Data processing addendum.
The processor terms that sit under our Terms of Service when you put personal data through VOLUME.
Last updated 2026-10-02
How this DPA is executed. This DPA takes effect between you and VOLUME Virtual by countersigning. Request a signed copy at hello@volumevirtual.com. Until countersigned, the published version describes how we operate but is not a signed contract.
Template prepared without legal counsel. Have your lawyer review it before relying on it. If you need changes, send a redline with your signature request.
1. Parties and scope
This Data Processing Addendum ("DPA") is between the customer who holds a VOLUME account ("Customer", "you") and VOLUME Virtual, a business based in British Columbia, Canada ("VOLUME", "we"). It forms part of, and is governed by, the Terms of Service (the "Agreement"). It applies whenever VOLUME processes personal data on your behalf in the course of providing the service — chiefly walkthrough footage of properties, the tours built from it, and the details of people who submit lead forms on your tours.
Where this DPA and the Agreement conflict on the subject of personal data, this DPA wins. Where this DPA is silent, the Agreement applies.
2. Definitions
"Data Protection Law" means every law that applies to the processing of personal data under this DPA, including Canada's PIPEDA and British Columbia's PIPA, the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, and applicable US state privacy laws.
"Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. Where PIPEDA / PIPA terms differ ("organization", "individual"), the GDPR term covers the equivalent.
"Customer Personal Data" means Personal Data you upload to or generate through the service and that VOLUME processes on your behalf. It does not include your own account data (name, email, billing details), which VOLUME processes as a controller under the privacy policy.
"Subprocessor" means a third party VOLUME engages to process Customer Personal Data. "SCCs" means the EU Standard Contractual Clauses adopted by Commission Decision (EU) 2021/914. "UK Addendum" means the UK Information Commissioner's International Data Transfer Addendum to the SCCs.
3. Roles
For Customer Personal Data, you are the Controller and VOLUME is the Processor. You decide what footage to upload, which tours to publish, and what to do with leads. VOLUME processes that data only to deliver the service to you.
You are responsible for having a lawful basis to collect and upload the data — including the right to film and publish each space, and whatever notice the people who appear in footage or submit lead forms are owed under Data Protection Law.
4. Details of processing
Subject matter and purpose. Converting walkthrough video into hosted 3D tours; hosting, serving and embedding those tours; capturing and delivering leads; reporting tour analytics to you.
Duration. For as long as you hold an account, plus the deletion periods in section 11.
Data subjects. Occupants or owners of filmed properties who may appear in footage; your team members; people who view tours; people who submit lead forms on your tours.
Categories of data. Video footage of interiors and exteriors (which may incidentally include people, belongings, documents in view); property addresses; lead names, email addresses, phone numbers and messages; tour-view events (timestamp, anonymous session id, referrer, coarse device type, country/city derived from IP — raw IP is not stored).
Special categories. The service is not designed for special-category data. Do not upload footage or submit leads that deliberately contain it.
5. Processing on your instructions
VOLUME processes Customer Personal Data only on your documented instructions. The Agreement, this DPA, and your use of the product (uploading, publishing, deleting, exporting) are those instructions. If a law VOLUME is subject to requires other processing, we will tell you before processing unless that law forbids it. If we think an instruction breaks Data Protection Law we will tell you promptly and may pause that instruction until it is resolved.
We do not use Customer Personal Data to train models, for marketing, or for any purpose of our own.
6. Confidentiality
Everyone VOLUME authorises to process Customer Personal Data is bound to confidentiality — by contract or by statute — and is given access only to the extent their role needs it. Today that is a single founder; if that changes, the same rule applies to every person added.
7. Security
VOLUME implements the technical and organisational measures set out in Annex 2, taking into account the state of the art, the cost of implementation, and the nature and risk of the processing. We may update those measures, but never in a way that lowers the overall level of protection during the term.
8. Subprocessors
You give VOLUME general authorisation to use the Subprocessors listed at volumevirtual.com/legal/subprocessors, which is incorporated into this DPA. Each Subprocessor is bound by written terms that impose data-protection obligations no less protective than this DPA. VOLUME stays fully liable to you for a Subprocessor's performance.
We will give at least 14 days' notice by email before a new Subprocessor receives Customer Personal Data (subscribe via the address on the subprocessor page). You may object within that window on reasonable, documented data-protection grounds. If we cannot resolve the objection, either of us may terminate the affected part of the service and we will refund any prepaid fees for the unused period.
9. International transfers
VOLUME is based in Canada; the primary database is in Canada (ca-central-1); several Subprocessors run in the United States. To the extent Customer Personal Data subject to the GDPR or UK GDPR is transferred to a country without an adequacy decision, the parties agree that:
· the SCCs (Module Two, controller-to-processor) are incorporated into this DPA by reference, with you as data exporter and VOLUME as data importer; Clause 7 (docking) included; Clause 9 option 2 (general authorisation) with the notice period in section 8; Clause 11 optional language not included; Clause 13 governed by the Supervisory Authority of your establishment; Clause 17 Irish law; Clause 18 Irish courts; Annex I and II completed by sections 4 and Annex 2 of this DPA;
· for UK transfers, the UK Addendum is incorporated by reference, with Table 2 selecting the SCCs as completed above and Part 2 mandatory clauses applying;
· for transfers from Canada, VOLUME remains accountable for the data under PIPEDA while it is held by a Subprocessor abroad, and uses contractual means to provide a comparable level of protection.
