Paradraw
Vercel/Privacy Notice is drafted as if it could incorporate Data Processing Addendum
Privacy Notice · p37
notice

Privacy Notice

7,613 words, 259 clausesupdated June 1, 2026read 11/10/2026source

·Privacy Notice

·Last Updated June 1, 2026

  • 1About Vercel
  • 2Applicability
  • 3Information We Collect
  • 3.1That You Provide Directly
  • 3.2From Third Parties
  • 3.3From Customers
  • 3.4Automatically
  • 4How We Use Information
  • 5How We Retain Information
  • 6How We Disclose Information
  • 7How We Secure Information
  • 8Third-Party Services
  • 9How We Transfer Information
  • 10Data Privacy Framework
  • 11Your Privacy Rights
  • 12Minimum Age
  • 13Changes
  • 14Jurisdiction
  • 14.1United States
  • 14.2EEA and UK
  • 15Contact Us
  • 16Previous Versions

·At Vercel, we respect customers' need for privacy. We offer our Sites and Services (defined below) to customers and users either directly or via a reseller. Where we refer to our "Customers" in this Privacy Notice, we refer to customers that have entered into an agreement with us or our resellers to use the Services (each, an "Agreement"). Each Customer's respective website users or applicable visitors are referred to as their "End Users."

·By using or accessing our Sites and Services in any manner, you accept the practices and policies outlined in this Privacy Notice and you acknowledge that we may process and share your information.

·About Vercel Products and Services

·Vercel is a frontend cloud for deploying and scaling frontend applications. Our Developer Experience Platform and Managed Infrastructure services provide Customers the ability to build applications and create, share and collaborate on deployments. Customers can preview changes, make Customer content immediately available through our global Edge Network, and test from the perspective of its End Users around the world.

·Vercel offers tools, workflows, and infrastructure products that Customers need to build and deploy their websites and applications. We may provide relevant privacy-specific information about our products and services in our Documentation.

·Applicability

·This Privacy Notice ("Notice") explains Vercel's practices regarding the collection, use, disclosure, and processing of your personal information; the rights and choices you may have with respect to such information; how you may contact us; and how we protect your information when you:

  • 1Visit Vercel's websites, such as https://vercel.com, https://nextjs.org, https://turbo.build, and other Vercel affiliated websites, such as blogs, event registrations, community discussions, forums, and social media platforms (collectively our "Sites");
  • 2Access or use products or services made available by Vercel or its affiliates (collectively, the "Services") as a Customer or authorized user; and
  • 3Interact with us in any way, including registering for, attending, or otherwise partaking in our events, accelerators, learning portals, or webinars (collectively, "Marketing Activities").

·Under this Notice, Vercel acts as a data controller or "business" for the personal information we process. This means we decide how to collect and process personal information.

·This Privacy Notice does not apply to:

  • ·When we process information at the direction of our Customer as their data processor subject to our Data Processing Addendum. In those circumstances, the Customer operates as the data controller and their privacy notice will govern how personal information is processed. Customers are solely responsible for ensuring compliance with all applicable laws and regulations with respect to their End Users, including notifying their End Users of their personal information collection, use, and disclosure under their own terms of service and privacy policies. If your personal information is contained in Customer Content (defined below) and you have any questions about the specific settings and privacy practices the relevant Customer has made to share your personal information with us, please contact the relevant Customer directly or review their privacy notice.
  • ·Third-party products, services, businesses, or any software accessible via the Service or that integrates with the Service. If you have any questions about the specific settings and privacy practices of such third parties, please contact the relevant third-party product, service, or business to review its privacy notice.
  • ·Job applicants. To learn more about our privacy practices related to personal information collected and used for recruiting purposes, please see our Job Applicant Privacy Notice.

·Information We Collect

·The information that we collect depends on your interactions with us, the choices that you make, the products and features you use, your location, and applicable laws. We may collect or receive information directly from you, such as your name and email address when you or your organization sign up for our Services or Marketing Activities. In other cases, we receive information through your use of our Services, such as IP address and telemetry data.

·Information You Provide Directly to Us

·We collect the following information directly from you when using our Sites and Services.

