Data Processing Agreement
For venues whose guests are in the EEA, the UK or anywhere with similar rules. In effect from 8 October 2026. On 8 October it added in section 6 that encrypted copies of the daily backups are also kept in OVHcloud’s Beauharnois region in Canada. It also removed the stopped server that held archives from before our September 2026 move, which has been deleted (sections 4 and 5). On 7 October it named Resend, which now sends vFound’s service email, as a sub-processor in section 4, and added in section 2 the record of whether each email was delivered, kept 90 days without the address (section 9). On 6 October it added one-time sign-in links by email to the security measures in section 6. On 5 October it stopped describing spoken requests in Ask vFound, which no longer takes them, and added how long background tasks that could not finish, disconnected AI assistant connections and error reports are kept. On 4 October it added email to inventory, the weekly insights and their Monday email, photo splitting and duplicate checks, what is withheld from the AI, how long what the AI wrote is kept, and what stays after an account is closed, and it clarified the closed-account exports and when a hotel stay is deleted, a venue owner’s right to take their venue out of a customer group, and that a platform administrator’s reads and refused changes of customer records are logged, and that describing a lost checkroom ticket to the AI sends no ticket notes. On 3 October it added the private, minimal hotel stay context used by Lost & Found and Parcels, with manual, CSV and API input, source freshness and separate room-at-event history, and customer groups with regional access, aggregate oversight and explicit per-venue policy application. It also covers customer-configured named operating-policy versions, local exceptions, acknowledgements and aggregate service-level alerts, which remain off until a group manager configures them. On 3 October it also covers a customer-authorised Cloudbeds connection limited to read:reservation and OfficeRnD Flex and Microsoft Entra ID connections limited to source ID, name, email and active status for the shared people list. The Cloudbeds reader keeps only the minimal stay context described below and never changes provider records. The OfficeRnD reader excludes memberships, bookings, invoices, payments, custom properties, addresses and phone numbers; the Entra reader never creates vFound staff accounts, roles or access decisions. It also states that deactivation prevents new assignments while authorised venue staff can resolve open parcels, equipment, reservations and visitor records. On 2 October it added optional private visitor photos, photo badges and a staff-recorded visual check of a physical photo ID, with no ID document image or number stored and no automated verification, facial recognition or watchlist screening. On 25 September it began to cover vFound Parcels, vFound Checkroom, vFound Equipment and vFound Visitors, directory connections and My vFound pages. On 26 September it added Checkroom stations, events, its exit queue, kiosk self check-in and fee recording. On 28 September it added that every product’s records can be exported for 90 days after an account closes, that My vFound links expire after 60 days and can be reset, that people-list email addresses are shown in full only to owners and managers, that a visitor type can follow the venue’s retention period, that lost-item report links expire after 30 days, that a host’s browser alerts end when they leave the people list, and that Slack host connection records and the Checkroom phone wallet option are no longer kept or offered. The previous version was dated 6 October 2026.
This agreement is between the venue using vFound (the controller) and Naltyx Data and Marketing Consulting (the processor), and applies where we process personal data on your behalf under the UK GDPR, the EU GDPR, Canadian privacy law or comparable legislation.
1. Subject matter and roles
You decide why and how personal data about your guests and claimants is processed. We process it only to provide vFound to you. For your own account, staff sign-in, billing and our own optional return-shipping transaction and fulfilment data we act as a controller. The venue still controls its ownership claim and release decision. That is covered by our Privacy Policy, not by this agreement.
Optional Google Analytics on the public marketing website is separate controller processing described in our Privacy Policy. It does not receive venue records, signed-in workspace activity or private guest workflows and is not a sub-processor of the venue records under this agreement.
2. Details of the processing
- Subject matter: providing lost-and-found software: publishing found items, receiving and managing ownership claims and lost-item reports, alerts, pickups and returns, and messaging between your team and a guest; and, if you switch on vFound Parcels, logging parcels your venue receives for people and handing them over; and, if you switch on vFound Checkroom, checking guests' coats, bags and luggage in, recording stations and events, preparing them from an exit queue, recording optional fees and handing them back; and, if you switch on vFound Equipment, recording assets, reservations, multi-item and kiosk checkouts, borrower requests, maintenance and stock-takes, taking equipment back and, within an authorised customer group, recording transfers between venues; and, if you switch on vFound Visitors, registering and approving visitors, creating multi-day passes, signing them in and out at a desk or paired kiosk, telling and receiving short replies from the people they came to see, importing verified calendar invitations, running roll calls, printing badges and recording couriers; and, where your venue uses it, keeping a minimal private hotel stay reference current for found items and parcels, including through a customer-controlled, read-only Cloudbeds connection; giving a customer that owns several venues an aggregate group command centre with group and regional access and explicit per-venue policy application and, when it opts in, named versioned operating policies, local exceptions, acknowledgements and aggregate service-level monitoring; keeping your people list current from a CSV link or automatic provisioning; and giving each person a signed page for their own linked records.
