects to such amendment within thirty (30) days of receiving the proposed amendment, the objecting Party may terminate the Agreement upon sixty (60) days’ written notice if the Parties are unable to reach mutual agreement on alternative terms that satisfy the legal or regulatory requirement. During such notice period, the Parties will negotiate in good faith to reach an acceptable resolution. Notwithstanding anything to the contrary herein, if Customer terminates pursuant to this Section 8.2, Customer shall not be entitled to any refund of prepaid Fees, and all Fees for the remainder of the then-current Term shall become immediately due and payable.

9. Conflict with Agreement.

To the extent the language in this Addendum is in conflict with any language in the Agreement, the language in this Addendum will control with respect to matters relating to data privacy, data security, and the processing of personal data. For all other matters, the Agreement will control.

Exhibit A

Details of Processing

Subject Matter: IT support for Vero’s Services, systems, and applications.

Duration: Term of the Agreement.

Nature and Purpose: Technical support, system maintenance, troubleshooting, and related IT services.

Categories of Data Subjects: Customer’s customers and Authorized Users.

Types of Personal Data:

Data Fields Documents
Dealership NameDealer License
DBADrivers License
Address - City, State, Zip - Biz / PersonalFinancials
Dealership WebsiteBank Statements
Ownership by Dealer PrincipalInsurance COI
Date of BirthCredit Report
SSNACH Form - Bank Details
Dealership property ownershipKYB Report -- i.e. Middesk
Leasing Contact NameBusiness License
Leasing Contact Phone NumberDealer Bond
Leasing CompanyBills of Sale
Leasing End DateAsset Titles
Dealer CodeTax Returns
Insurance Provider
Insurance Expiration Date
User Name
Lead Source
Primary Email
Phone Number - Biz / Personal
Years in Business
Auction Access Number (if applicable)
Primary Bank
Bank Account Number (for ACH)
Secondary Bank

Exhibit B

Authorized Subprocessors

Legal Name of Subcontractor Address Services Provided Data Handled / Access to Data
Docusign221 Main Street San Francisco, CA 94105Digital SignaturesPII in the completed agreements, but Vero resources don’t have access
Microsoft AzureOne Microsoft Way Redmond, WA 98052Infrastructure ServicesData is transmitted and stored but Vero will not have access to it
Mongo DB1633 Broadway, 38th Floor New York, NY 10019Database ServicesPII Data is stored and processed but Vero will not have access to data. In case of any production support or critical issues Vero resources will guide the solution.
Plaid1098 Harrison Street San Francisco, CA 94103Bank ConnectivityBank Data is not stored but transmitted. Vero resources will not have access.
SBSTour Trinity, 1bis Place de la Défense, Paris, Courbevoie 92400Loan Management SystemPII Data is stored and processed, Vero resources provide production support and have limited access
Vedhas Technology Solutions Pvt. Ltd.H.No.6-3-1090/2, 4th Floor, Vithaldas Chambers, Rajbhavan Road, Somajiguda, Hyderabad, Telangana, India - 500082Software Development ServicesDealer License, Driver’s License, Financial Statements, Bank Statements, Certificates of Insurance, Credit Reports, ACH Forms, KYB Forms, Business Licenses, Dealer Bonds, Bills of Sale, Asset Titles, Tax Returns