Version 1.0 · Effective 21 April 2026
In this DPA:
CertVault processes Worker personal data on behalf of Employers for the following purposes:
Processing is carried out electronically via the CertVault Platform on a continuous basis for the duration of the Controller's subscription.
As the Controller, the Employer agrees to:
CertVault, as the Processor, agrees to:
The Controller authorises CertVault to engage the following sub-processors. CertVault will ensure each sub-processor is bound by a written agreement containing equivalent data protection obligations:
| Sub-processor | Location | Purpose |
|---|---|---|
| Supabase, Inc. | USA (AWS us-east-1) | Database, auth, and file storage |
| Vercel, Inc. | USA / Global CDN | Web hosting and serverless compute |
| Resend, Inc. | USA | Transactional email |
| Stripe, Inc. | USA / EU | Payment processing |
| Anthropic, PBC | USA | AI certificate scanning; in-app assistant |
| VirusTotal (Google LLC) | USA | Malware scanning of uploaded documents |
CertVault will notify the Controller of any intended changes to the sub-processor list by updating this page. Controllers who object to a new sub-processor on reasonable GDPR grounds should contact legal@certvaultapp.com.
CertVault implements the following technical and organisational measures (TOMs) appropriate to the risk:
Where personal data is transferred outside the EEA or UK (e.g., to sub-processors located in the USA), CertVault relies on:
Copies of applicable SCCs/IDTAs with sub-processors are available on request at legal@certvaultapp.com.
Where a Worker exercises a data subject right (access, erasure, rectification, portability, objection) and that right requires action by the Employer as Controller (e.g., deletion of notes or workforce records maintained by the Employer), CertVault will:
In the event of a personal data breach affecting Worker data accessed by the Controller:
The Controller may request an audit of CertVault's data processing activities relevant to this DPA. In practice, CertVault will satisfy audit requests by providing:
Any audit must be conducted in a manner that minimises disruption to CertVault's business and is subject to reasonable confidentiality requirements.
This DPA applies for the duration of the Controller's CertVault subscription. Upon termination:
This DPA is governed by the laws of the jurisdiction most relevant to the Controller's location:
For questions about this DPA, to request a signed copy, or to exercise audit rights:
CertVault — Data Protection
Email: legal@certvaultapp.com