Legal

Data Processing Agreement

Last updated: April 2026

1. Introduction

This Data Processing Agreement (DPA) applies between Onvanta (processor) and the customer (controller) using the Onvanta platform. This agreement complies with the requirements of the GDPR (General Data Protection Regulation).

2. Definitions

  • Controller: the company using Onvanta for employee onboarding
  • Processor: Onvanta, established in the Netherlands
  • Data subjects: employees of the controller
  • Personal data: name, email address, onboarding progress, quiz results

3. Purposes of processing

Onvanta processes personal data solely for the purpose of providing the onboarding service: managing onboarding programmes, tracking progress and quiz results, and sending system-related emails.

4. Obligations of Onvanta as processor

  • We process data only on the instructions of the controller
  • We implement appropriate technical and organisational security measures
  • We notify the controller of a data breach within 48 hours
  • We delete or return all personal data upon termination of the agreement
  • We do not engage sub-processors without prior consent

5. Sub-processors

  • Supabase (database, US/EU) โ€” user data storage
  • Vercel (hosting, US/EU) โ€” platform hosting
  • Resend (email, US) โ€” transactional emails
  • Stripe (payments, US/EU) โ€” payment processing
  • Anthropic (AI, US) โ€” AI-generated template content (no personal data)

6. Retention periods

Personal data is retained for as long as the customer relationship is active. After termination, data is deleted within 30 days, unless a statutory retention obligation applies.

7. Rights of data subjects

The controller is responsible for handling requests from data subjects (access, rectification, erasure). Onvanta provides assistance upon request.

8. Governing law

This agreement is governed by Dutch law. Disputes shall be submitted to the competent court in the Netherlands.

9. Contact

For questions about this Data Processing Agreement: privacy@onvanta.io