DPA Documents


Data Processing Addendum

The latest Version V 4.1 (Current)


Full title: VORTEX Data Processing Addendum

Document ID: ISMS-DPA-001

Version: 4.1

Effective Date: July 28, 2026

Classification: Public

Standards Alignment: GDPR, UK GDPR (DUAA 2025), Swiss FADP (2023), Canada PIPEDA / Quebec Law 25, Taiwan PDPA (2025), Japan APPI, Australian Privacy Act 1988 (2024); EU AI Act (Regulation 2024/1689), NZ Privacy Act 2020 + Biometric Code 2025, ISO/IEC 27701:2025, ISO/IEC 27018:2025, ISO/IEC 27017:2015, ISO/IEC 27001:2022

1. Parties, Roles, and Scope

This Data Processing Addendum (“DPA”) is incorporated by reference into the VORTEX End User Agreement v2.1 (“EUA”) pursuant to EUA Section 5. For all matters relating to the processing and protection of personal data, this DPA prevails over the EUA (per EUA Section 9.8, Order of Precedence).

Data Controller: The VORTEX customer (“User” as defined in the EUA), who determines the purposes and means of processing.

Data Processor: VIVOTEK Inc., 6F, No. 192, Lian-Cheng Rd., Zhonghe Dist., New Taipei City 235, Taiwan (R.O.C.), provider of the VORTEX VSaaS service.

VIVOTEK processes personal data exclusively upon documented instructions from the Data Controller. To the extent VIVOTEK processes personal data for its own legitimate purposes (billing, account management, anonymized analytics), VIVOTEK acts as an independent Data Controller; these purposes are disclosed in the VIVOTEK Privacy Policy (VIV-ISP-PL01).

1.1 Applicable Regulations

This DPA ensures compliance with: EU GDPR (incl. Digital Omnibus where adopted); UK GDPR (DUAA 2025); Swiss Federal Act on Data Protection (FADP, revised 2023); Canada PIPEDA and Quebec Law 25; Taiwan PDPA (2025 amendments, PDPC); Japan APPI; Australia Privacy Act 1988 (as amended 2024); New Zealand Privacy Act 2020 and Biometric Processing Privacy Code 2025; and ISO/IEC 27701:2025, 27018:2025, 27017:2015, 27001:2022.

2. Data Controller Responsibilities

The Data Controller retains primary responsibility for the lawfulness and appropriateness of all surveillance activities. The Data Controller represents and warrants that:

  1. It has a valid legal basis for each category of processing and is responsible for conducting DPIAs where required.
  2. It shall comply with all applicable notice, signage, and transparency requirements for video surveillance.
  3. It has selected its cloud data center from the available options (Annex A, Section A.2), has considered VIVOTEK’s recommendation to select the DC region matching where its cameras/NVR are located, and bears responsibility for the data protection implications of its selection. The DC assignment is fixed once selected during onboarding. Where the Controller subscribes to AI Facial Recognition, the Controller additionally warrants: (i) it has a valid legal basis under Art. 9(2) (explicit consent, substantial public interest, or legal claims); (ii) it has completed a facial-recognition-specific DPIA; (iii) for real-time edge detection, the Controller is the sole controller and VIVOTEK does not act as data processor; (iv) it complies with EU AI Act deployer obligations where applicable; (v) for UK deployments, it has due regard to the Surveillance Camera Code of Practice (Protection of Freedoms Act 2012, s.33(5)), the ICO guidance on Facial Recognition Technology, and meets the conditions under DPA 2018 s.10 and Schedule 1 for biometric processing; (vi) where whitelist/blocklist features are used, the Controller ensures that watchlist entries are strictly necessary, proportionate, regularly reviewed, and deleted when no longer required.
  4. It is responsible for managing Cloud Archive retention in compliance with applicable storage limitation principles (e.g., GDPR Art. 5(1)(e)). The Data Controller determines the retention period for Cloud Archive data and is responsible for deleting archived content when it is no longer necessary for the original purpose.
  5. Where it accesses content from outside the data subjects’ jurisdiction (e.g., a US-headquartered Controller viewing EU site cameras), it has assessed whether such access constitutes a restricted transfer and has implemented appropriate mechanisms for its own access.
  6. It shall not use VORTEX for any of the prohibited uses defined in Section 9.
  7. Subscription to a VORTEX add-on feature (including AI Facial Recognition) constitutes a documented processing instruction for the purposes of Art. 28(3)(a). For AI Facial Recognition, VIVOTEK acts as data processor for: (i) cloud-based profile management (whitelist/blocklist synchronization across cameras); and (ii) post-search vector processing via AI Hub (Transfer 2). Edge-based real-time detection (face detection, matching, and access control decisions) executes on the Controller's camera hardware; however, profile data (biometric templates and associated metadata) is uploaded to the Controller's selected cloud DC for centralized whitelist/blocklist management. This cloud processing is covered by Transfer 1.
  8. Processing instructions shall comply with applicable data protection laws. VIVOTEK is not liable for breaches arising from non-compliant instructions. If VIVOTEK believes an instruction infringes applicable law, it shall promptly inform the Data Controller and may suspend processing of the affected data until the instruction is withdrawn or confirmed as lawful.
  9. Where VIVOTEK is required to process personal data by Union or Member State law to which it is subject, VIVOTEK shall inform the Data Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
  10. Jurisdiction-specific obligations (PIPEDA transparency notice, Quebec PIA, NZ Biometric Code, AU statutory tort awareness, Taiwan PDPC notification, Swiss FADP requirements) are detailed in Annex D.