If a transfer mechanism above is invalidated, the parties will cooperate in good faith to put a replacement in place.
10. Helping you with data-subject requests and compliance
If a Data Subject contacts VOLUME directly about Customer Personal Data, we will refer them to you and not respond on the substance unless you ask us to or the law requires it. We will help you respond to requests to access, correct, delete, restrict, port or object — first through the product (lead export, tour deletion, account export at Settings → Account), and otherwise by email within 10 business days of your request.
Taking into account the nature of the processing and the information available to us, we will help you meet your obligations on security, breach notification, data-protection impact assessments and prior consultation with a Supervisory Authority. Assistance beyond what the product already provides may be charged at a reasonable rate agreed in advance.
11. Deletion and return
At any time you can export your data (Settings → Account → Export gives a JSON bundle; every tour's .ply is downloadable) and delete tours, leads or your whole account from inside the product.
On termination of the Agreement, or on account deletion, VOLUME starts a 30-day grace period during which the account can be reactivated and the data stays recoverable. When the grace period ends we permanently delete Customer Personal Data from live systems and instruct Subprocessors to do the same; Subprocessor propagation may take up to a further 30 days. Encrypted backups roll off on the provider's schedule. We keep only what the law requires us to keep (for example invoice records for tax purposes) and only for as long as it requires.
12. Personal data breach
VOLUME will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice goes to the workspace owner's email and will describe, as far as known at the time, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. We will follow up as more becomes known, and will not announce a breach involving your data publicly without first consulting you, except where the law requires it.
13. Audits
VOLUME will make available the information reasonably necessary to show compliance with this DPA — this page, the subprocessor list, the security page, and answers to a reasonable security questionnaire. Once per year, or after a Personal Data Breach, you (or an independent auditor you appoint who is bound by confidentiality and is not a competitor) may audit VOLUME's compliance on at least 30 days' written notice, during business hours, in a way that does not disrupt the service or expose other customers' data. Audit costs are yours unless the audit finds a material breach of this DPA.
14. Liability
Each party's liability under this DPA is subject to the exclusions and the cap in the "Disclaimers + liability cap" section of the Terms of Service, and nothing in this DPA increases that cap. Nothing in this DPA limits either party's liability to Data Subjects or Supervisory Authorities where Data Protection Law does not allow it to be limited.
15. Term, order of precedence, law
This DPA lasts as long as VOLUME processes Customer Personal Data for you. It is governed by the law of British Columbia, Canada and the courts of Vancouver, BC, as the Agreement provides — except that the SCCs and UK Addendum carry their own governing law and forum where they apply, and those prevail for the matters they cover.
Annex 1 — Processing details
As set out in section 4 (subject matter, purpose, duration, data subjects, categories). Competent Supervisory Authority for GDPR purposes: the authority of the EU member state in which you are established.
Annex 2 — Technical and organisational measures
These describe what is in place today; they are not aspirations.
· Encryption in transit. All traffic — browser to VOLUME, VOLUME to every Subprocessor — is over TLS. Plain HTTP is redirected.
· Encryption at rest. The database, file storage and backups are encrypted at rest by Supabase and Vercel using provider-managed AES-256 keys. Secrets live in Vercel's environment vault, never in source.
· Tenant isolation. Postgres row-level security is the primary access control: every table carrying customer data is scoped by workspace, so one workspace cannot read another's rows even through the API with a valid key. Service-role (RLS-bypassing) access is restricted to a small set of server-side routes.
· Access logging. Security-relevant events (sign-ins, password and MFA changes, invites, role changes, tour creation and deletion, API-key lifecycle, every admin action) are written to an append-only audit log keyed by actor and workspace, with IP addresses stored only as a salted monthly hash. Retained 12 months.
· Authentication. Passwords are hashed by Supabase Auth and screened against the haveibeenpwned corpus via k-anonymity. Passkeys (WebAuthn) and TOTP two-factor authentication are available to every account.
· Deletion. Account deletion starts a 30-day grace period, after which an automated sweep hard-deletes the account and everything attached to it. Tours and leads can be deleted individually at any time from inside the product.
· Abuse controls. Rate limits on public and authenticated endpoints; per-tour retry caps; a daily reconstruction ceiling; signed webhooks.
· Vendor management. Every Subprocessor is listed publicly with its DPA, and is added to the list before it receives data.
· Monitoring. Errors and performance are monitored through Sentry with privacy-masked session replay (no input text, no media). Uptime and vendor health are checked on a schedule and surfaced on the status page.
· Organisational. VOLUME is a solo-founder company: production access at every provider is limited to the founder's accounts. No SOC 2 certification yet; our current readiness posture is available on request.
Annex 3 — Subprocessors
The current list, with purpose, data categories, location and each vendor's own terms, is maintained at volumevirtual.com/legal/subprocessors and forms part of this DPA.
Signatures
To execute this DPA, email hello@volumevirtual.com from your account's owner address with your legal entity name, address and signatory. We will return a countersigned PDF of this version (dated 2026-10-02). We may update the published template from time to time; a signed DPA keeps the version it was signed on unless both parties sign a new one.
Questions about this policy? Email hello@volumevirtual.com.