LIVE RELAY|UTC —
SYNC

← Procurement hub

# Velaru Data Processing Agreement — Template (v0)

**Between:** Nisaba LLC ("Processor") and **[Carrier / Client Name]** ("Controller")

## 1. Subject matter

Processor provides AI decision audit receipt services: classification, signing, verification, pre-dispute evidence bundles, and carrier mandate compliance reporting.

## 2. Duration

Term matches the Statement of Work or subscription period.

## 3. Nature and purpose

Generate tamper-evident, independently verifiable records of AI-assisted decisions for underwriting, claims, and regulatory defensibility.

## 4. Types of personal data

May include employment-related messages, applicant data in hiring verticals, and metadata in signed receipts. Controller determines lawful basis and data minimization.

## 5. Controller obligations

- Provide lawful instructions
- Obtain consents where required
- Configure domains and retention appropriately

## 6. Processor obligations

- Process only on documented instructions
- Implement appropriate technical measures (Ed25519 signing, hash chain, access controls)
- Notify Controller of confirmed breaches without undue delay
- Assist with verification and audit requests per SOW

## 7. Subprocessors

- OpenAI / Anthropic (classification inference) — when Controller routes through Velaru classify API
- Render.com (hosting)
- GitHub Gist (optional external anchor)
- FreeTSA / DigiCert (optional RFC 3161 timestamps)

## 8. International transfers

Production hosted in United States. Controller responsible for transfer mechanisms where applicable.

## 9. Deletion

Upon termination, Processor deletes or returns data per SOW unless retention required by law or active dispute hold.

## 10. Liability

As set forth in the governing MSA or SOW.

---

*Template only — not legal advice. Counsel should review before execution.*

**Live URL:** https://velaru.onrender.com/procurement/dpa