- Duration: for as long as your plan is active, plus the retention period in section 9.
- Nature and purpose: hosting, storage, display, transmission by email, backup, security monitoring and deletion; transmission of an optional browser alert at the person’s request, from 25 October 2026 or sooner where you have agreed to the push services (see the notice below); AI suggestions and translation where you keep vFound AI switched on (section 4); looking up the approximate city of a claim’s IP address; and sending data to services you connect yourself, such as Slack, Microsoft Teams, Google Chat, the calendar apps your team adds a private calendar link to, a directory or CSV source you choose, a hotel property or coworking member system you authorise, your own systems through our API and webhooks, or an AI assistant your owner or manager connects by signing in, which are yours to choose and instruct and not our sub-processors. An assistant you connect reaches only the tools its permissions allow, for the products you have open, and stops at once when you disconnect it; you pay for it and are responsible for your agreement with its provider.
- Types of personal data: claimant name, email address, optional phone number, description of the lost item, place and date of loss, answers to verification questions, photographs uploaded as proof, messages with your team, submitting IP address and the approximate city and region derived from it; for a lost-item report or alert, the guest’s name, email, optional phone, what they lost and any item-location link they add; for a return, a shipping address or the name and signature given at pickup, a booked pickup time and any feedback; for vFound Parcels, the name, email, room or apartment and any reference of each person on your parcel list, and for each parcel a photo of its label, the carrier, tracking number and sender, where it is kept, handling instructions, reminder snooze or hold date, desk arrival, delegate name and email, the notices sent, and the name, optional pickup photo and any signature of whoever collected it; for outgoing parcels and delivery rounds, the destination, courier or recipient and handover signature; for vFound Checkroom, a photo of what a guest handed in, its number and, where given, the guest's name, email, room and ticket language, its station, event and storage location, each piece's letter, type, storage location and hand-back state, a request to have it ready, any fee, currency and whether it was recorded as cash or an external POS or card payment, and who collected each piece, with a signature for a lost ticket; for vFound Equipment, each borrower's name and, where given, email, ID or reference and email language, what they borrowed and when it is due, the notices sent, any signature, reservations and their dates, approval state, extension requests and problem reports, and how each item came back with any note and photo; equipment asset fields, which can include a serial number, value, purchase and warranty dates and venue-defined fields, plus maintenance and stock-take records; and, for a group transfer, the owning, source, destination, service and custody venues, source and destination locations and codes, status, times, operational notes and the team members who performed its steps; for vFound Visitors, who they came to see and when they arrived and left, and, where given, their email, company, reason for visiting, expected time, valid dates, recurrence and email language, their visitor type and answers to your questions, the invitation sent, approval state, host reply, roll-call status and a copy of your visitor terms, that they agreed and any signature; where you enable them, a private visitor photo and the staff member and time of a visual check of a physical photo ID, but no image or number from that ID; for calendar intake, organizer and attendee names and addresses, meeting identifier, sequence and times, with no meeting description; for paired kiosks, the device name, random token, permitted actions and last-seen time; AI suggestions about items, claims, parcel labels and equipment you add; meeting invites your team pastes or forwards to vFound Visitors (a forwarded invite is kept up to 30 days); for email to inventory, each photo your team emails to the venue’s private address, with the sender’s email address, the subject and the first 500 characters of the message (kept up to 30 days); the requests your team makes in Ask vFound and the actions it suggests; for each email vFound sends, whether it was delivered, bounced or marked as spam, the provider’s reason with any email or IP address removed, the recipient’s domain and a one-way hash of the address, but not the address itself (kept 90 days); and, when a person turns on browser alerts, the browser push address, public encryption key, authentication token, expiry and delivery result linked to their account, pass, ticket or signed service-email record; and for a connected people directory, its encrypted CSV link, source identifier, active status and sync results; for a connected hotel property system, its encrypted credential and settings, connection state, sync cursor, timestamps, counts and bounded error history; for a connected OfficeRnD or Microsoft Entra directory, its encrypted application credential and source settings, connection state, sync cursor, timestamps, counts and bounded error history, and only the source ID, name, email and active status used in the people list; and for a hotel stay, its manual, CSV, API or property-system source, stable stay reference, optional stable guest reference, guest name, arrival, departure, source timezone, current room, state, source update time, sync time and the room recorded when a linked item or parcel entered vFound. The hotel stay context does not include room rate, payment or card data, loyalty status, passport or ID data, guest preferences or unrelated reservation notes. For a customer group, the data also includes its name, venue and region mappings, members and roles, policy templates, named operating-policy versions and targets, venue assignments, local exception reasons and expiry dates, acknowledgements, aggregate venue and service-level counts, alert notification times and group audit history. Aggregate group responses and escalation emails do not contain operational record details.