  • ·Contact Information. We collect your contact information when you use, inquire about, or purchase our Services or engage in our Marketing Activities. This information may include your full name, email address, phone number, and location.
  • ·Professional Information. We collect professional information about you, including your company name, company website, job title, and industry.
  • ·Account Information. We collect information you provide to us to create, update, or administer your account on the Sites & Services, such as email, phone number, and username. We also provide you the option of submitting a profile picture and social media profiles. By voluntarily providing us with such account information, you represent that you are the owner of such information or have the requisite consent to provide it to us.
  • ·Transactional Information. We collect payment and other transactional information related to our Services, such as hashed payment card values and billing address.
  • ·Domain Registration Information. We collect registration data when you purchase a domain, such as domain name and registrant contact information. This data may be made publicly available per ICANN policies.
  • ·User Content and File Information. We collect personal information that you upload, post, deliver, or otherwise provide to the Service, such as source code, text, photographs, document, or other files including videos or recordings (collectively, "Customer Content"), Git information, and other files that you provide us.
  • ·AI Product Information. We collect information when you interact with certain features or Services related to our AI Products and Services (as defined in the AI Product Terms), such as user chat prompts, uploaded images, design or text generations. Please see our AI Policy for more information on the development, deployment, and usage of our AI Products and Services.
  • ·Marketing Information. When you engage and interact with our Marketing Activities or one of our sales or customer support representatives we collect information, including through form submissions, surveys, email communications, or phone calls to inquire about Vercel and our Services, such as the nature of your communication, contact preferences, and any information you choose to provide to us when completing any "free text" boxes.
  • ·Image and Audio Information. We may collect your image or audio recordings. If you contact us by phone or video, we may record those calls. If you attend an event hosted or sponsored by Vercel, we may capture your image and/or voice in any video, photograph, or audio recording taken at the event. For more information, please see our Event Terms and Conditions.
  • ·Troubleshooting and Support Information. We collect information about your account preferences or information you provide when you contact us for support, such as the solution you use, the content of chats and other communications with Vercel, and other details that help us provide support or comply with legal obligations. Support information includes content of a message or attachments that you send to us.
  • ·Social Media Information. Our Sites and Services may use social media features, such as the "X" button and other sharing widgets. Vercel is not responsible for how these social media features collect, process, and disclose your information so we encourage you to review the social media platforms' privacy policies.
  • ·Any Information You Voluntarily Provide to Us. For example, when you provide feedback on your experience with our Services or join a public discussion forum as part of our Marketing Activities.

·Information We Collect from Third Parties

·We receive information about Customers from third parties or Vercel partners that provide services or support our business operations. We limit our use of your information to the purposes described in this Notice. Information that we receive from third parties includes:

  • ·Organization Information. We collect information from referral partners, such as company name, contact name, job title, and company address.
  • ·Transaction Information. We collect information from our payment providers and partners, such as fraud metrics (i.e., financial risk scores) and details about failed payments.

·Information We Collect from Customers

·We receive information from our Customers about their authorized users (i.e., account holders) and their End Users when they interact with our Customers' websites, web applications, and APIs. Information that we receive from our Customers includes:

  • ·Contact Information. We collect information when a Customer adds you to their account and/or designates you as an authorized user, such as name, email address, and username.
  • ·Website Information. We collect information about traffic to and from Customers' websites, such as End User IP address, location information derived from IP address, and system configuration information.

·Customers are responsible for the content transmitted across our network (e.g., images, written content, graphics, runtime logs, etc.), any personal information they process, and following acceptable behavior practices when using our Services. For more information about Vercel's shared responsibility model, please see our Documentation.

·Information We Collect Automatically

·When you use or interact with our Sites and Services, we automatically collect or receive certain information about you, your device, and your usage of our Site and Services. This information includes:

  • ·Usage Information. We collect information about how you interact with our Sites, Marketing Activities, and Services, such as clicks, pages viewed, searches, web browser used, page response times, errors, date/timestamps associated with your usage, request information (e.g., speed, frequency, the site from which you linked to us ("referring page"), and the name of the website you choose to visit immediately after ours ("exit page"), the amount of time spent on our Sites, and information about other websites you have recently visited.
  • ·Device Information. We collect information about how your devices interact with our Sites, Marketing Activities, and Services, such as browser type and settings, device details (e.g., device type, screen size, operating system, model, model number), language preferences, Internet Service Provider, mobile network, push notification tokens, and device event information (e.g., system activity and hardware settings, application version, and unique device identifiers, such as device ID).
  • ·Service-Generated Information. We collect and use information generated from using our Services and Sites, such as log files, Internet Protocol (IP) address, location information derived from your IP address, proxy server, diagnostics, capacity and usage information to determine storage requirements, performance information from our servers, data settings, and system configurations, including your elected privacy and security settings.
  • ·Location Information. We collect Customers' and End Users' city and country based on IP address. We do not identify precise location.
  • ·Telemetry Information. We collect anonymized statistical and telemetry information as well as aggregated, de-identified information about how you use our Sites and Services.
  • ·API Information. We collect functional data and customer-initiated events (i.e., authentication token, database URL, etc.) from Third-Party Services that connect or integrate with Vercel's Services.
  • ·Cookies. We collect information from your browser by using cookies (which may use a cookie ID) and similar tracking technologies, depending on your settings or preferences in connection with our Sites, Marketing Activities, and Services. Where required by applicable law, we obtain your consent for the use of cookies. You may choose to delete or not accept our cookies as described in our Cookie Notice.

·From time to time, except as restricted by applicable law or our data processing addendums with our customers, we may combine information that we collect as described above with information we obtain from different sources. For example, we may combine information entered through a Vercel sales submission with information we receive from a third-party sales intelligence platform to enhance our ability to market our Services to potential Customers. We may combine usage information with feedback to improve our Services or inform Customers about products that may be relevant to them.

