Skip to main content
Veskyra
  • Home
  • Platforms
  • About
  • Contact
Home Platforms About Contact
Legal

Data Handling and Processing Agreement

Standard form, version 1.0, published September 28, 2026
This form becomes binding for a customer only when incorporated into that customer's accepted agreement or signed by both parties, with its schedules completed.

This Data Handling and Processing Agreement ("DPA") is between Veskyra LLC ("Veskyra") and the organization identified in the applicable Order or signature block ("Customer"). It supplements the accepted Terms of Service or other written services agreement between them (the "Agreement"). It becomes binding when expressly incorporated into an accepted Agreement or signed by both parties. The schedules form part of this DPA.

Execution condition: complete Customer and contact details, the applicable retention choices, the verified security schedule, and the separately supplied subprocessor schedule before execution. For restricted international transfers, complete the required transfer instrument and annexes before processing begins. This form is not itself a completed international-transfer agreement or BAA.

1. Scope, definitions, and roles

"Customer Personal Data" means personal information contained in Customer Content that Veskyra processes on Customer's behalf through the Services. "Data Protection Law" means privacy, security, and data-protection laws applicable to that processing. "Processing," "controller," "processor," "business," "service provider," and "contractor" have their meanings under applicable Data Protection Law. "Subprocessor" means another processor engaged by Veskyra to process Customer Personal Data on Customer's behalf. "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

Customer acts as controller/business, or as a processor with authority from the relevant controller. Veskyra acts as processor/service provider or, where Customer is itself a processor, as a subprocessor. Each party meets the obligations applicable to its actual role.

The DPA does not characterize all data in the Services as Customer-controlled. Veskyra's independently determined account administration, billing, legal-compliance, and security processing is described in the Privacy Policy and remains limited to lawful purposes. A training provider or employer receiving records for its own disclosed purposes is not automatically a Veskyra subprocessor. Available personal-vault sharing choices cannot be overridden by an organization's general instructions under this DPA. Employer-paid plan reporting and employer-sponsored discount sharing are distinct relationships, as described in the Privacy Policy. For Kyrvec, agency-sponsored visit reporting does not authorize linking a member's separate personal account or disclosing its existence or activity to the agency. Customer instructions must respect that separation; an operator's authorized processing of its own records does not give an agency access to those personal records. Our current customer offering is U.S.-only.

2. Documented instructions and purpose limitations

Veskyra processes Customer Personal Data only on Customer's documented lawful instructions to deliver and support the Services, including storage, retrieval, transmission to authorized recipients, deletion, and optional AI tasks expressly selected by an authorized user. Instructions consist of the Agreement, this DPA, the Order, authorized configuration and feature choices, and additional written directions agreed by the parties.

Veskyra does not sell Customer Personal Data; share it for cross-context behavioral advertising; use it for unrelated advertising; or use it to train, fine-tune, or improve AI models. We do not authorize a subprocessor to do so. Veskyra may also use Customer Personal Data as Data Protection Law permits service providers and processors to do, to maintain, secure, repair, and improve the Services (but not to train AI models or to build profiles for use in serving another customer), and may create and use aggregated or deidentified data that does not identify Customer or any individual. Veskyra will not attempt to reidentify that data.

Communication functions are limited to service and transactional messages and recipient-opted-in reminders. Customer may not instruct Veskyra to operate promotional campaigns through the Services. Where Customer uses an SMS alert add-on, Customer ensures that each recipient has personally opted in and promptly removes recipients who leave or withdraw. Veskyra does not use Customer Personal Data to market its own products, except to Customer's account holders and business contacts who have their own relationship with Veskyra. Independent off-platform communications are Customer's responsibility and remain subject to applicable purpose restrictions, individual choices, and law.

If law requires processing beyond Customer's instructions, Veskyra informs Customer before processing unless the law prohibits that notice. If Veskyra reasonably believes an instruction infringes Data Protection Law, it promptly informs Customer and may suspend the affected processing while the issue is resolved. It does not knowingly carry out an unlawful instruction.

Customer represents and warrants that it has provided the notices, obtained the consents and authorizations, and has the legal basis required for Veskyra to process Customer Personal Data under this DPA, and that its instructions comply with Data Protection Law and the rights of individuals and any upstream controller. Customer will not submit data outside the categories in Schedule 1, including processing that requires a HIPAA business associate agreement, unless the parties have expressly agreed in writing to support it. Each party remains responsible for its own compliance.

