Doneven Ventures LLC d/b/a DV Technologies
DATA PROCESSING ADDENDUM
CCPA/CPRA service provider terms for Customer Data
Version 1.0 | Effective Date: January 1, 2026 | Last Updated: January 1, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service and any Master Services Agreement between Doneven Ventures LLC d/b/a DV Technologies ("Company," "Service Provider," or "Processor") and the customer identified on the applicable Order Form ("Customer," "Business," or "Controller"). Capitalized terms not defined here have the meanings given in the Terms of Service or applicable Privacy Laws.
1. DEFINITIONS
- "Privacy Laws" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 and its implementing regulations, and other applicable U.S. state privacy laws.
- "Personal Information" means Personal Information contained in Customer Data under applicable Privacy Laws.
- "Subprocessor" means a third party engaged by Company to Process Personal Information on Company's behalf.
- "Security Incident" means a confirmed breach of Company's security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information Processed by Company.
2. ROLES AND SCOPE
Customer is the Business or Controller with respect to Personal Information in Customer Data. Company is the Service Provider or Processor. Customer determines the purposes and means of Processing. Company Processes Personal Information only on Customer's documented instructions. Customer's use and configuration of the Services, together with the Terms of Service, Order Form, and this DPA, constitute Customer's complete documented instructions.
This DPA does not apply to Personal Information that Company Processes as a Business in its own right (website visitor data and account administration data), which is governed by the Privacy Policy.
3. CCPA SERVICE PROVIDER COMMITMENTS
With respect to Personal Information received from or on behalf of Customer, Company shall:
- Not Sell or Share the Personal Information.
- Not retain, use, or disclose it for any purpose other than the specific business purposes in Section 4, including not for a commercial purpose other than performing the Services, and not outside the direct business relationship, except as permitted by the CCPA.
- Not combine it with Personal Information from other sources except as permitted by 11 CCR section 7050(b).
- Comply with applicable CCPA obligations and provide the same level of privacy protection the CCPA requires of a Business.
- Grant Customer the right to take reasonable steps to help ensure compliant Processing.
- Notify Customer within five (5) business days if Company determines it can no longer meet its CCPA obligations.
- Permit Customer to take reasonable steps to stop and remediate unauthorized use.
- Cooperate with Customer in responding to Consumer requests as set out in Section 7.
Company certifies that it understands and will comply with the restrictions in this Section 3.
4. PERMITTED PROCESSING
Company may Process Personal Information solely to: (a) provide, operate, maintain, and support the Services; (b) perform automated transcription, extraction, summarization, quality-assurance analysis, and drafting where Customer has enabled those features; (c) transmit communications where Customer has enabled autonomous sending; (d) detect, prevent, and respond to security incidents, fraud, and unlawful activity, and debug errors; (e) maintain and improve the quality and safety of the Services as permitted by 11 CCR section 7050(a)(4) and Section 8; (f) retain and employ Subprocessors under Section 5; and (g) comply with legal obligations.
5. SUBPROCESSORS
Customer provides general authorization for Company to engage Subprocessors. The current list is published at https://www.dvtechnologies.com/legal/subprocessors. Company will provide at least thirty (30) days' notice before adding or replacing a Subprocessor that Processes Personal Information. Customer may object in writing within fifteen (15) days on reasonable data protection grounds. If the parties cannot resolve an objection, Customer may terminate the affected Services without penalty, with a pro-rata refund of prepaid unused fees. Company imposes data protection obligations on each Subprocessor no less protective than this DPA and remains liable for each Subprocessor's performance.
6. SECURITY AND INCIDENT RESPONSE
Company will implement and maintain the technical and organizational measures described in the Security Overview, including encryption in transit and at rest, database row-level security enforcing tenant isolation, role-based access control, least-privilege administrative access, managed secret storage, audit logging, and time-limited revocable portal tokens.
Incident notification. Company will notify Customer without undue delay, and in any event within seventy-two (72) hours of confirming a Security Incident affecting Customer's Personal Information. Notification to affected individuals and regulators is Customer's responsibility. Company will provide reasonable assistance.
Upon reasonable written request, no more than once per twelve (12) months, Company will provide a completed security questionnaire and any then-current third-party audit report or attestation Company holds.
7. CONSUMER RIGHTS ASSISTANCE
Company will not respond substantively to a Consumer request relating to Customer Data, except to direct the Consumer to Customer or forward the request. Company will provide functionality for Customer to access, export, correct, and delete Personal Information within its tenant, and reasonable additional assistance where self-service is unavailable. On Customer instruction to delete, Company will delete from active systems within thirty (30) days and from backups on the ordinary rotation cycle (not exceeding thirty-five (35) days), unless retention is required by law.
8. SERVICE IMPROVEMENT AND MODEL DEVELOPMENT
Company may use Personal Information to maintain and improve the quality and safety of the Services as permitted by 11 CCR section 7050(a)(4).
Model development requires opt-in. Company may use Customer Data, including call transcripts and outcome data, to develop, evaluate, tune, and improve AI models used in the Services only where Customer has separately and affirmatively opted in on an Order Form or in account settings. That election is unbundled from the purchase of the Services and may be withdrawn at any time by written notice, effective prospectively.
Where Customer has opted in, Company will: (a) de-identify the data before use for model development; (b) maintain measures prohibiting re-identification and not attempt to re-identify; (c) ensure no Customer's identifiable content appears in or is recoverable from output delivered to another customer; and (d) publicly commit not to re-identify as required by CCPA section 1798.140(m). Company's AI Subprocessors are contractually prohibited from using data submitted through the Services to train their own general-purpose models.
Company may create and use aggregated and de-identified data that cannot reasonably identify Customer or any individual without the opt-in requirement above.
9. INTERNATIONAL TRANSFERS
Personal Information is Processed in the United States. Company will not transfer Personal Information outside the United States without Customer's prior written consent and appropriate safeguards. Any Subprocessor Processing outside the United States will be identified on the Subprocessor list.
10. RETURN AND DELETION
On termination or expiration, Company will make Customer Data available for export in a machine-readable format for thirty (30) days. After that period, Company will delete or de-identify Customer Data in accordance with the Privacy Policy retention schedule, unless retention is required by law. On written request within the export window, Company will provide written confirmation of deletion.
11. LIABILITY AND ORDER OF PRECEDENCE
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service or Master Services Agreement. In the event of conflict between this DPA and the Terms of Service or MSA with respect to Processing of Personal Information, this DPA controls. This DPA is effective for so long as Company Processes Personal Information on Customer's behalf.
Contact: privacy@dvtechnologies.com
© 2026 Doneven Ventures LLC d/b/a DV Technologies. All rights reserved.
legal@dvtechnologies.com | [Principal Place of Business Address], California
This document is maintained by Doneven Ventures LLC d/b/a DV Technologies. It describes our practices and contractual terms. It is not a certification, an audit report, or legal advice.