- Categories of data subject: people who claim items from your venue, report a lost item or set an alert, people your venue receives parcels for, guests who use your checkroom, people who borrow your equipment, visitors to your venue and the people they come to see, hotel guests whose minimal stay context your venue links to an item or parcel, coworking members on a connected people list, and members of your team.
- Special category data: not requested and not required. You must not publish identity documents, payment card details or sensitive personal data found in or on an item.
3. Our obligations
We will:
- process personal data only on your documented instructions, your use of the product, and this agreement, are those instructions, unless the law requires otherwise, in which case we will tell you first unless that law prohibits it;
- ensure people authorised to process the data are bound by confidentiality;
- implement the security measures described in section 6;
- not sell the data, use it for our own marketing, or use it to train AI models;
- tell you if in our opinion an instruction infringes data protection law.
4. Sub-processors
You give general authorisation for the sub-processors below. We remain liable for their performance of these obligations.
- OVHcloud: application, database and file hosting in Singapore, including our own mail server, which receives the photos your team emails to vFound.
- Resend (Plus Five Five, Inc.): sends vFound’s service email from 7 October 2026. It receives each email’s recipient address, subject and content, and tells us whether the email was delivered, bounced or marked as spam. It processes data in the United States, where it sends through Amazon Web Services, under its data processing addendum, which includes the EU Standard Contractual Clauses.
- Cloudflare: bot protection on public forms.
- ipapi.co: IP-to-approximate-city lookup used to help you assess a claim.
- OpenRouter (OpenRouter, Inc.): AI gateway for venues that keep AI assistance switched on: suggesting item details and search words from item photos; reading a parcel's label photo to suggest who it is for, the carrier and the tracking number; ranking possible matches for a guest's description or search photo (used once, not kept by vFound); checking a claim against the item record (including its private description and internal notes) and proof photos as a suggestion for staff, who make every decision; translating messages between guests and staff and drafting staff replies; structuring a guest's lost item chat, which never asks for contact details; suggesting a name for equipment from its photo; turning a team member's typed request in Ask vFound into a suggested action (phone numbers removed first; the records found are never sent); telling whether a workspace camera photo shows a found item or a parcel label (codes are read on the device); reading meeting invites you paste or forward into suggested visits (links, passcodes, phone numbers and place lines removed first); comparing the description your team types of a checkroom item (email addresses, links and phone numbers removed) with that night's item photos and item types (never ticket notes, or the name, email address or room on a ticket); and cutting a photo that shows several items into one photo per item; comparing a newly logged item's photo and description with up to three earlier items to flag a possible duplicate; wording the daily summary on the workspace home page and the checkroom's end of night summary from counts only; and writing a weekly read of your venue's numbers from the venue name and aggregate counts, rates, item categories and the places guests said they lost things (never a guest's name or contact details), shown on the dashboard and emailed every Monday to your owners and managers unless you switch the email off. Nothing suggested is applied to a record or sent to a guest until a person on your team confirms it. Photos of items already flagged as showing personal details are not sent again, and an answer to a verification question that asks for a passcode, password, PIN, phone number, address, date of birth or full name is not sent. Proof photos a claimant uploads are sent as supplied when AI is on for your venue. Requests pass to the model provider (Google, with an OpenAI model as a backup run by OpenAI or Microsoft Azure), which may process them in the United States or other countries. Every request asks for zero data retention: only providers that keep no copy and do not use the data to train models are used, and OpenRouter keeps no copy of the content and does not train on it.
- Google (Google Workspace): our support mailbox, where messages about your venue’s data may arrive.
Stripe validates the card used to start a trial and handles billing for a vFound subscription. If you record a Checkroom fee collected in cash or through your own external POS or card terminal, that provider is yours to choose; vFound receives no such Checkroom payment or card details. Optional one-time return-shipping payments are handled separately by Stripe.
