Skip to content
CaviusConnect
B2B agreement

Data Processing Agreement

Last updated: February 7, 2026

1. Scope and nature of processing

CaviusConnect acts as a data processor for customer data processed through our platform. We process personal data solely on your instructions and in accordance with applicable data protection laws including GDPR and CCPA.

Data types: contact information, message content, metadata, usage analytics, and authentication credentials.

Data subjects: your customers, employees, and end-users who interact with your organization through our platform.

2. Data processor obligations

We commit to:

  • Process data only on your documented instructions
  • Ensure personnel authorized to process data are bound by confidentiality
  • Implement appropriate technical and organizational security measures
  • Assist with data subject rights requests (access, deletion, portability)
  • Notify you of data breaches within 48 hours of discovery
  • Delete or return data upon termination of services

3. Sub-processors

We engage the following categories of sub-processors:

  • Cloud infrastructure: Google Cloud Platform (GCP) for data hosting and compute
  • Database: MongoDB Atlas for data storage
  • Messaging providers: Twilio (SMS), SendGrid (Email), Meta (WhatsApp Business API)
  • AI services: Google Vertex AI for natural language processing
  • Monitoring: cloud logging and analytics services

We will notify you of any changes to sub-processors with 30 days' notice. You may object to new sub-processors within this period.

4. Security measures

Encryption: TLS 1.3 in transit, AES-256 at rest.

Access control: role-based access, multi-factor authentication, least-privilege principle.

Infrastructure: multi-tenant isolation, regular security patching, intrusion detection.

Testing: annual penetration testing, vulnerability scanning, security audits.

5. Data breach notification

We will notify you within 48 hours of becoming aware of a personal data breach. Our notification will include the nature of the breach, affected data categories, likely consequences, and mitigation measures taken.

6. International transfers

Data may be processed in the United States and other jurisdictions where our sub-processors operate. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers outside the EEA.

7. Audit rights

You have the right to audit our compliance with this DPA once per year with 30 days' notice. We will provide necessary documentation and access to demonstrate compliance.

8. Term and termination

This DPA remains in effect as long as we process personal data on your behalf. Upon termination, we will delete or return all personal data within 30 days, unless legally required to retain it.

9. Contact for DPA matters

For DPA-related questions or to exercise your rights under this agreement, contact our Data Protection Officer at dpo@caviusconnect.com.