Legal · Data processing
Data Processing Addendum
This standard DPA applies automatically where a Vora customer is a controller and Seedrus LLP processes personal data on that customer's behalf. It forms part of the Terms and covers the relevant processing by Seedrus LLP and its Subprocessors.
Effective August 2, 2026
Read this DPA together with the Terms of Service and Privacy Policy.
Jump to a section▾
- 01Application and Formation
- 02Definitions and Roles
- 03Processing Details
- 04Documented Instructions
- 05Customer Obligations
- 06Processor Obligations and Confidentiality
- 07Security Measures
- 08Subprocessors
- 09Data-Subject Requests and Compliance Assistance
- 10Personal Data Breaches
- 11Return and Deletion
- 12Documentation; No Customer Audit Rights
- 13International Processing and Transfers
- 14Priority, Liability, and Governing Law
- 15Contact
Application and Formation
This Data Processing Addendum ("DPA") forms part of the Vora Terms of Service (the "Terms") between the user accepting the Terms ("Customer") and Seedrus LLP ("we", "us", or "our"), the owner and legal operator of the Vora brand and product ("Vora"). Capitalized terms not defined in this DPA have the meanings given in the Terms.
This DPA applies automatically, without a separate signature, only to the extent Customer is a controller of personal data submitted through the Services and Seedrus LLP processes that personal data on Customer's behalf as a processor. It applies whether Customer uses the Services as an individual or for an organization. It does not apply to processing for which Seedrus LLP acts as a controller, as described in the Privacy Policy.
By accepting the Terms or using a Service that processes personal data on Customer’s behalf, Customer enters into this DPA for the relevant processing and instructs us to process that data as described here. This is our standard, non-negotiated DPA and cannot be individually modified or negotiated unless the parties enter into a separate written agreement signed by authorized representatives. A separately signed data processing agreement supersedes this DPA to the extent of a conflict.
Definitions and Roles
- “Applicable Data Protection Law” means any privacy or data protection law that applies to the relevant processing under this DPA.
- “Customer Personal Data” means personal data contained in Customer Content that we process on Customer’s behalf in providing the Services.
- “Personal Data Breach” means a breach of security affecting Customer Personal Data that meets the relevant definition under Applicable Data Protection Law.
- “Subprocessor” means a third party engaged by us to process Customer Personal Data on Customer’s behalf.
- “Controller”, “processor”, “personal data”, “processing”, and similar terms have the meanings assigned under Applicable Data Protection Law. Equivalent terms apply where a law uses different terminology.
For processing covered by this DPA, Customer is the controller and Seedrus LLP is the processor. Customer remains responsible for its controller obligations. We remain a controller for personal data we process for our own purposes, including account administration, billing, security and fraud prevention, support and communications, legal compliance, and service analytics, as explained in the Privacy Policy.
Processing Details
Subject Matter and Duration
The processing concerns Customer Personal Data submitted to Vora for document-upload, analysis, generation, and related workflows, including Contract Review, Issues List, Chronology Builder, and any other Service through which Customer submits personal data for processing on its behalf. Processing continues for the period in which we provide the relevant Service and afterward only as permitted by this DPA, the Terms, Customer’s instructions, or applicable law.
Nature and Purpose
Processing may include receiving, accessing, transmitting, organizing, extracting, analyzing, generating, displaying, storing where the workflow supports storage, deleting, securing, troubleshooting, and otherwise handling Customer Personal Data to provide requested outputs and features; maintain the Services; protect accounts and systems; prevent abuse; resolve support requests; and comply with lawful obligations.
Personal Data and Data Subjects
The categories depend on what Customer chooses to submit and may include identity, contact, professional, employment, contractual, commercial, financial, matter-related, correspondence, and other personal data contained in prompts, documents, files, instructions, and workflow outputs. Data subjects may include Customer’s users, personnel, clients, customers, counterparties, witnesses, advisers, suppliers, and other individuals identified in Customer Content.
Customer must not submit sensitive, special-category, criminal-offence, children’s, regulated, or similarly protected data unless Customer has determined that the relevant Service is appropriate, has a lawful basis and authority to do so, and has implemented any additional safeguards required by law or professional duty.
Documented Instructions
Customer’s documented instructions are limited to the Terms, this DPA, Customer’s use and configuration of the Services, Customer’s submitted prompts and workflow actions, and any separate signed written agreement. To the extent Applicable Data Protection Law imposes a mandatory non-waivable processor obligation, we will process Customer Personal Data in accordance with those instructions. Customer instructs us to process Customer Personal Data as reasonably necessary to provide, secure, support, and troubleshoot the Services and to engage Subprocessors for those purposes.
We do not undertake to monitor or independently determine the legality of Customer’s instructions. We may reject, limit, or suspend an instruction that we reasonably believe is unlawful, unsafe, technically infeasible, outside the Services, or disproportionately burdensome. If Applicable Data Protection Law expressly requires us to process outside Customer’s instructions or to notify Customer about a legally problematic instruction, we will provide only the notice and action mandatorily required, unless law prohibits notice. Instructions requiring material changes beyond the Services must be agreed in a separate signed writing.