We aim to give 30 days’ notice before adding or replacing a sub-processor. When a provider has to be replaced at once to keep the service working, for example when email stops arriving, we make the change first and tell you at the time, on this page and in the owner email. If you reasonably object on data-protection grounds within 30 days of the notice, we will work with you in good faith on an alternative; if none is workable, you may terminate the affected subscription and receive a pro-rata refund of fees paid for the unused period.
Optional return shipping
Paid return shipping is used only on enabled, reviewed routes. The venue's owner or manager agrees separately before vFound sends dispatch and recipient contact details, addresses, parcel measurements, description, used value, customs code and country of manufacture to Easyship for rates, labels and tracking. The selected carrier and customs authorities receive the details needed for delivery. Claim messages, proof photos and internal ownership notes are not sent. For Naltyx's own shipping payment and fulfilment service, Naltyx acts as a controller and the Privacy Policy applies. The underlying claim and release records remain processing on the venue's behalf under this agreement. No existing venue is automatically opted in. Provider terms, permissions, country coverage and applicable transfer arrangements must be reviewed before activation.
5. International transfers
We host the data in Singapore, keep an encrypted copy of our backups in Canada, and our AI, email delivery and support email providers may process it in the United States. Where personal data is transferred out of the EEA or the UK, we rely on an adequacy decision where one applies (Canada holds one from the European Commission) and otherwise on the EU Standard Contractual Clauses, with the UK International Data Transfer Addendum where relevant, together with appropriate supplementary safeguards. Those clauses are incorporated here by reference, with the details in section 2 filling their annexes.
6. Security measures
Taking account of the state of the art, cost and the risks involved, we maintain: encryption of data in transit (HTTPS with HSTS); passwords stored only as salted hashes, with rate-limited sign-in; one-time sign-in links by email that work once, for 15 minutes, checked against a one-way hash; browser push addresses and keys encrypted in the database; directory links encrypted in the database, public HTTPS checks on every redirect and a 10 MB download limit; pending calendar invitation details encrypted in the database; optional shipping address, parcel and payment snapshots encrypted in the database, with label PDFs in private storage and signed guest shipping links that expire after 30 days; paired kiosk tokens stored only as a hash on the server, revocable by an owner or manager, and never used as a staff identity; kiosks that never list the people at a venue and reset entered details after 60 seconds; role-based access control, with every request checked against the person’s venue or group membership, regional group roles restricted to matching venue regions, aggregate group views containing no operational record details, policy effect previews tied to the actor, version, selected venues, their current settings and active exceptions before explicit assignment, every record query limited to an authorised venue, and automated tests of cross-venue and cross-region denial; signed, expiring links for claimant access, lost-item reports and My vFound pages, and an owner or manager can also reset a My vFound link; people-list email addresses shown in full only to owners and managers; a content security policy and bot protection on public forms; rate limiting; an audit log of security-relevant actions, kept 24 months; daily backups kept 30 days on our server with access limited to administrators, an encrypted copy kept off the server, and rehearsed restores; and least-privilege access for our own staff. Encrypted copies of the daily backups are also kept in OVHcloud’s Beauharnois region in Canada, encrypted before they leave the server and kept 30 days, while the application, database and files stay hosted by OVHcloud in Singapore. We review these measures as the service changes.
7. Helping you meet your duties
Taking into account the nature of the processing, we will give you reasonable assistance with requests from data subjects (access, correction, deletion, portability, objection), with data protection impact assessments, and with consultations with a supervisory authority. In the product your owners and managers can read claim records, correct a guest’s name, email and phone, export every claim with its messages as a spreadsheet file, and delete a guest’s personal details from a finished claim, which keeps only an anonymous record of the item’s outcome, and export the people list. If a data subject contacts us about your venue’s data, we will refer them to you rather than respond on your behalf.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, with the information we hold about what happened, the categories and approximate numbers affected, the likely consequences and the steps taken, supplementing it as we learn more. Notifying regulators and affected individuals where you are the controller remains your decision and duty.
