Skip to content

Data Processing Addendum

Effective March 10, 2026

This addendum applies when Securvantage Technologies processes personal data on behalf of a customer through VantageOpsix. It supplements the customer's agreement and these Terms. A countersigned copy is available on request from legal@securvantage.io.

1. Roles and instructions

The customer is the controller (CCPA "business"); Securvantage Technologies is the processor (CCPA "service provider"). We process customer personal data only on the customer's documented instructions, which are the agreement, the customer's configuration of the service, and written requests. We will tell the customer if we believe an instruction breaks applicable law.

2. Details of processing

ItemDescription
Subject matterProviding security operations, access control, alarm verification and field service
Data subjectsCustomer staff and users, technicians, visitors and people captured at monitored sites
Data categoriesNames, work contact details, badge IDs, access events, camera stills, alarm records, device and session data
Special categoriesNone intended. No biometrics, audio or facial recognition
DurationTerm of the agreement plus the retention periods in the Privacy Policy

3. CCPA service-provider terms

We will not sell or share customer personal data, retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in the agreement, or combine it with data from other sources except as permitted by the CCPA. We will comply with the CCPA, give the same level of privacy protection it requires, and let the customer take reasonable steps to stop unauthorized use.

4. Processor obligations

  • Personnel with access are bound by confidentiality and trained on data handling.
  • We maintain the security measures in Annex A and keep an audit log of administrative actions.
  • We assist with data-subject requests, data-protection impact assessments and regulator inquiries.
  • We notify the customer of a personal data breach without undue delay and in any event within 72 hours of confirmation.
  • At the end of the service we delete or return customer data, keeping backups no longer than 30 days.
  • We make information available to show compliance and allow reasonable audits once a year on 30 days' notice.

5. Subprocessors

The customer authorizes the subprocessors listed on the Subprocessors page. We give at least 30 days' notice of a new subprocessor, during which the customer may object on reasonable data-protection grounds. We remain responsible for our subprocessors.

6. International transfers

For transfers from the EEA, the EU Standard Contractual Clauses (Module 2, controller-to-processor, and Module 3 where applicable) are incorporated by reference; for the UK, the UK International Data Transfer Addendum; for Switzerland, the clauses as adapted for the Swiss FADP.

Annex A: Security measures

  • Encryption in transit (TLS 1.2+) and at rest through our hosting providers.
  • Passwords and technician PINs stored only as salted one-way hashes; tablet tokens hashed.
  • HTTP-only, secure session cookies with 7-day expiry; sign-in rate limiting; PIN lockout.
  • Role- and facility-scoped authorization checked on every request.
  • Audit log of state-changing actions, kept 365 days.
  • Security headers (HSTS, frame protection, content-type and referrer policies).
  • Automated daily retention and self-healing jobs; backups for recovery.