Legal
Data processing addendum
Last updated 1 September 2026
Roles
For customer content you are the controller and Voopr is the processor. For account and billing records Voopr is the controller.
Processing scope
We process customer content only to provide the platform, follow your documented instructions and meet legal obligations. Duration matches your subscription.
Security measures
Hardware-isolated microVMs per tenant, encryption in transit (TLS 1.3) and at rest (AES-256), least-privilege access with mandatory MFA, and audit logging of administrative actions.
Sub-processors
You give general authorisation for the sub-processors on our current list. We notify you 30 days before changes and you may object on reasonable data-protection grounds.
Transfers
Where data leaves the EEA we rely on the EU Standard Contractual Clauses together with the UK addendum, plus a transfer impact assessment.
Breach notification
We notify you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your content, with the facts known at that time.
Deletion and audit
On termination we delete customer content within 30 days unless law requires retention. We make security documentation available annually and support reasonable audits.