3. Description of Processing

VORTEX is a cloud-based Video Surveillance as a Service (VSaaS) platform. Surveillance content data is stored both locally on the Data Controller’s equipment (camera SD card, NVR) and in VIVOTEK’s cloud infrastructure in the Data Controller’s selected regional data center.

The Data Controller selects a cloud data center during onboarding. VIVOTEK recommends selecting the DC region matching where the Data Controller’s cameras and NVR are physically located (e.g., Frankfurt for EU-based cameras). The detailed storage architecture, data center options, cloud services, remote access paths (direct streaming vs. relay service), AI/analytics processing, license tier profiles, retention periods, and data categories are set forth in Annex A.

VIVOTEK also provides an optional Embeddings/Vector Data Processing Service through which AI-generated embeddings and Vehicle Identification Numbers (VINs) are transferred to Cloud Database Service Provider (USA) for vector similarity search. Details are in Annex A, Section A.5.

Processing is solely for: cloud hosting and storage of surveillance content; security monitoring and event detection; AI analytics (where enabled); service operation, maintenance, and technical support; and content retrieval, playback, and export. No processing for commercial profiling, behavioral analysis, or advertising. Consent for marketing use shall NOT be a condition of providing VORTEX. VIVOTEK may create and use fully anonymized, aggregated data from which no individual is or can be identified (GDPR Recital 26 standard) for service improvement, security research, and statistical purposes; such data is no longer personal data and falls outside this DPA. Biometric templates, facial recognition feature vectors, and embeddings derived from facial images (Annex A, Sections A.5 and A.9) are excluded from this carve-out and shall not be used to create such anonymized datasets.

4. Sub-Processor Management

VIVOTEK may engage sub-processors to process personal data on behalf of the Data Controller under a general written authorization model. The current sub-processor list is set forth in Annex C and maintained at https://www.vivotek.com/user_agreement/data_processing_addendum?tab=Sub-Processor_List.

  1. VIVOTEK shall provide at least thirty (30) days’ notice before engaging a new sub-processor or replacing an existing one.
  2. The Data Controller may object within fifteen (15) days. If unresolvable, the Data Controller may terminate without penalty.
  3. VIVOTEK shall impose equivalent data protection obligations on all sub-processors by written contract.
  4. VIVOTEK shall be liable for sub-processor failures, subject to Section 17.
  5. Annex C may be updated by VIVOTEK to reflect changes in sub-processors. Such updates are subject to the notice and objection mechanism above.

5. Security Measures

VIVOTEK implements appropriate technical and organizational measures to protect personal data from accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. Key commitments include: encryption at rest and in transit; multi-factor authentication; role-based access control; comprehensive audit logging; regular vulnerability scanning and penetration testing; multi-tenant data isolation; personnel training and confidentiality obligations; and third-party certifications (ISO 27001, ISO 27701, ISO 27018, IEC 62443-4-1). The specific measures are detailed in Annex B.