·How We Use Information

·We use your information as described in this Notice to provide our Sites and Services. For example, we may use your information in the following ways:

  • ·Service Operation. To operate and administer our Sites and provide, operate, deliver, monitor, and maintain our Services, including troubleshooting, system maintenance and upgrades.
  • ·Product Development and Improvement. To improve functionality, quality, user experience, and develop new features, including our AI Products and Services. Customers can learn about how to control the use of their information for AI product training here.
  • ·Support. To provide Customer assistance and technical support, such as responding to your requests and inquiries. Vercel personnel are prohibited from viewing Customer Content, except when instructed by you, as necessary to resolve Customer support issues, or for security, Services integrity, or legal purposes.
  • ·Communication. To send you marketing and administrative messages, such as technical or legal notices, invoices, product updates, surveys, security alerts, marketing promotions, newsletters, training, event reminders, and/or provide other news or information about Vercel and/or our partners. Please see Your Privacy Choices and Rights to learn how to manage your communication preferences.
  • ·Account Administration. To create and manage your account, complete transactions, and send billing, tax and other administrative information, such as purchase confirmations, receipts, and invoices.
  • ·Marketing Activities. To develop and improve our Marketing Activities, such as to review and analyze trends, usage, and interactions with our Services, Site, and to personalize and improve our Marketing Activities.
  • ·Advertising. We may use your information to provide you with content and/or features that match your interests and preferences. We advertise our Services through third parties, and may use cookies and other tracking technologies to support targeted advertising and serve relevant ads.
  • ·Security. To detect, investigate, prevent, protect against and respond to potential threats, fraudulent transactions, unauthorized access, and other malicious, deceptive, fraudulent, or illegal activity.
  • ·Legal, Safety, and Compliance. To comply with applicable laws and regulations or a court or legal order, and to review compliance with applicable terms.
  • ·For Any Other Purposes with Your Consent.

·How We Retain Your Information

·We retain your information for the minimum necessary period to fulfill our legal and contractual obligations, develop our Sites and Services, resolve disputes, enforce our rights, for legitimate business purposes, such as tax or accounting requirements, as described in this Notice and as recommended by industry standards.

·When we no longer have an ongoing legitimate business need to process your information, we will either delete or anonymize it. When we choose to anonymize information, we strive to make sure that the information cannot be linked back to you or any specific user. If deletion is not possible (e.g., backups), we will store it securely.

·How We Disclose Information

·We disclose information as necessary to provide the Sites and Services, as required by law, or as part of our business practices as follows. We only disclose information on a need-to-know basis where appropriate safeguards and contractual arrangements are in place and as described below.

  • ·Corporate Affiliates. We may share or transfer information to any person or entity which directly or indirectly controls, is controlled by or is under common control with Vercel, whether by ownership or otherwise ("Corporate Affiliate"). Any information relating to you that we provide to our Corporate Affiliates will be treated by those Corporate Affiliates in accordance with the terms of this Notice.
  • ·New Owner and Other Corporate Transactions. We may disclose or transfer your information to relevant third parties in the event of, or as part of the due diligence or during negotiations of, any proposed or actual reorganization, sale, merger, consolidation, joint venture, assignment, transfer, or other disposition of all or part of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding). Personal information may be part of the transferred assets. You may be notified thereafter of any such change in ownership or control through email or other means as applicable.
  • ·Vercel Customers. We disclose information to our Customers when using our Services, in accordance with our contractual obligations. For example, if you join a Vercel Customer team within our Services, certain information about you including your name, contact information, and profile image may become accessible to that Customer and other individuals with whom the Customer shares access. If you are a Customer managing authorized users within our Services, such as an account administrator or team owner, we may share authorized user information for the purpose of facilitating Services-related requests.
  • ·Vercel Partners and Event Sponsors. We engage with several partners, such as third-party advertising networks, integration service partners, event sponsors, and resellers. We may share information with them to provide and support our Services, and to conduct our Advertising and Marketing Activities.
  • ·Third-Party Service Providers. We disclose information with third-party service providers that require access to information to support our operations and delivery of our Sites and Services. The third parties that Vercel discloses your information with may include:
  • ·Professional services advisors to protect and manage our business interests.
  • ·Cloud providers to provide data hosting, data storage and content delivery network services.
  • ·Billing and payment providers to authorize, record, settle and clear transactions.
  • ·Customer support providers to respond and resolve Customer inquiries and support requests.
  • ·AI providers in connection with providing you Vercel's AI Products and Services.
  • ·Security, abuse, and fraud service providers to monitor and protect the Services and Customers from illegal, deceptive, or malicious activity.
  • ·Domain registrars, registries and other domain name service providers for the purposes of domain registration and listing via the WHOIS protocol.
  • ·Corporate and information technology services to facilitate business operations and communications.
  • ·Analytics companies to review and report on our Advertising and Marketing Activities and Services.
  • ·Any other suppliers, sub-contractors, partners, vendors, and other service providers acting on our behalf.

·These service providers are authorized to use your information only as necessary to provide Services to Vercel. We may use and disclose aggregate information that does not identify or otherwise relate to an individual for any purpose unless we are prohibited from doing so under applicable law.

