Data Processing Agreement
Draft date: August 10, 2026 · Status: Draft for counsel — not an executable contract until signed
Counsel action required: This DPA outline is not executable. Counsel must finalize roles, SCCs, breach timelines, and annexes against the retention matrix before customer signature.
This draft describes how Veracrew processes Customer Personal Data as a processor when providing the workforce operations SaaS. Customer organizations remain controllers for worker and operational data they enter into Veracrew.
Parties and roles
- Customer = Controller (employer organization) for Customer Personal Data in the SaaS.
- Veracrew = Processor for that SaaS data; Controller for its own account, billing, marketing, and security logs about admins.
Subject matter and duration
Processing covers identity, membership, scheduling, time, documents, messaging, invoicing metadata, and audit signals for the subscription term plus retention and deletion schedules in the annex (internal retention matrix).
Data subjects and types
- Customer employees and contractors: name, email, role, documents, time, geolocation at clock-in when enabled, messages.
- Customer admins: account identifiers, 2FA state, billing contacts.
- Client contacts if entered by the customer: names and emails in CRM-like fields.
Processing instructions and product limits
Veracrew processes Customer Personal Data to provide, secure, and bill the Service and to comply with law. Product-backed limits that counsel must disclose include:
- User erasure is anonymization (tombstone), not guaranteed physical destruction of all historical rows.
- Invoices and time entries default to a multi-year legal hold before hard-delete eligibility.
- Organization soft-delete does not automatically wipe the tenant; it enters an internal review queue.
- Cancelled subscriptions receive an export-oriented grace period; there is no silent hard-delete of the tenant at that moment.
Subprocessors
Representative subprocessors matching typical production infrastructure:
- Vercel — application hosting.
- Neon (or managed PostgreSQL host) — primary database.
- Cloudflare R2 — object storage for documents and images.
- Stripe — payments and subscription billing.
- Resend — transactional email.
- Upstash Redis — rate limits and short-lived keys when enabled.
- Sentry — error monitoring.
- PostHog — product analytics.
- Cloudflare Turnstile — bot protection on public boundaries.
Security
Security measures are summarized on the Security overview. Veracrew does not claim SOC 2, ISO, or HIPAA attestation unless separately documented.
Assistance with data-subject rights
Customers handle employee requests first. Veracrew assists via support@veracrew.com and, where the plan includes it, in-product admin audit export. A full self-serve EU-grade DSAR package is not yet shipped.
Breach notification
After a confirmed personal-data breach affecting Customer Personal Data, Veracrew will notify the Customer without undue delay under timelines counsel sets in the signed DPA, paired with internal incident runbooks.
Return and deletion on termination
On subscription end, Customers should export needed data during the product grace window. Thereafter deletion and anonymization follow the retention matrix and operator review—not an automatic nightly cascade wipe.
Contact
DPA and procurement questions: support@veracrew.com.