Annex B may be updated by VIVOTEK to reflect improvements in security measures. Updates shall not degrade the overall level of protection.

6. Data Breach Notification

  1. Baseline: VIVOTEK shall notify the Data Controller within seventy-two (72) hours of confirming a breach. VIVOTEK’s internal procedures target notification within twenty-four (24) hours, exceeding this commitment.
  2. Notification includes: nature, scope, consequences, measures taken, and designated contact.
  3. VIVOTEK shall maintain a documented record of every breach and preserve forensic evidence for at least ninety (90) days.
  4. VIVOTEK shall cooperate with the Data Controller’s notification obligations to supervisory authorities and data subjects.
  5. Jurisdiction-specific breach notification timelines and thresholds (including Taiwan PDPA 24h, Japan APPI 3-5 day preliminary, Canada PIPEDA RROSH, Swiss FADP “high risk” threshold, UK DUAA) are set forth in Annex D.
  6. Regulatory reporting by VIVOTEK under product cybersecurity laws (including Cyber Resilience Act Articles 14–16 reporting to ENISA and national CSIRTs, per EUA Section 5A.6) is independent of, and does not modify or accelerate, the notification obligations owed to the Data Controller under this Section 6.

7. Data Subject Rights

VIVOTEK shall assist the Data Controller in fulfilling data subject rights obligations. Response within fifteen (15) days. The Data Controller is responsible for verifying the data subject’s identity before instructing VIVOTEK to act. Where a DSR is manifestly unfounded or excessive (GDPR Art. 12(5)), VIVOTEK may charge a reasonable fee for administrative costs or decline to act, subject to agreement with the Data Controller. Technical mechanisms for video-specific DSRs (identify, export, delete footage) subject to the Data Controller’s identity verification. VIVOTEK shall not respond to direct DSRs without Data Controller authorization unless legally required. Standard self-service tools at no charge; manual processing at professional services rates with advance estimates.

8. International Data Transfers

The cross-border transfer profile depends on the Data Controller’s selected cloud data center and service configuration:

  1. EU/EEA Data Controllers who selected Frankfurt: Cloud content stays in the EU. Cross-border elements are: (a) operational data through the US-West-2 application platform; (b) embeddings/vectors to Cloud Database Service Provider USA (covered by Schedule 1 (AI Hub section)); (c) relay service through US-West-2 if NAT is disabled (transient, zero retention); (d) VIVOTEK Taiwan staff remote access. These elements are covered by EU SCCs Module 2 (Schedule 1).
  2. EU/EEA Data Controllers who selected a non-EU DC: ALL cloud content is cross-border. Full SCCs coverage applies. VIVOTEK strongly recommends selecting the DC matching camera/NVR location.
  3. UK Data Controllers: UK International Data Transfer Document (Schedule 2) applies, reflecting the DUAA 2025 “not materially lower” standard.
  4. Swiss Data Controllers: EU SCCs with Swiss Finish apply (Schedule 3, Swiss International Data Transfer Document). The FDPIC is the competent supervisory authority. Swiss data subjects may bring claims in Swiss courts. Where US recipients are certified under the Swiss-US Data Privacy Framework, such certification provides an additional transfer basis. Swiss FADP Art. 16-17 requirements are satisfied by the SCCs and supplementary measures.
  5. Japan Data Controllers: APPI Article 28 contractual safeguards apply. Content in Tokyo stays in Japan.
  6. Australia / New Zealand Data Controllers: APP 8 / IPP 12 compliance. Content in Sydney stays in AU.
  7. Canada Data Controllers: PIPEDA accountability model — no SCCs required; this DPA serves as the contractual safeguard per PIPEDA Principle 4.1.3. Quebec Law 25 PIA required before transfer.
  8. USA / LATAM Data Controllers: All data on US-West-2. No cross-border transfer mechanism required for US.
  9. Relay Service: When NAT traversal is unavailable, video/audio streams transit through VIVOTEK’s relay server on AWS US-West-2. This is transient (zero persistent storage). The Data Controller can avoid the relay by enabling NAT. Currently relay is US-West-2 only; regional relay deployment is planned. The relay transfer is covered by the Data Controller’s applicable regional Schedule (1, 2, or 3).
  10. Controller Cross-Border Access: When the Data Controller’s users access content from outside the data subjects’ jurisdiction (e.g., direct streaming from EU cameras to a US browser), this is the Controller’s own transfer. VIVOTEK provides geo-restriction controls, RBAC, audit logging, and export controls to support compliance.
  11. Transfer Impact Assessment (TIA): VIVOTEK has conducted a TIA evaluating the US legal framework (FISA Section 702, CLOUD Act, EO 14086). The TIA is available to Data Controllers upon request.
  12. Supplementary measures are detailed in Annex B, Section B.11.

