Data Processing Agreement
Last Updated: March 26, 2026
This Data Processing Agreement ("DPA") forms part of the Master SaaS Service Agreement or Terms of Service (as applicable) between TrueSense Solutions LTD (DBA "Vest" or "Company") and the Customer. In the event of conflict between this DPA and the main agreement, this DPA governs with respect to data processing matters.
1. Definitions
"Applicable Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data, including the Israeli Protection of Privacy Law 5741-1981 and its regulations, the EU General Data Protection Regulation (GDPR) 2016/679, and any other applicable national or state privacy laws.
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Vest on behalf of the Customer under the Agreement.
"Processing" has the meaning given in Applicable Data Protection Laws and includes any operation performed on Personal Data.
"Data Subject" means the natural person to whom Personal Data relates (e.g., an employee or equity grantee whose data is managed through the Platform).
"Customer Data" means all Personal Data uploaded to or generated within the Platform by or on behalf of the Customer.
"Sub-processor" means any third party engaged by Vest to process Personal Data on Vest's behalf in connection with the Services.
2. Roles
2.1 The Customer is the controller of Customer Data — it determines the purposes and means of processing.
2.2 Vest is the processor — it processes Customer Data solely on the Customer's instructions and for the purpose of providing the Services.
2.3 Where the Customer itself acts as a processor for its own clients (e.g., a trustee, law firm, or financial advisor managing equity data on behalf of third-party companies), the Customer warrants that it has the authority to enter into this DPA on behalf of those clients and to instruct Vest accordingly.
3. Processing Instructions
3.1 Vest shall process Customer Data only:
- as necessary to provide the Services described in the Agreement; and
- in accordance with the Customer's documented instructions, including those set out in this DPA.
3.2 Vest shall promptly notify the Customer if, in Vest's reasonable opinion, an instruction would violate Applicable Data Protection Laws.
3.3 Vest shall ensure that all personnel authorized to process Customer Data are bound by appropriate confidentiality obligations.
4. Nature of Processing
| Subject matter | Equity management: cap table management, equity grant management, expense calculations, document processing |
| Duration | For the term of the Agreement and the post-termination retention period as set out in Section 9 |
| Nature | Storage, AI-powered data extraction from uploaded documents, calculation, reporting, export |
| Purpose | Providing the Vest platform services as described in the Agreement |
| Data categories | Employee and grantee PII (name, email address, ID/passport number, address); compensation and salary data; equity grant terms (grant date, exercise price, number of options, vesting schedule); uploaded documents (e.g., grant agreements, board resolutions, equity plan documents, share purchase agreements, exercise notices); financial calculations |
| Data subjects | Employees, officers, and consultants of the Customer and its managed companies who are granted equity; the Customer's authorized users |
5. Customer Obligations
5.1 The Customer represents and warrants that:
- it has a valid lawful basis for processing Customer Data and for instructing Vest to process it;
- it has provided all required notices and obtained all required consents from Data Subjects where required by Applicable Data Protection Laws;
- the Customer Data submitted to the Platform is limited to what is necessary for equity management purposes.
6. Sub-processors
6.1 The Customer grants Vest general authorization to engage Sub-processors to assist in providing the Services.
6.2 Vest's current Sub-processors are listed in Exhibit A. Vest shall ensure that Sub-processors are bound by data protection obligations materially equivalent to those in this DPA.
6.3 Vest shall remain liable to the Customer for the acts and omissions of its Sub-processors to the same extent Vest would be liable if performing the services directly.
6.4 Vest shall notify the Customer by email of any addition or replacement of Sub-processors. If the Customer cannot accept a Sub-processor change, the Customer may terminate the affected services in accordance with the Agreement.
6.5 Sub-processor change notifications are sent to the Customer's account email address. For questions, contact privacy@get-vest.com.
7. Security
7.1 Vest shall implement and maintain appropriate technical and organizational security measures to protect Customer Data against unauthorized access, disclosure, alteration, or destruction, as described in Exhibit B.
7.2 Access to Customer Data is limited to Vest personnel who require it for the performance of the Services, and such personnel are subject to confidentiality obligations.
7.3 The Customer is responsible for maintaining the security of its account credentials and for managing user access controls within the Platform.
8. Security Incidents
8.1 Vest shall notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any confirmed security incident involving unauthorized access to, disclosure of, or loss of Customer Data.
8.2 Such notification shall include (to the extent known at the time): the nature of the incident, the categories and approximate volume of Customer Data affected, the likely consequences, and the measures taken or proposed to address the incident.
8.3 Vest shall cooperate with the Customer's reasonable requests to provide information necessary for the Customer to meet its own notification obligations under Applicable Data Protection Laws.