3. Confidentiality and personnel

Veskyra limits access to people who need it for authorized work and ensures those people are subject to confidentiality obligations or an appropriate statutory duty. It maintains appropriate access authorization and revocation procedures and trains personnel for their responsibilities. Customer Personal Data is not made available across unrelated customer workspaces merely because customers use the same infrastructure.

4. Security measures

Veskyra implements and maintains technical and organizational measures appropriate to the risk, taking into account the nature, scope, context, and purposes of processing, reasonably available technology, and the likelihood and severity of harm. The agreed measures are recorded in Schedule 2.

Veskyra may update those measures as technology or threats change without materially reducing the overall protection provided for the contracted processing. Customer remains responsible for its own access permissions, endpoints, authorized users, lawful use, and configuration within its control. Neither party guarantees that security incidents are impossible.

5. Subprocessors

Customer grants general written authorization to use subprocessors disclosed in the completed Schedule 3. Veskyra maintains an accurate list of their legal identities, services, processing locations, and relevant data categories. On request, it provides additional information reasonably needed to evaluate the processing and any transfer safeguards. Schedule 3 may be supplied to Customer as a confidential contractual attachment or through controlled customer access; this DPA does not require public posting of that register. It identifies providers and processing at the level necessary for authorization and compliance, without exposing credentials, account identifiers, internal endpoints, network diagrams, or vulnerability details. Confidentiality restrictions do not prevent legally required disclosures, regulatory access, or Customer from fulfilling its applicable obligations.

Veskyra provides at least 30 days' advance notice before adding or replacing a subprocessor that will process Customer Personal Data. Customer may object within 15 days of receiving notice on reasonable data-protection grounds. The parties work in good faith to resolve the concern through further safeguards, an alternative, or a change to the affected feature. If unresolved before processing by the new subprocessor would begin, Customer may terminate the affected Service and receive a refund of unused prepaid fees for the remaining period. Objections must be in writing and state the data-protection grounds. If Customer does not object within the 15-day period, the change is deemed approved. Termination and refund under this section are Customer's sole remedy for an unresolved objection. If a subprocessor must be replaced urgently for security, legal, or service-continuity reasons, Veskyra may do so with notice as soon as practicable, and the objection process above applies from that notice.

Before access begins, Veskyra imposes written data-protection, confidentiality, and security duties appropriate to the processing and no less protective in substance than the relevant duties under this DPA. Veskyra remains responsible to Customer for its subprocessors' performance of those duties as required by law and this DPA.

Customer-directed integrations and independent recipients are identified separately from subprocessors and cannot be used to bypass these obligations.

6. Optional AI processing

The AI Data Use Policy applies to AI tasks. An authorized user's deliberate selection of a described AI operation is an instruction for that operation, including the disclosed selected-file or batch scope. General account creation, acceptance of the Agreement, or upload to an ordinary feature is not a standing instruction to run content AI.

Veskyra uses models hosted through the infrastructure engaged for the Services. AI inputs and outputs are not used for model training, fine-tuning, or provider service improvement. Veskyra does not enable provider retention of content for those independent purposes. Temporary operational processing and Customer-directed saved records remain subject to the purposes and retention rules of this DPA.

7. Individual rights and assistance

Taking account of the nature of processing and information available to it, Veskyra assists Customer through appropriate technical and organizational measures to respond to requests for access, correction, deletion, restriction, portability, objection, and other applicable rights.

If Veskyra receives a request concerning Customer-controlled data, it promptly informs Customer and does not respond substantively on Customer's behalf except as instructed or legally required. It may acknowledge receipt and explain how to contact Customer. The parties coordinate verification using no more information than reasonably necessary.

Veskyra also provides reasonable assistance with Customer's security obligations, data-protection impact assessments, and regulator consultations relating to the Services. Ordinary assistance needed to meet this DPA is included. Any unusual customer-specific work requires prior agreement on reasonable charges where legally permitted; charges may not obstruct a mandatory duty, a lawful audit, or remediation of Veskyra's own breach.