Customer Obligations
Customer is responsible for complying with Applicable Data Protection Law and for ensuring its instructions are lawful. Without limiting that responsibility, Customer will:
- have all rights, permissions, authorizations, notices, consents, and lawful bases needed to submit Customer Personal Data and instruct the processing described in this DPA;
- give data subjects any required privacy information and handle requests, objections, and regulatory obligations for which Customer is responsible;
- limit Customer Personal Data to what is reasonably necessary and avoid submitting data that the relevant Service is not designed to process;
- maintain appropriate account, access, device, and credential security and promptly notify us of suspected unauthorized use; and
- assess whether the Services and available safeguards meet Customer’s legal, professional, contractual, and risk requirements.
Processor Obligations and Confidentiality
Our processor commitments are limited to this DPA and any mandatory non-waivable requirements of Applicable Data Protection Law. Subject to the nature of the Services, our technical and operational capabilities, and information reasonably available to us, we seek to:
- handle Customer Personal Data consistently with the documented instructions described above and as reasonably necessary to provide the Services;
- limit authorized personnel access through confidentiality arrangements or other measures we consider appropriate or are legally required to maintain;
- apply the security practices described below, without promising any particular control, standard, or outcome;
- consider requests for assistance as described below on a discretionary, reasonable-efforts basis where feasible, except to the extent mandatory non-waivable law requires otherwise;
- address return or deletion as described below, subject to technical capabilities, retention constraints, and applicable law; and
- consider requests for existing security or privacy documentation under the documentation-only process described below.
We will not sell Customer Personal Data or use it for advertising directed by third parties. Our controller processing of service metadata, security information, support records, and aggregated or de-identified information remains governed by the Terms, Privacy Policy, and applicable law.
Security Measures
We select and may change technical and organizational security practices based on our own assessment of the Services, processing, risks, available technology, implementation costs, and operational needs. We seek to use practices we consider reasonable for the relevant Service, but this DPA does not establish a specific minimum control set, security architecture, service level, or guaranteed degree of protection. Any mandatory non-waivable security requirement under Applicable Data Protection Law applies only to the extent it governs the relevant processing.
Depending on the relevant Service and circumstances, practices may include access controls and authentication, least-privilege practices, protections for data in transit or at rest, logical separation, logging or monitoring, vulnerability or incident-management processes, availability or recovery measures, personnel practices, and provider review or contractual protections. This illustrative list is not a representation that every measure applies to every Service, data set, system, provider, or time period, and we do not promise to maintain any particular measure unless a separate signed agreement or mandatory non-waivable law expressly requires it.
No method of transmission, storage, or security is completely secure. This DPA does not represent that the Services meet a particular certification, industry framework, or regulatory standard unless we expressly confirm that in a separate signed writing.
Subprocessors
Customer gives general authorization for us to engage Subprocessors to provide and secure the Services. Depending on whether they process Customer Personal Data for the relevant workflow, Subprocessors may support AI models and APIs, document extraction, hosting and cloud infrastructure, storage and databases, service communications, analytics and logging, monitoring and security, customer support, and related technical functions. Providers used only for our controller activities, such as account administration or billing, are not Subprocessors merely because they support Vora. Provider categories, providers, processing locations, and provider terms may change as the Services evolve.
Subprocessors operate under their own contracts, policies, technical capabilities, security practices, and service terms. We may maintain contractual, privacy, security, or operational requirements for Subprocessors that we elect to use or that mandatory non-waivable law requires. We do not undertake to impose any customer-requested audit, contract, security, operational, notification, cooperation, or other obligation on a Subprocessor, and Customer receives no right to inspect, audit, assess, contact, direct, or enforce terms against a Subprocessor through this DPA. Any responsibility we have for a Subprocessor is limited to responsibility that cannot lawfully be excluded or limited.
We may update provider information through the Privacy Policy, the Services, or another channel we choose, but do not promise advance or individual notice, an objection period, provider-specific disclosure, or an alternative provider. If mandatory non-waivable law expressly requires notice or an opportunity to object to a Subprocessor change, we will provide the minimum notice or process required for the relevant processing. No broader objection, suspension, termination, refund, or remedy arises under this DPA.
Data-Subject Requests and Compliance Assistance
Customer is responsible for receiving, evaluating, authenticating, and responding to data-subject requests. On Customer’s written request, we may use reasonable efforts to provide limited assistance where we consider it feasible, proportionate, and within the functionality of the Services and information then reasonably available to us. We do not guarantee that requested data can be identified, retrieved, corrected, restricted, exported, or deleted. If mandatory non-waivable law requires specific processor assistance, we will provide only the assistance legally required for the relevant processing, subject to lawful limits and technical capabilities.
If we receive a request concerning Customer Personal Data, we may direct the requester to Customer and may choose not to respond unless law requires otherwise. Support for Customer’s security reviews, data protection impact assessments, regulatory consultations, notices, or responses is discretionary and may be declined, limited, conditioned, or charged for where permitted. Customer remains solely responsible for deciding whether any assessment, consultation, notice, or response is required. Mandatory non-waivable assistance obligations, if any, apply only to the extent required by law and based on our available information and capabilities.
