Skip to content
VenSoc Technologies

Legal

Data processing (GDPR)

Last reviewed

In short

Where an engagement involves personal data, the client is the controller and VenSoc is the processor. A data processing agreement is signed before processing begins, and standard contractual clauses cover transfers outside the EEA and the UK.

Which page you need

This page covers personal data VenSoc processes on behalf of a client, as part of delivering or operating a system. If you are a visitor to this website and want to know what happens to an enquiry you send, the privacy policy is the page you want.

Controller and processor

In a client engagement the client determines why and how personal data is processed and is therefore the controller. VenSoc processes that data only on the client’s documented instructions and is therefore the processor, within the meaning of Article 4 of the UK and EU GDPR.

This distinction is not a formality. It means VenSoc will not use client personal data for its own purposes — not to train a model, not to build a benchmark, not to enrich a marketing list — and will not engage a sub-processor the client has not been told about.

The data processing agreement

A DPA is signed before any processing begins. VenSoc will sign the client’s own DPA where one exists, which is usually the fastest route, or provide one. It records the matters Article 28 requires.

Subject matter and duration
What is being processed and for how long, tied to the term of the engagement rather than left open-ended.
Nature and purpose
The specific operations performed — for example migrating records into an ERP, or operating a system that stores customer contact details.
Categories of data and data subjects
Which fields and whose data. Special category data is identified explicitly, because it changes the controls required.
Security measures
The technical and organisational measures applied, described on the security page and committed contractually.
Sub-processors
Named, with the client’s right to object. Sub-processors depend on the infrastructure the client chooses, so they are listed per engagement rather than generically.
Assistance obligations
Help with data subject requests, breach notification within agreed windows, and support for a data protection impact assessment where the client needs one.
Deletion or return on exit
What happens to the data at the end, chosen by the client, and confirmed in writing when it has been done.

International transfers

VenSoc is established in Pakistan, which holds no adequacy decision from the European Commission or the UK government. Any engagement where VenSoc personnel access EEA or UK personal data therefore involves a restricted transfer.

These transfers are covered by the European Commission’s standard contractual clauses, and for UK data by the UK International Data Transfer Addendum, incorporated into the DPA. A transfer risk assessment is provided where the client requires one.

Stating this plainly costs VenSoc nothing and saves the client a due-diligence cycle. A supplier that leaves it to be discovered is a supplier that has not thought about it.

Where the data lives

Delivered systems run in the client’s own cloud accounts and regions unless the client has asked otherwise. VenSoc does not require client data to be hosted on VenSoc infrastructure, and where data residency is a requirement it is designed for rather than worked around.

Development and test environments run on synthetic or anonymised data. Production data is not copied out to make debugging convenient; where a defect can only be reproduced against real data, it is reproduced inside the client’s environment under the client’s controls.

Breach notification

Where VenSoc becomes aware of a personal data breach affecting client data, it notifies the client without undue delay and within the window agreed in the DPA, with the information the client needs to meet its own seventy-two hour regulatory obligation.

Notification is not conditional on VenSoc having completed its investigation. A partial notification on time is more useful to a controller than a complete one that is late.

Requesting the documents

Email info@vensoc.com for the DPA template, the standard contractual clauses as VenSoc executes them, or a completed security questionnaire. These are sent without requiring a call first.