8. Personal Data Breaches

Veskyra notifies Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and complies with applicable breach-notification law, including North Carolina General Statutes § 75-65 where applicable. When Veskyra maintains or possesses personal information it does not own or license and § 75-65(b) applies, it notifies the owner or licensee immediately following discovery of a qualifying security breach, subject only to a lawful delay. Other applicable jurisdictions' requirements also apply; choosing North Carolina law in the Agreement does not displace them. Notice goes to the security contact in Schedule 1, with a reasonable alternative contact attempt if necessary.

Available information includes the nature of the breach; affected data and individual categories and approximate numbers where known; likely consequences; measures taken or proposed to contain, remediate, and mitigate it; and a contact for follow-up. Veskyra provides information in stages without delaying initial notice solely because details are incomplete.

Veskyra promptly investigates, takes reasonable containment and remediation measures, preserves relevant evidence, and cooperates with Customer. Customer determines notices it must provide as controller, unless law requires Veskyra to notify independently. Neither party may prevent the other from meeting a legal duty. Notice is not an admission of fault.

Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, blocked sign-in attempts, or denial-of-service attacks that do not result in unauthorized access, are not Personal Data Breaches. Veskyra evaluates the available evidence before concluding that an event did not compromise Customer Personal Data.

9. Compliance information and audits

Veskyra makes available information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable written security questionnaires, summaries of its security measures, and any independent reports it holds. This does not imply that Veskyra holds a particular certification.

If that information does not reasonably demonstrate compliance with an obligation that Data Protection Law requires Customer to verify, Customer may audit Veskyra's processing of Customer Personal Data, itself or through an independent auditor that is bound by confidentiality and is not a Veskyra competitor. Audits take place no more than once in any 12-month period, on at least 30 days' written notice, during normal business hours, under a scope and plan agreed in advance, and without access to other customers' data, to systems in a way that could affect their security or availability, or to Veskyra's privileged or unrelated confidential information. Customer bears its own audit costs and reimburses Veskyra's reasonable costs for time exceeding one business day. The frequency and notice limits do not apply to an audit required by a regulator or following a Personal Data Breach affecting Customer Personal Data.

Veskyra informs Customer if it can no longer meet material obligations under this DPA and cooperates in reasonable steps to stop and remediate unauthorized processing.

10. Retention, return, and deletion

During the term, Veskyra follows Customer's lawful retention and deletion instructions within the supported service configuration. After the Services end, at Customer's choice, it returns Customer Personal Data in a reasonably usable supported format or deletes it, and deletes remaining copies unless law requires retention. The agreed export window, nonpayment cure period, and deletion schedule appear in Schedule 1 and must be consistent with the Agreement.

Ordinary service access ends at effective cancellation, expiration, or suspension for nonpayment. For 90 days after that event, an authorized Customer representative may request a standard raw export and discuss reactivation. Ending future renewal does not shorten the paid term or start the window early. Export includes Customer's records and attachments, with available relationships and identifiers needed to interpret them, without requiring a full application replica or another party's protected content. Standard export is included; custom migration work requires a separate agreement.

After the 90-day window, or an authorized earlier deletion instruction, active-system deletion occurs within 30 days, and residual backups expire within 90 additional days. Veskyra gives notice of the export deadline and impending deletion. Applicable shorter legal deadlines control. The separate 180-day consumer reactivation/export window does not extend this organizational window or control independently retained provider learning records.

Backup copies remain protected and unavailable for ordinary business processing while awaiting expiry. If restored for disaster recovery, deletion instructions are reapplied. Legally retained copies are isolated or access-restricted, used only for the retention purpose, and deleted when no longer required. Veskyra explains the legal retention requirement unless prohibited and confirms completion of deletion on reasonable request.

Deletion of an individual account does not automatically authorize destruction of Customer's incident, employment, or education records. Customer must also respect valid rights requests and may not use this distinction to retain data unlawfully. Customer must identify relevant statutory recordkeeping or public-record obligations and preservation holds, and obtain and verify exports before the deadline. Neither expiration of a window nor cancellation authorizes unlawful destruction. Where a law applicable to Veskyra or a binding hold requires preservation, Veskyra retains the necessary records with restricted access. The parties must separately arrange any longer archive or hosting service needed; the ordinary subscription does not promise perpetual hosting after cancellation. A KorLea provider's course-access promise to learners, including a lifetime offer, does not amend Veskyra's hosting or retention obligations without a separate agreement. Customer must disclose and fulfill its learner access and completion-record commitments and arrange an appropriate continuation or migration when leaving the platform, subject to applicable law.

