Legal

Data processing addendum

Last updated 1 September 2026


Roles

For customer content you are the controller and Voopr is the processor. For account and billing records Voopr is the controller.

Processing scope

We process customer content only to provide the platform, follow your documented instructions and meet legal obligations. Duration matches your subscription.

Security measures

Hardware-isolated microVMs per tenant, encryption in transit (TLS 1.3) and at rest (AES-256), least-privilege access with mandatory MFA, and audit logging of administrative actions.

Sub-processors

You give general authorisation for the sub-processors on our current list. We notify you 30 days before changes and you may object on reasonable data-protection grounds.

Transfers

Where data leaves the EEA we rely on the EU Standard Contractual Clauses together with the UK addendum, plus a transfer impact assessment.

Breach notification

We notify you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your content, with the facts known at that time.

Deletion and audit

On termination we delete customer content within 30 days unless law requires retention. We make security documentation available annually and support reasonable audits.