9. Prohibited Uses and Data Restrictions

9.1 Prohibited Intentional Uses. The Data Controller shall not use VORTEX for: (a) systematic profiling based on special category data attributes; (b) covert workplace surveillance without employee notification; (c) mass biometric identification without a valid lawful basis and documented DPIA; (d) real-time facial recognition for law enforcement without written authorization; (e) social scoring, emotional analysis for discrimination, or predictive policing; (f) processing of minors’ biometric data without parental/guardian consent where required.; (g) real-time remote biometric identification in publicly accessible spaces, except where explicitly authorized under EU AI Act Art. 5(1)(h) exceptions and documented in a signed processing instruction; (h) using facial recognition whitelist/blocklist features for discriminatory access control based on race, ethnicity, religion, gender, disability, or any other protected characteristic

9.2 Incidental Capture. The parties acknowledge that video surveillance inherently involves incidental capture of special category data. VIVOTEK’s processing is limited to storage, transmission, transcoding, indexing, and display — VIVOTEK does not classify or profile based on special category attributes. The Data Controller is solely responsible for assessing DPIA requirements.

9.3 Data Type Restrictions. The Data Controller shall not transmit to VORTEX any data unrelated to the surveillance service (medical records, criminal records, unrelated financial records, personnel files, privileged data). If such data is transmitted in violation of this clause, VIVOTEK shall not be liable and the Data Controller shall indemnify VIVOTEK per Section 18.

10. Privacy by Design and Disclosure Controls

  • Default settings provide the highest level of privacy (facial recognition disabled by default).
  • VIVOTEK shall not disclose personal data to any third party without Data Controller authorization unless required by law.
  • Government access requests: VIVOTEK shall (a) notify the Data Controller promptly unless prohibited; (b) challenge the request where reasonable; (c) disclose only the minimum required.
  • VIVOTEK shall maintain a register of all PII disclosures to third parties, available to the Data Controller upon request.
  • VIVOTEK shall provide documentation of shared responsibility, compliance support information, and privacy-protective configuration guidance.

11. Term, Termination, and Data Deletion

This DPA remains valid as long as the EUA is active. Retrieval: thirty (30) days post-termination for data export at no charge. Deletion: within thirty (30) additional days (sixty (60) total). Written certification of deletion upon request. Non-standard export formats may incur reasonable fees. The anonymized data carve-out (Section 3) and Sections 2, 6, 14, 17, 18 survive termination.

12. Audit and Inspection

One (1) audit per twelve-month period with thirty (30) days’ advance written notice. Third-party auditors: NDA required, no competitors, business hours. VIVOTEK may satisfy requests via ISO 27001 certificates, ISO 27701/27018 certificates (where available), or SOC 2 Type II reports. VIVOTEK shall cooperate with regulatory inspections under applicable law.

13. DPIA Cooperation

VIVOTEK shall provide reasonable assistance for DPIAs, particularly for public/semi-public surveillance, biometric processing, and large-scale monitoring. The Data Controller retains primary DPIA responsibility.

14. Confidentiality

All personnel bound by confidentiality obligations. Need-to-know access only. Annual privacy-specific training. Mutual confidentiality: Data Controller shall treat VIVOTEK security information as confidential. Survives termination for three (3) years.

15. Complaints Handling

VIVOTEK shall maintain accessible complaint channels, acknowledge within thirty (30) days, and respond without undue delay.

16. Governing Law

16.1 If the Data Controller is located in the European Union, United Kingdom, Switzerland, Japan, Australia, New Zealand, or Canada, this DPA is governed by the laws of Ireland, without regard to its conflict of law provisions.