  • ·Legal or Public Authorities. We only disclose your information when:
  • ·It is reasonably necessary to comply with any applicable law or regulation;
  • ·We are required by law to comply or respond to any court order, legal process, government and/or regulatory request;
  • ·Necessary to enforce our agreements and this Notice;
  • ·Necessary to protect the security or integrity of our Sites and Services;
  • ·Necessary to protect against harm to the rights, property, or safety of Vercel, its agents and affiliates, you, or the public as required or permitted by law; and
  • ·Necessary to respond to an emergency which we believe in good faith requires us to disclose information to assist in preventing the death or serious bodily injury of any person.

·Note that we may also disclose information that we have de-identified. For Hobby and Pro plan users, subject to your data preferences in your team settings, we may disclose de-identified information (including de-identified AI Product Information) to AI business partners for their product improvement and development, including training and improving AI and machine learning models, with the ultimate purpose of improving the Vercel Services you use. You can learn more here.

·How We Secure Your Information

·We use reasonable and appropriate administrative, technical, and physical safeguards designed to protect the information that we have about you from unauthorized or unlawful access, use, modification, destruction, loss, alteration and/or disclosure.

·We require third parties acting on our behalf or with whom we disclose your information to provide security measures in accordance with industry standards and in compliance with contractual obligations, their privacy and security obligations, and any other appropriate confidentiality and security measures. We are not responsible for the privacy and security practices of such third parties outside of the information we receive from or disclose to them.

·Notwithstanding our security safeguards, it is impossible to guarantee absolute security in all situations. For information on our shared responsibility model with Customers, please see our Documentation.

·If you have any questions about the security of our Sites and Services, please contact us as provided in Contact Us.

·Third-Party Services

·Our Sites and Services may contain links to or integrations with other websites or applications not operated or controlled by Vercel ("Third-Party Services"). Certain Third-Party Services used to navigate to and from our Sites and Services have separate user terms and privacy notices that are independent of this Notice. We are not responsible for the content, accuracy, or opinions expressed in such Third-Party Services. We do not monitor or check these Third-Party Services for accuracy or completeness. We recommend carefully reviewing the terms and privacy notices of each Third-Party Service prior to use in alignment with your specific compliance, privacy, and security requirements.

·How We Transfer Your Information

·If you are accessing or using our Sites and Services or otherwise providing your information to us, you consent to the processing of your information in the United States and other jurisdictions in which we operate.

·To provide our Sites and Services, Vercel may store, process and transmit your information outside of your country of residence, which may have different data protection laws and may not offer the same level of protection or guarantees as in your country or the country where you initially provided the information. To the extent required by applicable law, whenever we transfer your information, we take the appropriate steps to protect your information, including the use of standard contractual clauses or other appropriate legal mechanisms.

·Data Privacy Framework

·Vercel complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Vercel has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Vercel has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit the Data Privacy Framework website.

·In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Vercel commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, should first contact us at privacy@vercel.com.

·If a privacy complaint or dispute relating to personal information received by Vercel in reliance on the Data Privacy Framework (or any of its predecessors) cannot be resolved through our internal processes, we have agreed to participate in the VeraSafe Data Privacy Framework Dispute Resolution Procedure. Subject to the terms of the VeraSafe Data Privacy Framework Dispute Resolution Procedure, VeraSafe will provide appropriate recourse free of charge to you. To file a complaint with VeraSafe and participate in the VeraSafe Data Privacy Framework Dispute Resolution Procedure, please submit the required information here: https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/.

·For transfers of personal information to a third party acting as a controller, Vercel complies with the DPF Notice Principle and Choice Principle. For onward transfers, Vercel is responsible for the processing of personal information it receives under the DPF Principles and subsequently transfers to a third party acting as an agent on its behalf. Vercel remains liable under the DPF Principles if its agent processes such personal information in a manner inconsistent with the DPF Principles, unless Vercel proves that it is not responsible for the event giving rise to the damage.

·The Federal Trade Commission has jurisdiction over Vercel's compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).

·In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Vercel is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles. You have the possibility, under certain conditions, to invoke binding arbitration for complaints regarding DPF compliance not resolved by any of the other DPF mechanisms. For additional information please see Annex I.

·Your Privacy Rights and Choices

·You may have certain rights and choices available when it comes to how we collect and use your information. The rights available to you depend on your jurisdiction and applicable law. Below is a summary of rights and choices that may be available to you and how to exercise them. For more details on jurisdiction-specific rights, see the Jurisdiction-Specific Information section in our policy.

  • ·Right to Access and Portability. You have the right to request access and receive certain information that we have collected about you.
  • ·Right to Rectify or Update. You have the right to request correction of your personal information where it is inaccurate or incomplete.
  • ·Right to Restriction. You have the right to request that Vercel restrict the processing of your personal information in certain instances and/or restrict further disclosures, such as for certain sensitive information.
  • ·Right to Delete. You have the right to request that we delete your personal information that we have collected.
  • ·Automated Decision-Making. We sometimes use AI features and automated decision-making to analyze your personal information, but we do not use these technologies for decisions that have legal or similarly significant effects on you.
  • ·Opt-out of Marketing Communications. You may opt-out of receiving marketing communications by clicking the "Unsubscribe" link within each email or by contacting us as provided in Contact Us. If you are a Customer, you will continue to receive transactional and administrative communications from us regarding our Sites and Services.
  • ·Right to Lodge a Complaint. You may also have the right to lodge a complaint with a supervisory authority about our processing of your personal information. This may, for example, be the supervisory authority of your specific jurisdiction.

