HOME / DATA PROCESSING AGREEMENT

Data Processing Agreement

Effective 1 September 2026

This agreement applies where ValueRamp processes personal data on your behalf. It forms part of the Terms of Service. It is written to match what ValueRamp actually does — several clauses that appear in a standard DPA are absent here because the corresponding mechanism does not exist yet, and each of those absences is stated rather than papered over.

1. Roles

You are the controller. ValueRamp is the processor, and processes personal data only on your documented instructions.

Your use of the product is the instruction: which integrations you connect, which channels you enable, which accounts you mark “do not analyze”. We do not process your customers’ personal data for our own purposes, and we do not train AI models on it.

The people whose conversations are ingested have no relationship with ValueRamp. They are your contacts. Establishing a lawful basis for ingesting and analysing their communications, and providing them any notice they are owed, is your responsibility as controller. ValueRamp cannot do it on your behalf, because we have no way to reach them.

2. Scope of processing

ItemDetail
Subject matterProvision of the ValueRamp post-sales execution platform.
DurationFor as long as your account is open, plus the retention periods in §6.
Nature and purposeStoring customer-success records; ingesting and analysing business communications to extract structured signals; sending email on your behalf.
Categories of data subjectYour staff who use the product; your customers’ staff who appear in communications, calendar events and CRM records.
Categories of personal dataNames, business email addresses, job titles and employers; the content of business communications, including full meeting transcripts; calendar attendees and event titles; CRM engagement history.
Special category dataNot requested and not required. ValueRamp does not ask for it and has no feature that depends on it — but free-text conversation content is ingested verbatim, so we cannot guarantee none is present. Do not use ValueRamp where that risk is unacceptable.

3. Sub-processors

You authorise the sub-processors below. Each receives only what it needs for its stated purpose, and each is engaged under terms requiring appropriate protection.

Sub-processorPurposeData received
SupabasePrimary database (Singapore)All application data
RailwayBackend hostingAll backend data in transit and in memory; application logs
VercelFrontend hostingRendered pages, session cookies, request logs
CloudflareInbound email routing; document and backup storage (R2)Inbound email; uploaded documents; encrypted backups
ResendOutbound emailRecipient addresses and email bodies
AnthropicAI analysis and draftingMessage bodies, meeting transcripts, participant lists
HubSpotCRM import (read-only)Deals, companies, contacts, engagement history
SlackCommunication ingestChannel and user information, message text
GoogleCalendar ingest; usage-data importCalendar attendees and event titles; spreadsheet contents
FathomMeeting transcriptsFull verbatim meeting transcripts
SentryServer-side error monitoringException messages, stack traces, a sample of request traces
FrankfurterCurrency reference ratesCurrency codes only — no personal data

Anthropic is the one to look at hardest. The full text of ingested conversations, with participant identities, is sent there for analysis. If that is not acceptable, do not enable Communication Intelligence — it is off by default and everything else in the product works without it.

We will give notice before adding or replacing a sub-processor that processes personal data, and you may object. If we cannot resolve an objection, you may terminate the affected part of the service.

4. International transfers

Data is stored in Supabase’s Singapore (ap-southeast-1) region, and backups in Cloudflare R2 in the Asia-Pacific region. Regional data residency selection is not currently available. Several sub-processors operate outside Singapore and India — our error-monitoring provider, Sentry, runs in a United States region — so using ValueRamp involves cross-border transfer. Where transfers require a lawful mechanism, we rely on the transfer terms in each sub-processor’s own data processing terms.

5. Security

Third-party integration credentials are encrypted by ValueRamp using AES-256-GCM. All other data is protected by our database provider’s encryption at rest and by access controls. Data in transit uses TLS. Backups are encrypted, and have been restored and verified. Every read and write is scoped to a single workspace by the backend, and the database refuses direct client access entirely.

What we do not have: no SOC 2 report, no ISO 27001 certification, and no penetration-test report to share. The security page lists what is missing in full. A DPA that implied otherwise would be the most damaging sentence on this site.

6. Retention and deletion

DataRetention
Raw communication content30 days by default; configurable by the workspace between 7 and 90 days
— exception: sales email imported from HubSpot24 months from the deal close date
Structured analysis (the AI extraction)Indefinite
— identifiers inside that analysisReplaced with pseudonymous tokens after 365 days
Audit logIndefinite
Backups30 days. Data deleted from live systems ages out of backups within a further 30 days — a full purge at day 60

Retention windows are stamped when data is written, so changing the setting applies to what arrives afterwards and not to what is already stored. Structured analysis — including participant names and email addresses — is retained indefinitely; identifiers within it are replaced with pseudonymous tokens after 365 days. Because the salt is retained, that data remains personal data.

On termination, we will delete or return personal data on your written request. Account deletion in the product is a soft delete — data is archived rather than erased — so a deletion request is carried out manually. We do not commit to a deletion deadline, because no automated erasure mechanism or request-tracking system exists to support one. We will act as promptly as we are able, and we will confirm when it is done.

7. Personnel and confidentiality

Access to customer data is limited to those who need it to operate and support the service, under a duty of confidentiality. ValueRamp is operated by Arjun Sachdeva as a sole proprietor (not incorporated); where that changes, this clause and the Terms of Service will be reissued.

8. Assisting you with data-subject requests

We will help you respond to requests for access, correction, deletion or objection. That help is manual: there is no self-service export and no per-individual erasure function reachable from the product. Send requests to privacy@valuerampai.com.

No turnaround time is stated here, deliberately. You have statutory deadlines to meet and we would rather you plan around an honest “manual, promptly” than a number we cannot evidence. Tell us your deadline when you write and we will work to it.

The nearest in-product control is the per-account “do not analyze” flag. It stops AI analysis of that account’s communications; messages already received may remain in our ingestion records. It is set by your administrator, not by the individual.

9. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the detail we have at the time, and will keep you updated as we learn more. We do not state a fixed number of hours: your notification clock as controller is the one that matters, and a figure we could miss would help neither of us.

10. Audits

On reasonable written request, and no more than once a year unless required by a regulator, we will provide the information reasonably necessary to demonstrate compliance with this agreement. In practice that means written answers and the documentation we hold. We do not currently offer on-site audits or third-party audit reports, and we would rather say so than agree to something we could not deliver.

11. Signing this agreement

This agreement applies automatically to every customer as part of the Terms of Service; there is nothing you must do to bring it into effect. If your procurement process needs a countersigned copy, or your own DPA reviewed, write to privacy@valuerampai.com and we will arrange it.

To be accurate about the current state: ValueRamp has no system that records DPA acceptance, consent versions or the accepting party. So we cannot claim that every customer has signed one. What we can say is that these terms bind us from the effective date above, whether or not a signature exists.