16.2 If the Data Controller is located in Taiwan (R.O.C.), this DPA is governed by the laws of the Republic of China (Taiwan).

16.3 For all other jurisdictions, this DPA is governed by the laws of the State of California, United States, without regard to its conflict of law provisions.

16.4 Where an applicable Schedule (Schedule 1, 2, or 3) specifies a different governing law for matters within that Schedule’s scope, the Schedule’s governing law provisions prevail for those matters.

16.5 Disputes arising from this DPA shall be subject to the dispute resolution provisions of the EUA (Section 9.4). Where this DPA survives termination of the EUA (during the data deletion period), disputes shall be resolved by the courts corresponding to the governing law specified above.

16.6 This section is without prejudice to mandatory data protection laws applicable in the Data Controller’s jurisdiction. Nothing in this section limits the rights of data subjects or supervisory authorities under applicable law.

17. Limitation of Liability

17.1 General Cap. Except as provided in Sections 17.2 through 17.4, each party’s aggregate liability arising out of or related to this DPA shall not exceed the total fees paid by the Data Controller for VORTEX in the twelve (12) months immediately preceding the event giving rise to the liability.

17.2 Enhanced Cap for Data Protection Claims. For claims arising from VIVOTEK’s breach of this DPA, VIVOTEK’s failure to implement the security measures described in Annex B, or a personal data breach caused by VIVOTEK, VIVOTEK’s aggregate liability shall not exceed two (2) times the amount described in Section 17.1. VIVOTEK’s indemnification obligations under Section 18 are subject to this Section 17.2.

17.3 Administrative Fines. Each party is solely responsible for administrative fines imposed on it by a competent supervisory or regulatory authority in respect of its own infringement. A party may recover amounts corresponding to such fines from the other party only to the extent the fine directly and primarily resulted from the other party’s breach of this DPA; any such recovery from VIVOTEK is subject to the cap in Section 17.2. The Data Controller’s indemnification obligations under Section 18 (including for unlawful instructions, non-compliant deployments, and prohibited uses) are not subject to the caps in this Section 17.

17.4 Uncapped Liabilities. Nothing in this Section 17 limits or excludes liability for: willful misconduct or gross negligence; fraud; death or personal injury; or any liability that cannot be limited or excluded under applicable law, including liability to data subjects under Clause 12 of an applicable Schedule (EU SCCs).

17.5 Exclusive Channeling. Claims arising from unauthorized access to, or unauthorized disclosure of, User Personal Data (as defined in the EUA) are governed exclusively by this DPA, including this Section 17 and Section 18, and shall not be characterized as breaches of confidentiality obligations under the EUA or this DPA for the purpose of avoiding the caps in this Section 17.

17.6 Damages Exclusion. Neither party shall be liable for indirect, incidental, special, consequential, or punitive damages.

18. Indemnification

Data Controller indemnifies VIVOTEK from claims arising from: unlawful instructions, non-compliant deployments, prohibited uses, or violation of applicable law. VIVOTEK indemnifies Data Controller from claims arising from: VIVOTEK’s breach of this DPA, failure to implement Annex B security measures, or unauthorized access/disclosure caused by VIVOTEK’s negligence or willful misconduct. Conditioned on prompt notice, reasonable control of defense, and cooperation.

19. Force Majeure

Neither party liable for failures beyond reasonable control. Affected party shall notify promptly. Sixty (60) day trigger for termination.

20. Designated Privacy Contact

VIVOTEK designates the IT ISMS Manager as the primary privacy contact for VORTEX Data Controllers.

Email: privacy@vivotek.com

Address: 6F, No. 192, Lian-Cheng Rd., Zhonghe Dist., New Taipei City 235, Taiwan (R.O.C.)

Where required by law, VIVOTEK shall appoint a DPO and communicate contact details. For Swiss Data Controllers: a Swiss representative will be designated if required under FADP Art. 14.