·Exercising your Rights. To exercise your rights you can either:

  • 1Use your Account and Team Preferences as described below,
  • 2Submit a request via our Privacy Request Center, or
  • 3Contact us using the Contact Us information provided below.

·Account Preferences. Your Account Preferences allow you to:

  • ·Access, update and correct certain account information at any time by logging into your account or contacting our support services.
  • ·Delete your account, by following the instructions in our Documentation.
  • ·Update certain communication preferences, such as receiving SMS notifications.

·Team Preferences. Your Team Preferences allow you to:

·Minimum Age Requirements for Our Sites and Services

·The Sites and Services are not directed or intended for use by individuals under the age of 16. To use Vercel's Sites and Services, you must be old enough to consent to the processing of your information in your jurisdiction. We do not knowingly collect personal information from anyone under the age of 16. If you are a parent or guardian and you become aware that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from anyone under the age of 16 without verification or parental consent, we take steps to remove such information.

·Changes to Our Privacy Notice

·We periodically review and update this Notice to describe new Services or changes to our practices. You can determine when this Notice was last revised by referring to the "Last Update" date at the bottom of this Notice. We encourage you to review the Notice whenever you interact with us to stay informed about our privacy practices and the ways that you can help protect your privacy.

·Jurisdiction-Specific Information

·United States

·This section applies to individuals based in the U.S. and supplements our Privacy Notice with respect to the processing of your personal information in accordance with all applicable privacy and data protection laws and regulations and in each case, as amended, superseded, or replaced from time to time ("US Data Privacy Laws"). This includes residents of US states such as California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, and other states to the extent they enact similar privacy laws.

·Data Collection, Use, and Disclosure

·We collect the following categories of information as classified by US Data Privacy Laws:

Category of Personal InformationExamples
IdentifiersName, email address, phone number, username, IP address, unique device identifiers, account ID
Personal Information categories listed in the California Consumer Records statuteName, phone number, billing address, and payment information.
Professional or Employment-Related InformationCompany name, company website, job title, industry.
Characteristics of Protected ClassificationsAge, gender, or other protected information that may be shared when you communicate with us via social media, or as required for age verification. We do not request this information.
Commercial InformationRecords of Sites and Services requested or purchased, account subscription tier, domain name and registration data.
Internet or Other Electronic Network Activity InformationBrowsing and search history, cookies and similar technologies, analytics data, device type and settings, log files, server diagnostics, deployment metadata, system configurations, and telemetry data.
Geolocation InformationCity and country-level location derived from IP address. We do not collect precise geolocation.
Audio, Electronic, Visual, or Similar InformationPhotos, profile pictures, video or audio recordings from calls or events.
InferencesInferences drawn from the above categories to understand preferences, characteristics, or predispositions.

·Publicly Available Information. Personal information does not include publicly available information. For purposes of this paragraph, "publicly available" means information that is lawfully made available from federal, state, or local government records or that you disclose, disseminate, or make available to the public, regardless of form or format.

·Please see Information We Collect in our Notice to see the full description of the information that we collect.

·We use your personal information as described in the How We Use Information section above.

·We disclose your personal information to our providers, such as suppliers, vendors, business partners, advertising partners, resellers and consultants to operate our business and provide you with our Sites and Services, as described below.

·Categories of Personal Information Collected, and Disclosed: Our Privacy Notice describes how we collect, use, and disclose your personal information. The table below describes the categories of information we have disclosed to service providers for business purposes in the last twelve months, and the categories of those service providers.

Category of Personal Information | Other Vercel users and the public, depending on your settings | Service providers | Advertising / marketing partners | Other parties*
Identifiers (e.g., your name, username, IP address, email address, and other similar identifiers)
Personal information categories listed in the California Consumer Records statute (e.g., your name and phone number)
Professional or employment-related information (e.g., your association with a corporate Vercel account)
Protected characteristics under California or federal law (e.g., your age for age verification purposes or if you choose to provide it to us)
Commercial information (e.g., subscription status or history) Internet or similar network activity Geolocation information
Audio, electronic, visual, or similar information, such as photos
Inferences drawn from any of the above-listed categories of information

·*Other parties means Vercel's corporate family of companies, parties with whom you direct us to share information, government entities or law enforcement or other third parties if we believe doing so is necessary to comply with a legal obligation or prevent harm.

·Categories of Personal Information Shared and the Categories of Third Parties to Whom it was Shared: Our Services are for users ages 16 and older, and we do not "sell" or "share" the personal information of users we know are under 16 years old. To the extent that certain US Data Privacy Laws consider some sharing of personal information for Advertising purposes to be "selling" or "sharing" of personal information, Vercel may have shared the following categories of personal information with third-party advertising networks in the preceding 12 months:

  • ·Identifiers; Commercial information; and
  • ·Internet or similar network activity.

·When data is deidentified (as defined by the US Data Privacy Laws), we maintain it in deidentified form and do not attempt to reidentify the information.