9. Return and deletion
You can export your records at any time while your subscription is active. If your account is closed, your owners and managers can still sign in for 90 days to export your items, claims, parcels, visits, equipment checkouts, checkroom tickets, hotel stays and people list (lost-item reports and alerts, equipment transfers and checkroom stations have no download once an account is closed), or you can ask us to reopen it; after that we permanently delete the personal data we process for you, except where the law requires us to keep it, except the reserved venue code and the sign-in of an owner who still has another venue (which goes when that venue is deleted), and except copies in backups, which are deleted within 30 days as those backups age out (archives from our September 2026 server move are deleted once that move is confirmed complete). Data in backups remains protected by this agreement until it is deleted. Parcel records, their label photos, pickup photos and signatures are deleted 12 months after a parcel is collected or returned; finished outgoing parcels follow the same period. Expired delegate codes and served desk-arrival rows are deleted after 30 days. Checkroom tickets, their piece and hand-back records, photos and signatures are deleted 90 days after all the things are handed back, or 12 months after they were left at closing. Unclaimed self check-ins are deleted after two days. Checkroom events are deleted 12 months after they end once no ticket refers to them; station records remain until the venue deletes them or its account. Equipment records, their return photos and signatures are deleted 13 months after the item comes back or is marked lost. Collected or cancelled equipment reservations and completed stock-takes are deleted after 13 months. Completed equipment-transfer records, including venue, custody, location, status and note history, are deleted after 24 months. Equipment asset and maintenance records remain until the venue account is deleted. A hotel stay is deleted 13 months after its last known date (departure, then arrival, then last update) when no item or parcel still links to it, whether or not the source ever marked it departed or cancelled; linked stay context remains until those parent records no longer require it. A venue chooses a visitor retention period from 7 to 365 days, with 365 days as the default, and may set a different period for a visitor type; a type without its own period follows the venue’s. After that period, a finished visit, its optional visitor photo, staff visual-check record, sessions, roll-call entries, courier link and any signature are deleted. Calendar invitation details with no visit are deleted after 30 days. What vFound AI wrote for your team (item descriptions and search words, match verdicts for lost reports and weekly insights) is deleted 13 months after it was written, and the wording of the daily summary after 30 days; a claim check is kept with its claim and deleted when the guest’s details on that claim or the venue’s data are deleted. Photos emailed to a venue’s address for email to inventory are deleted with their sender, subject and note 30 days after they arrive, logged or not (the photo file goes as soon as the draft is logged or discarded). Paired kiosk records are deleted with the venue account, and can be revoked sooner. Background tasks that could not finish, with the details they were working on, are deleted after 30 days. The record of an AI assistant connection is deleted 90 days after it is disconnected. Error reports, which record faults in vFound itself with email addresses, numbers, codes and quoted text removed, are deleted 90 days after the error was last seen. The daily count of how each kind of email link ended, which holds no address, token or person, is deleted after 90 days. Browser push addresses are deleted when the person turns them off, the browser expires them, or the related account or record is deleted, and a host’s are also deleted when their My vFound link is reset, their email changes, or they are deactivated (including by a directory sync) or removed; an address whose deliveries keep failing is deleted after 30 days. The record of whether an email was delivered is deleted after 90 days. Current venue and product access is checked again before every alert. Deactivated people cannot be selected for new work. Their open operational records remain venue-scoped and follow the product retention periods above while authorised staff resolve them. People-list entries and their encrypted directory setting are deleted with the venue account. A signed My vFound link expires after 60 days. Removing or deactivating a person, changing their email or resetting their link invalidates their earlier links at once.
Customer-group activity records are deleted after 24 months. Closing a group removes its group access immediately; the remaining membership, venue-region, policy-template, operating-policy version, assignment, exception, acknowledgement alert and completed equipment-transfer records are deleted 24 months after closure. A venue’s own owner can take their venue out of a group at any time, which ends group access to it at once. Removing a venue stops its assignments, exceptions and open alerts. Removing a venue from a group or closing the group does not delete the venue or any of its operational records, which continue under the venue's own account and the periods above.
Local paid-shipping address and parcel snapshots, payment snapshots and private PDFs are removed 12 months after delivery or cancellation, or after dispatch when no final delivery callback arrives, and can be removed sooner with a finished claim or the venue account. Unsettled payments, refunds and disputes must be resolved before deletion. Minimal shipping transaction references and ledger facts are kept for six years after completion for accounting; processed shipping callbacks are removed after 30 days. Deleting vFound's local details does not erase delivery or transaction records separately retained by a provider or carrier. We assist with requests where appropriate.
10. Audits
On reasonable written request, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this agreement. Any on-site audit must be at a mutually agreed time, under confidentiality, and must not compromise the security or data of other customers.
11. General
If this agreement conflicts with the Terms of service on the processing of personal data, this agreement prevails. The liability limits in the Terms of service apply to this agreement, except where data protection law does not permit them. It is governed by the laws of Ontario, Canada, except where mandatory data protection law requires otherwise.
Questions, or a countersigned copy: armaan@vfound.io.
