# Data Processing Addendum

Effective September 8, 2026. This Addendum forms part of the [OrgVault Terms](https://orgvault.md/terms) between [SiteVue AI, Inc.](https://sitevue.ai) (“SiteVue”) and the customer using OrgVault (“Customer”) when SiteVue processes personal data in Customer's private organization content on Customer's behalf. A separately signed data-processing agreement prevails if it expressly replaces this Addendum. Contact: [andrew@sitevue.ai](mailto:andrew@sitevue.ai).

## Roles and scope

Customer is the controller, or a processor authorized by its controller, of the personal data it supplies through OrgVault. SiteVue acts as processor, or subprocessor, for that data (“Customer Personal Data”). Customer is responsible for having authority, notices, legal bases and any required consent for its instructions and content. SiteVue acts separately for account administration, security, payment and service-relationship information as described in the [Privacy Policy](https://orgvault.md/privacy).

The subject is provision of a hosted knowledge and collaboration service. Processing lasts for the service relationship and the retention/deletion periods described below. Processing includes collection, hosting, organization, retrieval, authorized disclosure, scoped indexing, backup, recovery and deletion. Customer's settings, authenticated requests, administrator decisions and written support instructions constitute documented instructions within the agreed service scope.

Data subjects may include Customer's employees, contractors, clients and other people mentioned in submitted content. Data can include business contact details, user and bot associations, work documents, communications, activity metadata and other personal data Customer chooses to submit. Customer determines the actual categories. The standard service is not intended for children's data, health records requiring a business-associate agreement, or other specially regulated data requiring additional contractual or technical controls. Arrange suitable terms before submitting such data.

## SiteVue's obligations

SiteVue will process Customer Personal Data only on documented instructions to provide the service, unless law requires otherwise. We will inform Customer of such a requirement before processing unless prohibited by law. We will inform Customer if we believe an instruction infringes applicable data-protection law and may pause the affected processing while the issue is resolved.

People authorized to access Customer Personal Data must be subject to appropriate confidentiality obligations. Access is limited to legitimate operational, security, support or legal needs. SiteVue will not sell Customer Personal Data, use it for targeted advertising, or train general-purpose AI models on private Customer content. We will not retain, use or disclose it outside the permitted service/business purposes and applicable law, including applicable restrictions on combining data from other customers or independent sources.

SiteVue will maintain technical and organizational measures appropriate to the processing risk, taking account of the nature of the service and available technology. Current measures are described in [Security](https://orgvault.md/security): encryption at rest and HTTPS; scoped authentication and authorization; human-linked organization bot access; restricted administrative access; audit records; backup and recovery controls; and retention/deletion procedures. We may improve or replace measures without materially reducing the overall protection during the service relationship. These descriptions are not a certification or a guarantee against every incident.

## Customer controls and encrypted content

Customer controls admission, human and bot access, publication, retention, legal holds and deletion. Customer must secure its endpoints and credentials, use appropriate scopes, review automation, and prevent unlawful disclosure. Customer is responsible for instructions that make content public and for evaluating its own connectors and LLM destinations.

End-to-end encrypted message and file content remains ciphertext at the service when the supported client protocols are used. Metadata still requires protection and may be personal data. Customer is responsible for encryption keys, secure distribution, rotation and recovery backups. Preservation or export of ciphertext does not provide decryption without the corresponding keys. We cannot fulfill a request to decrypt content for which we do not hold a key. Revocation cannot recall previously obtained keys or plaintext.

## Subprocessors

Customer generally authorizes the service providers listed at [Subprocessors](https://orgvault.md/subprocessors) for their described functions. SiteVue will use written obligations providing protection appropriate to the relevant processing and remains responsible for its subprocessors' performance of delegated data-processing obligations to the extent required by applicable law.

We will give affected Customers at least 30 days' notice before appointing a new subprocessor for Customer Personal Data, except where an urgent security or continuity need makes earlier replacement necessary, in which case we will give notice as soon as practicable. Customer may object on reasonable, documented data-protection grounds within that notice period by contacting us. We will work in good faith on an alternative. If the issue cannot reasonably be resolved, Customer may terminate the affected service before the new processing begins, with a proportionate refund of prepaid unused fees for that affected service. We will maintain the current list and change history on the subprocessor page.

## Assistance and incidents

Taking account of the processing and information available to us, SiteVue will reasonably assist Customer with applicable data-subject requests, impact assessments, regulator consultations and security obligations. We will refer requests about Customer-controlled content to Customer unless law requires a direct response. Customer can use scoped downloads, access revocation, retention and closure controls; contact us for requests the product cannot handle. We may agree reasonable charges in advance for substantial assistance beyond ordinary service support, where law permits.

SiteVue will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. Initial notice will include information then reasonably available about the nature of the breach, affected data or people, likely consequences, mitigation and a contact for follow-up. We will provide material updates as the investigation progresses and reasonably cooperate with Customer. Notice is not an admission of liability. Customer remains responsible for its own notices to authorities and individuals unless law assigns that obligation to SiteVue.

## Return, deletion and retention

Customer can download available content during authorized service access. On termination or Customer's documented deletion instruction, SiteVue will delete Customer Personal Data from live service storage or return available data as instructed, except where law requires continued storage. Product retention and legal holds apply to organization content. Customer must release its legal holds before requesting destructive closure; SiteVue will cooperate on lawful conflicting instructions. A hold does not recreate deleted information.

Protected backups, recovery copies and security/financial records have separate lifecycles. Copies retained for recovery remain restricted, are not used for ordinary service purposes and expire under their configured lifecycle. Deletion and revocation records must be reconciled before restored content is reopened. We retain information separately required for legal obligations or legitimate account-security purposes as described in the Privacy Policy. Customer must separately delete exports, endpoint copies and keys it controls.

## Information and audits

SiteVue will make information reasonably necessary to demonstrate compliance with this Addendum available to Customer. Where required by applicable law, we will allow and contribute to proportionate audits by Customer or an independent auditor bound by confidentiality. The parties will first use relevant documentation and existing evidence where adequate, and agree reasonable timing, scope and safeguards to protect other customers, systems and confidential information. Audits may not involve accessing another customer's data or unapproved destructive testing. These arrangements do not limit a competent regulator's lawful powers.

## Location and international transfers

Primary application storage is in AWS US East (Ohio), with recovery infrastructure in the United States and edge/service-provider processing as listed on the subprocessor page. Customer authorizes those locations subject to applicable law. This Addendum alone does not constitute EU Standard Contractual Clauses, a UK transfer addendum or another regulated international-transfer mechanism. If the intended processing requires an additional transfer agreement or safeguard, contact SiteVue and complete that arrangement before submitting the affected data. We do not promise exclusive-country residency or that every jurisdiction's requirements are satisfied by this public Addendum.

## Applicable obligations and priority

Where applicable US state privacy law treats SiteVue as a service provider or contractor, SiteVue will observe the purpose, use and disclosure restrictions in this Addendum, provide the required level of protection, notify Customer if it can no longer meet relevant obligations, and allow reasonable steps to stop and remediate unauthorized use. Neither party must follow an instruction that violates applicable law.

This Addendum controls over conflicting general Terms on processing Customer Personal Data; mandatory law controls over both. The Terms otherwise continue to apply, including their liability provisions to the extent permitted by law. Obligations concerning retained Customer Personal Data survive termination for as long as that data remains subject to this Addendum.