·Your Privacy Rights

·U.S. Data Privacy Laws grant individuals certain rights in connection with the personal information that we collect. In addition to the rights described above, you may have the additional rights:

  • ·Right to Access. You have the right to request access and receive certain information that we have collected about you.
  • ·Right to Correct. You have the right to request correction of your personal information where it is inaccurate or incomplete. We generally recommend first making any changes in your Account Settings.
  • ·Right to Delete. You have the right to request that we delete your personal information.
  • ·Right to Know. You have the right to request information about the collection, sale, and disclosure of your personal information from the previous 12 months.
  • ·Right to Opt-out of Sale, Sharing, and Targeted Advertising. You have the right to opt-out of the sale of personal information we have collected about you. Please complete this form to opt out. We do not currently process "Do Not Track" signals, but we honor Global Privacy Control ("GPC") opt-out preference signals in connection with the use of cookies and similar tracking technologies for advertising and related purposes on our Sites. When we detect a GPC signal from your browser, we treat it as a valid request to opt out of the sale or sharing of your personal information for cross-contextual behavioral advertising, as required by applicable law.
  • ·Limit Use of Sensitive Personal Information. We do not use or disclose sensitive personal information for purposes other than with your consent to provide the Services, or as otherwise permitted by law.
  • ·Right to Non-Discrimination. You have the right to not receive discriminatory treatment for exercising any of your rights. We do not treat anyone differently for exercising any of the rights described above.
  • ·Right to Data Portability. You have the right to request a copy of your personal information in a structured, commonly-used, machine-readable format to facilitate the transfer to another company when technically feasible.
  • ·Appeal. You may have the right to appeal our decision regarding a request related to your privacy rights.
·Exercising your Rights

·To exercise your rights you can either:

  • 1Use your Account and Team Preferences (as described in section Your Rights and Privacy Choices)
  • 2Submit a request via our Privacy Request Center
  • 3Contact us using the Contact Us information provided below.

·You, or an authorized individual acting on your behalf, may submit a request relating to your personal information.

·We may need you to provide certain identifying information related to your account (i.e., user ID) or your recent interactions with us to verify your identity or the identity of any individual for whom you are requesting information. We cannot respond to your request if we cannot verify your identity and/or authority to make the request on behalf of another and confirm that the personal information relates to you.

·If you wish to use an authorized agent to submit a request to exercise your rights on your behalf, you must provide the authorized agent written permission signed by you. We may deny a request from an authorized agent if the agent cannot provide Vercel your signed permission demonstrating that the agent is authorized to act on your behalf.

·We fulfill requests within 45 days of receiving your request. Please note that your request may be limited in certain cases, for example if complying with your request would conflict with:

  • ·Federal, state, or local law;
  • ·Regulatory inquiries; Subpoenas; or
  • ·Exercising or defending legal claims.

·EEA and UK

·This section applies to individuals based in the EEA and UK and outlines the processing of your personal information under Data Privacy Laws, including the General Data Protection Regulation ("GDPR").

·Vercel acts as a data controller for personal information that we collect about you while using our Sites, Services, or interacting with our Marketing Activities as described in this Notice. We act as a data processor on behalf of our Customers for the personal information contained in Customer Data.

·This Notice does not apply to any personal information that we process as a data processor, as we only process that information on behalf of our Customers and in accordance with our agreements with them. A Customer that has entered into an agreement to use our Services (e.g., an individual or organization that uses our platform to deploy their websites) controls its instance of the Service and any associated data. If your personal information is contained in Customer Data, and you have any questions about the specific settings and privacy practices the relevant Customer has made to share your personal information with us, please contact the relevant Customer or review the Customer's privacy notice.

·Legal Bases for Processing

·In some countries, such as the EEA and UK, we need to have a legal basis to process your personal information. Our processing of your personal information for the purposes described in this Privacy Notice is done pursuant to the following legal bases:

Purpose of ProcessingCategories of InformationLegal Basis
Providing our services and account administrationContact information, Professional and organizational information, Account information, Transactional information, Domain registration information, User content and file information, Website information, Device, location, and telemetry information, Image and audio information, AI product informationWhere necessary, we process this information to perform a contract with you, such as processing your contact information to send you a technical announcement about the Services.
Internal product development and improvement, including AI model trainingAI product information, Domain registration information, User content and file informationWhere necessary, we process this information for our legitimate interests, including in developing, maintaining, and improving our Services, such as when we use your information to train the AI models that support our Services.
Third-party product improvement and development, including AI model trainingAI product information, Domain registration information, User content and file informationWe process this information based on our legitimate interest and the interests of third-party AI providers in developing and improving AI models under commercial arrangements, subject to appropriate and feasible safeguards and user opt-out rights. This processing does not apply to Enterprise Customers and is handled solely in accordance with applicable customer agreements and data processing addenda.
Customer supportTroubleshooting and support information, Device, location, and telemetry information, Contact Information, Account Information, User Content and file Information, AI Product InformationWhere necessary, we process this information to perform a contract with you, such as resolving support inquiries, troubleshooting technical issues, maintaining the services we provide, or sending you technical announcements about the Services.
Direct marketing and advertisingContact information, Marketing information, Usage information, Social media information, Professional InformationWhere necessary, we process this information on the basis of your consent when we ask for it to process your personal information for a specific purpose that we communicate to you, such as processing your contact information to send you certain forms of marketing communications. Where necessary, we process this information for our legitimate interests and those of third parties, for example when sending surveys to ask for feedback.
Platform securityTroubleshooting and support information, Device, location, and telemetry information, User content and file information, Account InformationWhere necessary, we process this information to comply with a legal obligation. Where we are not under a specific legal obligation, where necessary for our legitimate interests and those of third parties, including in protecting our Services from abuse, fraud, or security risks, such as processing data from trusted partners to protect against fraud, abuse and security threats in our Services.
Legal compliance and trustContact information, Professional information, Organizational information, Account information, Transactional information, Domain registration information, User content and file information, Website information, Device, location, and telemetry information, Image and audio information, User content and file Information, AI product information, Troubleshooting and support information, Marketing InformationWhere necessary, we process this information to comply with a legal obligation such as to comply with a subpoena or similar legal process, or retaining billing information to comply with financial requirements. Where we are not under a specific legal obligation, we may process this information where necessary for our legitimate interests and those of third parties and broader society, including in protecting our or our affiliates', users', or third parties' rights, safety, and property, such as analyzing log data to identify fraud and abuse in our Services.
·Your Privacy Rights

