VenturaVentura ← Back to site
Legal

Data Processing Agreement

Last updated 20 July 2026
Template draft. Placeholder wording for layout only — review and finalise with qualified legal counsel before publishing.

This Data Processing Agreement ("DPA") forms part of the agreement between the client ("Controller") and Ventura Global SRL ("Processor", "Ventura") for the Ventura service. It reflects the parties' obligations under the GDPR.

1. Roles

The Controller determines the purposes and means of processing the personal data within its assistant instance. Ventura processes that data only on the Controller's documented instructions, as its Processor.

2. Subject matter and duration

The subject matter is the operation of the Ventura assistant for the Controller. Processing lasts for the term of the engagement and any wind-down period.

3. Nature, purpose and data

Purpose: capturing and organising tasks, reminders, notes, calendar events and briefs. Data subjects may include the Controller and the people they interact with. Categories may include names, contact details, scheduling information, and the content of messages, notes and files the Controller sends.

4. Processor obligations

5. Sub-processors

The Controller authorises the sub-processors below. We give notice before adding or replacing a sub-processor so the Controller may object on reasonable grounds.

Sub-processorPurposeRegion
Hosting providerIsolated instance hostingEU
AI providerLanguage understanding & generationEU / contractual
NotionTasks & knowledge base (your account)Per Notion
GoogleCalendar (your account)Per Google
Messaging providerMessage deliveryPer provider

Placeholder list — specific legal entity names and regions to be confirmed before publishing.

6. Security measures

A separate, isolated instance per client; access on a need-to-know basis; encryption in transit; logging and monitoring; and regular review of measures.

7. Data-subject requests and breaches

We assist the Controller in responding to data-subject requests and notify the Controller without undue delay after becoming aware of a personal-data breach affecting its data.

8. International transfers

Where any transfer outside the EEA occurs, it is made under an appropriate safeguard such as the Standard Contractual Clauses.

9. Audits

We make available information reasonably necessary to demonstrate compliance and allow for audits on reasonable notice, subject to confidentiality.

10. Return and deletion

On exit, and at the Controller's choice, we delete or return personal data, save where storage is required by law. Your tasks and notes remain in your own tools throughout.

11. Governing law and contact

This DPA is governed by the laws of Romania and the EU. To request a signed copy, use the contact page. Ventura Global SRL, Romania.