Personal Data Breaches
We do not promise any particular monitoring, detection, investigation, remediation, notification time, notification method, or notification content for an actual or suspected security event. If we become aware of a Personal Data Breach affecting Customer Personal Data and mandatory non-waivable Applicable Data Protection Law requires us, in our role as processor, to notify Customer, we will provide notice within the legally required period and manner based on information reasonably available to us at that time. Information may be incomplete, delayed by investigation or legal restrictions, or provided in phases, and notice does not constitute an admission of fault or liability.
We may take steps we consider appropriate in light of the circumstances, our capabilities, available information, and applicable law. Any cooperation with Customer is discretionary and limited to reasonable efforts where feasible, except for a specific mandatory non-waivable obligation. Customer remains responsible for determining whether to notify a regulator, data subject, client, or other third party and for the content and timing of those notices, except where law assigns that responsibility directly to us.
Return and Deletion
Customer should use available Service features to export or delete Customer Content before ending the Services. On written request, we may use reasonable efforts to make Customer Personal Data then available through the Services available for return or deletion where technically feasible and consistent with our retention practices. We do not guarantee retrievability, portability, restoration, or deletion on a requested schedule. If mandatory non-waivable law requires return, deletion, protection, or restricted processing, we will take the minimum action legally required. Backups, logs, security records, legal holds, and systems not reasonably capable of immediate deletion may be retained and removed through ordinary retention and deletion cycles.
Where a workflow states that source documents or outputs are not saved as durable Vora workflow records, the content may nevertheless be processed transiently by us and our Subprocessors to complete the request, maintain security, prevent abuse, troubleshoot failures, or meet legal obligations. Customer acknowledges that return may not be available for transient content or content already deleted in accordance with the workflow.
Documentation; No Customer Audit Rights
On written request, we may make relevant security or privacy documentation or information available only to the extent it already exists, is reasonably available to us, and we consider disclosure appropriate. Any disclosure may be subject to confidentiality terms and may be summarized, redacted, withheld, or limited to protect security-sensitive information, trade secrets, legal privilege, other customers, providers, systems, and business operations. We do not undertake to create documents, complete questionnaires, obtain reports or certifications, or provide evidence in a customer-specified format.
To the fullest extent permitted by law, neither Customer nor any representative, adviser, auditor, client, authority acting at Customer’s request, or other third party has a right under this DPA to inspect, audit, test, assess, or review Seedrus LLP, Vora, our premises, personnel, systems, networks, controls, records, source code, providers, or Subprocessors, whether onsite, remotely, directly, or indirectly. We do not consent to penetration testing, onsite reviews, direct audits, provider or Subprocessor audits, or customer-defined audit procedures. If mandatory non-waivable law expressly requires a measure despite this exclusion, only the minimum legally required measure will apply. We may first offer existing documentation, summaries, responses to narrowly tailored questions, regulator-facing materials where lawfully shareable, or another non-intrusive alternative, and may impose reasonable confidentiality, security, scope, scheduling, and cost conditions to the extent legally permitted. No broader audit right is created.
International Processing and Transfers
Customer authorizes us and our Subprocessors to process Customer Personal Data in countries where we or they operate, subject to this DPA and Applicable Data Protection Law. We do not promise to implement a customer-selected transfer mechanism or jurisdiction-specific arrangement. If mandatory non-waivable law requires an additional transfer mechanism for the relevant processing, we will take only the steps legally required and reasonably available within our technical and operational capabilities, or may discontinue the affected processing where lawful.
This DPA does not itself claim that a particular transfer mechanism, adequacy decision, certification, or contractual-clause regime applies. Any jurisdiction-specific transfer terms must be required by Applicable Data Protection Law or set out in a separate signed writing. Customer is responsible for assessing its own transfer obligations and providing lawful instructions.
Priority, Liability, and Governing Law
If this DPA conflicts with the Terms or Privacy Policy concerning processor obligations for Customer Personal Data, this DPA controls for that conflict. The Terms otherwise remain in effect, including their disclaimers, limitations of liability, indemnity provisions, suspension and termination rights, and dispute-resolution terms. Nothing in this DPA limits a right or remedy that cannot lawfully be limited.
This DPA is governed by the governing-law and dispute-resolution provisions in the Terms. It terminates automatically when the Terms and all processing of Customer Personal Data on Customer’s behalf end, except for provisions that by their nature must survive, including confidentiality, deletion, liability, and dispute provisions.
Contact
Documentation requests and data protection questions may be sent to the contacts below. Submitting a request does not create a right to a response, disclosure, assistance, remedy, or particular response time except to the extent mandatory non-waivable law requires one.
- Seedrus LLP — Vora's contracting entity and processor where applicable
- hello@seedrus.in
- hello@seedrus.com
© 2026 Seedrus LLP. Vora is a brand and product owned and operated by Seedrus LLP.