·You have certain rights related to the personal information that we process when you use our Sites and Services. Some of these rights only apply in certain circumstances, as set out below.

  • ·Right of Access. You have the right to request access and receive certain information about how we use your personal information and with whom we share it.
  • ·Right to Rectification. You have the right to request correction of your personal information where it is inaccurate or incomplete. We generally recommend first making any changes in your Account Settings.
  • ·Right to Data Portability. You have the right to request a copy of your personal information in a structured, machine-readable format and to ask us to share this information with another entity.
  • ·Right to Erasure. You have the right to request deletion of your personal information where you believe it is no longer necessary for us to hold it, where we are processing based on legitimate interests and you object and we cannot demonstrate an overriding ground, where you wish to withdraw consent and there is no other processing ground, or where you believe processing is unlawful.
  • ·Right to Restriction of Processing. You have the right to ask us to stop any active processing of your personal information:
  • ·Where you believe your personal information is inaccurate and while we verify accuracy;
  • ·Where we want to erase your personal information as the processing is unlawful, but you want us to continue to store it;
  • ·Where we no longer need your personal information for our processing, but you require us to retain the data for the establishment, exercise, or defense of legal claims; or
  • ·Where you have objected to us processing your personal information based on our legitimate interests and we are considering your objection.
  • ·Right to Object. You can object to our processing of your personal information based on our legitimate interests. We will no longer process your personal information unless we can demonstrate an overriding legitimate purpose. You also have the right to object to our processing of personal information for marketing communications.
  • ·Automated Decision-Making. We sometimes use AI features and automated decision-making to analyze your personal information, but we do not use these technologies for decisions that have legal or similarly significant effects on you.
·Exercising your Rights

·To exercise your rights you can either:

  • 1Use your Account and Team Preferences, (as described in section Your Rights and Privacy Choices)
  • 2Submit a request via our Privacy Request Center, or
  • 3Contact us using the Contact Us information provided below.

·You, or an authorized individual acting on your behalf, may submit a verifiable request to exercise your rights relating to the personal information that we process about you.

·We may need to provide certain identifying information, related to your account (i.e., user ID) or your recent interactions with us to verify your identity, or the identity of any data subject for whom you are requesting information. We cannot respond to your request if we cannot verify your identity and/or authority to make the request on behalf of another and confirm that the personal information relates to you.

·We will fulfill your request within 30 days of receipt. Please note that the above rights may be limited in the following situations:

  • ·Where fulfilling your request would adversely affect other individuals, company trade secrets or intellectual property;
  • ·Where there are overriding public interest reasons; or
  • ·Where we are required by law to retain your personal information.

·If you have unresolved concerns, we encourage you to come to us in the first instance, but you are entitled to address any grievance directly to the relevant Supervisory Authority. In certain instances if you are an End User, we encourage you to reach out to the relevant Customer first to address any complaints.

·Contact Us

·If you have questions about this Notice, please contact us at privacy@vercel.com or write to us:

·Vercel Inc. 440 N Barranca Avenue #4133 Covina, CA 91723 United States

·Previous Versions

·The previous versions of our Privacy Policies are listed below: March 15, 2021 April 23, 2024 March 17, 2026 Effective Date: June 1, 2026

Data Processing Addendum · data processing addendum
Part of the agreement

Data Processing Addendum

8,942 words, 345 clausesupdated March 17, 2026read 11/10/2026source

·Data Processing Addendum

·Last Updated March 17, 2026 Effective Date March 31, 2026

11. Introduction

·This Data Processing Addendum ("Addendum") forms part of Vercel Enterprise Terms and Conditions or other agreement executed between Vercel and Customer for Vercel's provision of Services on an Enterprise plan (the "Agreement") as of the effective date of such Agreement ("Effective Date") and is by and between Vercel Inc., a Delaware corporation ("Vercel"), and the Customer that executed the Agreement. This Addendum applies to Vercel's Processing of Personal Data as a Processor under the Agreement for Customers who are on Enterprise and Pro plans.

