Skip to content
Veltor
Use casesDocumentationSupportSecuritySign InGet Started
Use casesDocumentationSupportSecurity
Sign InGet Started
Legal

Data Handling Addendum

This Data Handling Addendum (“DHA”) describes how Scalith, LLC processes Customer Data on your behalf when you use the Veltor Service. The DHA is incorporated into the Terms of Service and Customer Agreement.

Effective date: October 8, 2026

Veltor is operated by Scalith, LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States. Questions: support@veltor.dev.

On this page

  1. 1. Roles of the parties
  2. 2. Processing instructions
  3. 3. Categories of data and subjects
  4. 4. Prohibited data
  5. 5. Confidentiality and personnel
  6. 6. Security measures
  7. 7. Subprocessors
  8. 8. International transfers
  9. 9. Data subject requests
  10. 10. Incidents
  11. 11. Audits
  12. 12. Retention and deletion
  13. 13. Liability
  14. 14. Term
  15. 15. Contact

1. Roles of the parties

For Customer Data relating to your end users that you submit to the Service, you are the controller (or equivalent under applicable law) and Scalith, LLC is the processor. For account, billing, and operational data about your personnel who access the dashboard, Scalith, LLC acts as an independent controller as described in the Privacy Policy.

2. Processing instructions

We will process Customer Data only on your documented instructions as transmitted through the Service, the Documentation, and this DHA, unless required by law. You instruct us to process Customer Data to provide abuse-prevention evaluations, store configuration and outcomes according to your retention settings, secure the Service, provide support, comply with law, and improve reliability and security of the Service using aggregated or de-identified data where feasible.

3. Categories of data and subjects

Depending on your integration, Customer Data may include:

  • identifiers you supply (such as email addresses, hashed or tokenized payment fingerprints, phone HMACs, custom hashed identifiers, and network addresses);
  • benefit names, policy configuration, evaluation outcomes, and retained evidence;
  • optional browser-observation signals when you enable collection and obtain end-user consent through your application; and
  • metadata necessary to operate APIs, dashboards, and audit logs.

Data subjects are your end users and other individuals identified in Customer Data.

4. Prohibited data

You will not submit categories of data prohibited in the Documentation, including raw payment card numbers, raw phone numbers, or postal addresses where prohibited. You are responsible for minimizing data sent to the Service and for lawful collection.

5. Confidentiality and personnel

We limit access to Customer Data to personnel and subprocessors with a need to know and subject to confidentiality obligations. We provide training appropriate to role and enforce access controls on production systems.

6. Security measures

We maintain measures designed to protect Customer Data, including encryption in transit, encryption at rest for designated protected records, scoped credentials, environment isolation between Test and Live, keyed hashing of matching identifiers, and monitoring. Details of retention, deletion, and technical architecture are described in the Documentation and Privacy Policy. No security program can guarantee absolute security.

7. Subprocessors

You authorize our use of subprocessors to host and operate the Service. Current categories of subprocessors include infrastructure hosting, database hosting, email delivery, queue and cache providers, IP intelligence, and email-validation providers, as listed in the Privacy Policy. We remain responsible for subprocessors’ performance of data-processing obligations to the extent required by applicable law. We will provide notice of material subprocessor changes by updating the Privacy Policy or Documentation.

8. International transfers

Customer Data may be processed in the United States and other countries where we or subprocessors operate. Where required, we implement appropriate safeguards for cross-border transfers consistent with applicable law.

9. Data subject requests

If we receive a request from a data subject to exercise rights under applicable privacy law relating to Customer Data, we will direct the individual to you unless prohibited by law. You will respond to such requests using tools in the Service or by contacting support@veltor.dev. We will provide reasonable assistance consistent with the nature of the request and your instructions.

10. Incidents

We will notify you without undue delay after confirming a security incident involving Customer Data that compromises confidentiality, integrity, or availability and is likely to require notice under applicable law. Notifications will describe known facts, mitigations, and contact points. You are responsible for regulatory and end-user communications relating to your product unless otherwise agreed in writing.

11. Audits

Upon reasonable written request no more than once per twelve (12) months, we will provide information necessary to demonstrate compliance with this DHA, which may include summaries of certifications or third-party reports when available. Onsite audits require thirty (30) days’ notice, occur during business hours, and must not unreasonably interfere with operations or disclose other customers’ data.

12. Retention and deletion

Customer Data is retained according to your environment settings, product defaults, and legal requirements as described in the Privacy Policy and Documentation. You may configure deletion scopes through authorized dashboard actions. Following termination of the Service, we will delete Customer Data within a commercially reasonable period, subject to backup cycles (up to seven (7) additional days for encrypted backups), billing records, audit logs, and legal holds.

13. Liability

Each party’s liability arising from this DHA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DHA limits either party’s liability to the extent liability cannot be limited under applicable law.

14. Term

This DHA remains in effect for the duration of your use of the Service and until Customer Data is deleted or returned in accordance with this DHA.

15. Contact

Data protection inquiries: support@veltor.dev.

Terms of ServiceCustomer AgreementData HandlingPrivacy PolicyCookie PolicyContact
Veltor
DocumentationSupportSecurityPricingUse casesContact

© 2026 Scalith, LLC. All rights reserved.

TermsAgreementData handlingPrivacyCookies