11. International transfers

The present customer offering is U.S.-only. Processing locations are identified in the schedules; customer location does not determine where every service provider processes data. Neither the Agreement nor this DPA promises a particular residency location unless expressly stated in an Order and supported by the actual configuration.

If processing ever requires a restricted international transfer mechanism, such as EU standard contractual clauses or the UK Addendum, the parties will execute the applicable instrument and complete its annexes before that processing begins. That instrument prevails over this DPA to the extent it requires. This DPA does not itself provide an international transfer mechanism.

12. U.S. state service-provider and processor terms

Where applicable U.S. state privacy law requires such terms, Customer discloses personal information to Veskyra only for the limited and specified business purposes in Schedule 1. Veskyra complies with applicable obligations and provides the required level of protection.

Veskyra will not sell or share Customer Personal Data, retain/use/disclose it outside the specified purposes or the direct business relationship except as permitted by law, or combine it with personal information obtained from other customers or its own interactions except as expressly allowed for the contracted purposes by applicable law. Veskyra certifies that it understands and will comply with these restrictions.

Customer may take reasonable and appropriate steps to confirm consistent use, and, after notice, stop and remediate unauthorized use. Veskyra notifies Customer if it determines it can no longer comply. Subprocessor contracts must preserve applicable restrictions. Nothing converts a disclosure that legally constitutes a sale or another regulated use into permitted processor activity merely by labeling it service provision.

13. Liability, order of precedence, and term

The Agreement's liability allocation applies to this DPA to the extent lawful, including the aggregate cap of the greater of qualifying fees paid for the affected Service during the preceding 12 months or US $100, as defined in the Terms. The DPA does not create an additional or separate cap. It does not limit liabilities that applicable law does not allow to be limited.

This DPA controls conflicting provisions concerning processing of Customer Personal Data. An applicable executed BAA and mandatory transfer instrument control their respective subject matter. Amendments require the agreement mechanism permitted by the underlying contract and applicable law; an update to a website does not silently reduce an executed DPA's safeguards.

Disputes between Customer and Veskyra under this DPA follow the underlying Agreement's validly accepted dispute-resolution provisions, including Terms Section 15 when applicable. A valid arbitration opt-out continues to apply. This DPA does not independently impose arbitration, bind data subjects who have not agreed, waive regulatory powers, or override mandatory transfer rights or a legally authorized government-customer agreement.

This DPA continues for as long as Veskyra or its subprocessors retain Customer Personal Data, including protected backup or legally retained copies.

Schedule 1 — Processing details and contacts

ItemDescription
Customer and role[LEGAL NAME, ADDRESS, AND CONTROLLER/PROCESSOR ROLE]
Customer privacy/security contact[NAME OR ROLE, EMAIL, INCIDENT ESCALATION CONTACT]
Veskyra contactVeskyra LLC; legal service address: 4030 Wake Forest Rd Ste 349, Raleigh, NC 27609, United States; privacy requests: privacy@veskyra.com; security incidents and vulnerabilities: security@veskyra.com; legal/contractual notices: legal@veskyra.com.
Services and subject matter[IDENTIFY PURCHASED PRODUCTS]. Hosting, administering, and supporting organizational operational records, credentials, or training, as applicable. Kyrvec covers supported shooting-range operations such as memberships/bookings, waivers, access events, agency arrangements, and permitted non-firearm transactions. Firearm sales, associated sale-verification processing, and firearm-sale record/summary integrations are outside the permitted scope.
Purposes and operationsCollection on instruction; organization; storage; retrieval; authorized display, analysis, export, transmission, correction, and deletion; security and support; specifically selected AI extraction or editing.
IndividualsAuthorized users, employees, contractors, learners, customers, incident subjects, witnesses, property occupants, and other people lawfully represented in Customer's records. Kyrvec may additionally include members, guests, agency personnel, emergency contacts, and minors represented by authorized adults. Narrow to the purchased use.
Data categoriesIdentity/contact and organization information; operational reports; attachments; training and assessment records; credentials and renewal data; selected AI input/output only for products with AI; related audit information. For Kyrvec, include applicable waivers/signing evidence, approved derived verification fields, memberships, bookings, visits/access events, agency qualifications, and transaction or performance records. Verification-only source material is discarded after verification. Any retained identifying fields or signing evidence must be specified for the contracted service and have a separate lawful purpose; this schedule does not authorize persistent storage of verification-only SSNs or ID images. Kyrvec has no AI and permits no independent minor logins. Narrow to the contracted purposes.
Sensitive categoriesInjury/health information, locations, identification or regulatory records, and other sensitive content only where lawful, necessary, and supported. Reskyr serves non-transporting fire/rescue departments; Ryskra serves non-healthcare businesses. HIPAA-regulated processing requiring a BAA is excluded from the standard service; no present BAA-ready offering is represented. [SPECIFY ACTUAL CATEGORIES AND EXTRA SAFEGUARDS.]
Frequency and durationContinuous or intermittent processing during use and the approved retention period; AI only upon authorized feature selection.
Retention and exportSection 10 applies unless a mandatory or separately agreed customer-specific schedule is identified in the applicable Order or this Schedule.
Locations and transfers[COMPLETE FROM ACTUAL CONFIGURATION; IDENTIFY ANY RESIDENCY COMMITMENT AND EXECUTED TRANSFER INSTRUMENT.]
Upstream controller, if applicable[IDENTIFY OR REFERENCE CUSTOMER'S VALID AUTHORIZATION.]