21. Reference Documents

  • VORTEX End User Agreement v2.1 (EUA) — incorporates this DPA by reference (EUA Section 5)
  • VIVOTEK Privacy Policy (VIV-ISP-PL01 v2.0) — developed in accordance with Delta Group Information Security and Personal Data Protection Policy (DEI-DIS-PL01)
  • Schedule 1: EU Standard Contractual Clauses (ISMS-DPA-001-SCH1) — Core Service + Optional AI Hub
  • Schedule 2: UK International Data Transfer Document (ISMS-DPA-001-SCH2) — self-contained (EU SCCs + UK adaptations)
  • Schedule 3: Swiss International Data Transfer Document (ISMS-DPA-001-SCH3) — self-contained (EU SCCs + Swiss FADP adaptations)
  • Transfer Impact Assessment (ISMS-DPA-001-TIA) — available on request
  • VORTEX Data Protection Technical Reference (ISMS-DPA-001-REF) — available on request for auditors and DPOs

22. Document Control and Annex Updates

This DPA body shall be reviewed annually or upon material regulatory changes. Annexes A through D may be updated by VIVOTEK to reflect changes in processing activities, technical measures, sub-processors, or regulatory requirements. VIVOTEK shall provide at least thirty (30) days’ notice of material changes to any Annex. The current version of each Annex is maintained at https://www.vivotek.com/user_agreement/data_processing_addendum. For sub-processor changes specifically, the notification and objection mechanism in Section 4 applies.

Next Review: July 2027 or upon material regulatory change.

(Annexes of DPA and related Schedules upon request)

Sub-Processor List

Current version — last updated July 28, 2026 (maintained in accordance with the VORTEX Data Processing Addendum v4.1, Annex C)


This page lists the sub-processors engaged by VIVOTEK Inc. to process personal data contained within the User Data on behalf of the Data Controller in connection with the VORTEX service, where VIVOTEK acts as Data Processor. This list constitutes Annex C of the VORTEX Data Processing Addendum (available at https://www.vivotek.com/user_agreement/data_processing_addendum) and is governed by its Section 4 (Sub-Processor Management). Recipients of Service Data, for which VIVOTEK acts as Data Controller, are separately listed in the VORTEX Privacy Policy (available at https://www.vivotek.com/user_agreement/vortex?tab=Privacy_Policy).

Current Sub-Processors

Sub-Processor

Service

Processing Locations

DPA/Certification

Amazon Web Services, Inc. 410 Terry Ave North, Seattle, WA 98109, USA

Cloud Infrastructure

Germany; Japan; Australia; United States

ISO 27001, 27017, 27018, SOC 2 Type II

Cloud Database Service Provider

Vector Database

United States

DPA in place with VIVOTEK

VIVOTEK engineering and support personnel located in Taiwan (R.O.C.) may access personal data in any regional data center for troubleshooting, maintenance, and support via encrypted VPN. This access is subject to RBAC, audit logging, MFA, and confidentiality obligations.

Advanced AI Add-On (Data Processing Addendum, Annex A, Section A.11): inference executes on the Data Controller's camera hardware (edge) and does not involve any sub-processor beyond those listed above. Any future engagement of a third-party AI model provider will be subject to the Section 4 notification and objection mechanism (30 days' notice) before taking effect.

Updates, Notice, and Objection Mechanism

Per Section 4 of the Data Processing Addendum, VIVOTEK may engage sub-processors under a general written authorization model, and this list may be updated to reflect changes in sub-processors. Such updates are subject to the following mechanism:

  • VIVOTEK shall provide at least thirty (30) days' notice before engaging a new sub-processor or replacing an existing one.
  • The Data Controller may object within fifteen (15) days. If unresolvable, the Data Controller may terminate without penalty.
  • VIVOTEK shall impose equivalent data protection obligations on all sub-processors by written contract.
  • VIVOTEK shall be liable for sub-processor failures, subject to Section 17 of the Data Processing Addendum.

International transfers to the sub-processors listed above are conducted under the transfer mechanisms set forth in the Data Processing Addendum (Section 7 and Annex B) and its transfer Schedules.

Effective date of this Annex: April 29, 2026. Last updated: July 28, 2026.

For questions regarding this list, please submit DSAR and contact Privacy@vivotek.com.

Ready to Deploy Smarter Security Solutions

Connect with our team to explore solutions built for real-world enterprise deployments.

Request Demo