# VenturePath Business Data Processing Addendum: Owner and Counsel Review Copy

**Version:** 0.1 · **Review date:** 25 July 2026

> This outline is for counsel and institutional procurement review. It is not an executed DPA.

## Parties and roles

Customer/controller: `[INSERT]`  
VenturePath/processor: `[INSERT LEGAL ENTITY]`

The Customer controls personal data submitted to its workspace and documents its lawful instructions. VenturePath processes that data only to provide, secure, support, and legally administer the service, unless legally required otherwise.

## Processing details

- Subject matter: hosted venture-planning, research, collaboration, AI-assistance, and export service.
- Duration: agreement term plus documented deletion/backup expiry.
- Data subjects: customer users, invited team members, mentors/reviewers, research participants, prospects/suppliers entered by the Customer.
- Data: account/role data, venture content, research notes, comments, files, logs, AI inputs/outputs, support data.
- Special data: prohibited unless expressly authorized in a signed schedule with additional controls.

## Processor commitments

VenturePath will:

- process only documented lawful instructions and notify the Customer of an apparently unlawful instruction where permitted;
- ensure confidentiality, training, least privilege, and access logging;
- implement appropriate technical and organizational security measures;
- maintain a current subprocessor register, flow down equivalent duties, and provide change notice/objection handling;
- assist with rights requests, DPIAs, regulator consultations, records, audits, and verified deletion/return;
- notify the Customer without undue delay after becoming aware of a personal-data breach and provide available facts/cooperation;
- not sell customer personal data or use it for advertising;
- not use it for shared-model training without a separate written opt-in; and
- provide information reasonably needed to demonstrate compliance.

## Transfers

List each processing country/region and transfer mechanism. For Qatar-origin data, assess PDPPL Article 15 and serious-damage safeguards. For EEA/UK data, attach the applicable approved transfer clauses/addendum and transfer-risk measures. Customer-specific localization requirements must be scheduled.

## Security schedule

Minimum controls: verified authentication; MFA for privileged roles; server-side tenant authorization; RLS; encrypted transport/storage; secure secrets; SDLC and reviewed migrations; dependency/secret scanning; tested backup/restore; logging/monitoring; incident response; vendor due diligence; vulnerability handling; deletion verification; and independent assessment before broad launch.

## Audit

Use a proportional assurance ladder: current security documentation and reports; questionnaire; independent report/certification when available; then scoped audit if those are insufficient. Protect other customers’ confidentiality and system security.

## End of service

On instruction or termination, export and delete active Customer Personal Data within the agreed period, subject to disclosed recovery/backup expiry and documented legal hold. Provide deletion confirmation upon request.

## Required schedules

1. Processing description and instructions
2. Security measures
3. Subprocessors and locations
4. Transfers
5. Retention/deletion
6. Customer-specific restrictions
7. Applicable Qatar/EU/UK/other clauses