Schedule 2 — Technical and organizational measures

Required contractual measures for the covered Services, not an audit report or representation of ISO, SOC, HIPAA, or other certification. Any lawful, agreed service-specific variation must be recorded expressly before execution.

AreaRequired measure
AccessRole-based authorization, least-privilege administrative access, strong administrative authentication, review and timely removal of access, and confidentiality duties.
Tenant separationEnforce organization and record authorization in relevant application and storage operations; restrict cross-customer access.
EncryptionEncryption of personal data in transit over public networks and at rest in production storage and backups, with restricted access to credentials and key-management functions.
Application securityControlled change management, security review proportionate to changes, dependency/vulnerability remediation, and separation of production secrets from public source and logs.
LoggingAccess/security records appropriate to detection and investigation; avoid unnecessary sensitive-content logging; restrict access and apply defined retention.
AI handlingApproved hosted model routes, user-initiated processing, no training authorization, scoped task inputs, and defined handling of prompts, results, temporary files, and errors.
Availability and recoveryBackup and restoration processes, protection of retained copies, recovery procedures, and periodic recovery testing appropriate to contracted services.
Incident responseDocumented assessment, containment, escalation, notification, and remediation procedures with assigned responsibility.
Data lifecycleDefined active-data and backup deletion, authorized exports, rights-request handling, and instructions reapplied after recovery.
Suppliers and personnelSupplier confidentiality and processing terms, risk-based due diligence, personnel security instruction, and access restrictions.
ReviewPeriodic assessment of safeguards and correction of identified weaknesses proportionate to risk.

Schedule 3 — Subprocessor authorization record

Confidential attachment to be completed before execution. The parties identify the applicable register by title, version/date, and attachment or controlled-access reference: [COMPLETE REGISTER REFERENCE]. The register is supplied to Customer and forms part of this DPA; it need not be published with the public policy pages. General vendor categories do not replace the provider identities in this contractual authorization record.

For each direct subprocessor, record its legal name, function, data categories, processing countries, applicable transfer mechanism, and effective date. Distinguish the direct contracting entity from its own downstream infrastructure providers. Identify services with a separate controller role outside this list and explain that role. Record the notice channel and Customer contact for changes. Include hosted AI processing and any support, communication, or monitoring provider that can access Customer Personal Data, not just database and storage vendors.

Acceptance if not incorporated by an accepted Order

CustomerVeskyra LLC
Legal name[COMPLETE]Veskyra LLC
Authorized signatory[COMPLETE][COMPLETE]
Title[COMPLETE][COMPLETE]
Signature and date[COMPLETE][COMPLETE]
Order/agreement reference[COMPLETE][COMPLETE]
Veskyra

Focused platforms for underserved industries.

  • Platforms
  • Reskyr
  • Kyrvec
  • Ryskra
  • ValKred
  • Contact
  • hello@veskyra.com
© 2026 Veskyra LLC. Raleigh, NC. All rights reserved. Privacy · Terms · Status