8.4 Notification of a security incident does not constitute an admission of fault or liability by Vest.
9. Retention and Deletion
9.1 Vest shall retain Customer Data for the duration of the Agreement.
9.2 Upon termination or expiry of the Agreement:
- Days 1–90 (Transition Period): The Customer retains read-only access to the Platform solely for data retrieval and export in a structured, machine-readable format (e.g., CSV, JSON), at no additional charge.
- After 90 days: Vest shall securely delete all Customer Data from its active systems. Backup copies are deleted in accordance with Vest's standard backup retention cycle (approximately 30 days).
9.3 Upon written request, Vest shall provide written confirmation of deletion.
9.4 Security audit logs (access and action records) are retained for 24 months for security, forensic, and compliance purposes. These logs are subject to the same confidentiality obligations as Customer Data and are not used for any commercial purpose.
9.5 Vest may retain certain data for longer periods where required by applicable law (e.g., for regulatory or tax compliance). Such retained data remains subject to the obligations of this DPA.
10. Data Subject Rights
10.1 Vest shall promptly notify the Customer if it receives a request from a Data Subject exercising rights under Applicable Data Protection Laws (e.g., access, rectification, erasure, portability).
10.2 Vest shall not respond to such requests on the Customer's behalf but shall provide the Customer with reasonable assistance to enable the Customer to respond.
10.3 The Customer is responsible for handling Data Subject requests in relation to Customer Data.
11. Cross-Border Data Transfers
11.1 Customer Data may be transferred to and processed in countries outside the EEA in connection with Vest's Sub-processors (primarily the United States).
11.2 All cross-border transfers shall use lawful mechanisms, including:
- Transfer to Israel, which holds an EU adequacy decision under GDPR;
- Standard Contractual Clauses (SCCs) as approved by the European Commission, where applicable;
- The EU-US Data Privacy Framework, where applicable;
- Any other mechanism recognized under Applicable Data Protection Laws.
11.3 Upon request, Vest shall provide information about the transfer mechanisms applicable to specific Sub-processors.
12. Audit Rights
12.1 Upon reasonable written request (no more than once per 12 months), Vest shall make available to the Customer information reasonably necessary to demonstrate Vest's compliance with this DPA, including available security summaries or certifications.
12.2 Where documentation is insufficient to satisfy the Customer's compliance inquiry, Vest shall allow the Customer to conduct a reasonable audit via questionnaire or personnel interview, subject to reasonable confidentiality protections and at the Customer's cost.
13. Governing Law
13.1 This DPA is governed by the laws of the State of Israel. The competent courts of Tel Aviv-Jaffa shall have exclusive jurisdiction.
13.2 For Customers subject to GDPR, this DPA shall be interpreted consistently with GDPR requirements, and in the event of conflict, GDPR requirements shall prevail.
14. Contact
Privacy and data protection inquiries: privacy@get-vest.com
15. Order of Precedence
15.1 In the event of conflict between this DPA and the main Agreement (including the Terms of Service), the terms of this DPA shall prevail with respect to the processing of Personal Data.
15.2 Where a negotiated enterprise agreement contains data protection provisions more protective than this DPA, those provisions shall apply to the relevant customer.
Exhibit A – Sub-processors
| Sub-processor | Purpose | Country |
|---|---|---|
| Base44 (Wix.com Ltd.) | Cloud infrastructure, hosting, data storage, and application services | Israel / US |
| Google LLC (Google Cloud Platform) | Cloud infrastructure, AI services, data storage, and analytics | US |
| OpenAI, Inc. | AI processing services | US |
| Plus Five Five, Inc. (Resend) | Communication and notification services | US |
Each sub-processor is bound by a data processing agreement with data protection obligations materially equivalent to those in this DPA.
Exhibit B – Technical and Organizational Security Measures
Vest implements the following measures to protect Customer Data:
Access Controls
- Authentication required for all platform access
- Role-based access controls limiting data access to authorized personnel
- Audit logging of all access and actions with timestamps
Data in Transit
- All data transmitted to and from the Platform is encrypted using TLS 1.2 or higher
Data at Rest
- Customer Data stored within Vest's infrastructure is encrypted at rest per the security standards of Vest's infrastructure provider
Personnel
- Vest personnel with access to Customer Data are subject to confidentiality obligations
- Access to Customer Data is limited to personnel with a business need
Incident Response
- Internal incident response process with escalation procedures
- Customers notified within 72 hours of a confirmed incident
Sub-processor Security
- Vest reviews sub-processors' security posture prior to engagement
- Sub-processors are contractually required to maintain appropriate security measures
Security Architecture
- Vest implements application-level security controls including authentication, role-based access, audit logging, and data processing safeguards
- Infrastructure security is provided by enterprise-grade providers (Base44/Wix and Google Cloud) under contractual data protection agreements, including penetration testing at least annually