·Customer enters into this Addendum on behalf of itself and, to the extent required under applicable Data Protection Laws and Regulations, in the name and on behalf of its Affiliates to the extent such Affiliates are included and covered under the Agreement with Vercel. For the purposes of this Addendum only, and except where indicated otherwise, the term "Customer" shall include Customer and Affiliates.

·This Addendum shall become legally binding upon Customer entering into the Agreement or upon execution of this Addendum.

22. Definitions

·Any terms used in this Addendum and not defined will have the meanings given to them in the applicable Agreement.

  • 1"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. "Control" for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interest of the subject entity.
  • 2"Applicable Data Protection Laws" means all applicable privacy and data protection laws and regulations and in each case, as amended, superseded, or replaced from time to time, including, without limitation, the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"); the United Kingdom Data Protection Act 2018; the California Consumer Privacy Act of 2018 ("CCPA"); the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"); and the Australian Privacy Principles and the Australian Privacy Act (1988).
  • 3"Contact Data" means the Personal Data that Vercel Processes as a controller, such as account information, payment information, and event attendee information.
  • 4"Controller" will have the following meaning (as applicable): (a) the meaning given to "controller" under Applicable Data Protection Laws; or (b) the meaning given to "business" under Applicable Data Protection Laws.
  • 5"Customer Data" means the Personal Data in Your Content that Vercel Processes in connection with the Services.
  • 6"Data Subject" means the identified or identifiable natural person who is the subject of Personal Data or the meaning as set forth in Applicable Data Protection Laws, including similar terms, such as "Consumer" as used in the CCPA.
  • 7"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction and including all "processing" as defined in any Applicable Data Protection Laws.
  • 8"Personal Data" means "personal data", "personal information", "personally identifiable information" or similar information defined in and governed by Applicable Data Protection Laws.
  • 9"Processor" means either a "processor" or a "service provider" as those terms are defined under Applicable Data Protection Laws.
  • 10"Security Incident" means any confirmed unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Data Processed by Vercel and/or its Subprocessors in connection with the provision of Services. Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks or other network attacks on firewalls or networked systems.
  • 11"Service-Generated Data" means usage data and metadata that is generated through the use of the Services, including data generated through the use of Support Services. This Addendum applies to Service-Generated Data to the extent Service-Generated Data constitutes Personal Data.
  • 12"Subprocessor" means any third-party authorized by Vercel to Process Customer Data in assistance with fulfilling its obligations with respect to providing Services under the Agreement or this Addendum.

33. General; Termination

  • 1This Addendum forms part of the Agreement and except as expressly set forth in this Addendum, the Agreement remains unchanged and in full force and effect. If there is any conflict between this Addendum and the Agreement, this Addendum will govern.
  • 2Any liabilities arising under this Addendum are subject to the limitations of liability in the Agreement.
  • 3This Addendum will be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement, unless required otherwise by Applicable Data Protection Laws.
  • 4This Addendum will remain in effect until, and automatically terminate upon, deletion of Customer Data as described in this Addendum.

44. Relationship of the Parties

  • 1Vercel as Processor. The parties acknowledge and agree that with regard to the Processing of Customer Data for Customers who are on Enterprise or Pro plans, Customer acts as a Controller (or Processor) and Vercel is a Processor. Vercel will process Customer Data under and in accordance with Customer's instructions (on behalf of the Controller) as outlined in Section 6 (Role and Scope of Processing), as set forth in Schedule 1.
  • 2Vercel as Controller. To the extent that any Service-Generated Data is considered Personal Data and as to any Contact Data, Vercel is the Controller with respect to such data and will Process such data in accordance with its Privacy Notice. For the avoidance of doubt, Schedule 1 does not apply when Vercel Processes Customer Data as a Controller.

55. Compliance with Law

·Each party will comply with its obligations under Applicable Data Protection Laws with respect to its Processing of Customer Data.

66. Role and Scope of the Processing

  • 1Customer Responsibilities. Customer is solely responsible for obtaining and maintaining all the necessary consents prior to accessing, storing, uploading, processing, or storing Customer Data in the Service. Customer has provided, and will continue to provide, all notices and has obtained, and will continue to obtain, all consents, permissions, and rights necessary under applicable laws, including Applicable Data Protection Laws, for Vercel to lawfully process Customer Data for the purposes contemplated by the Agreement. Customer has complied with all applicable laws, rules, and regulations, including Applicable Data Protection Laws, in the collection and provision to Vercel and its Subprocessors of such Customer Data.
  • 2Customer Instructions. Vercel will Process Customer Data only in accordance with Customer's documented, lawful instructions on behalf of the controller, except to the extent required by Applicable Data Protection Laws to which Vercel is subject or where Vercel becomes aware or believes that Customer's instructions violate Applicable Data Protection Laws, in which case Vercel will notify Customer. By entering into the Agreement, Customer instructs Vercel to Process Customer Data to provide the Services and as otherwise instructed by Customer (such as through opt-in services Customer may choose to enable). Customer acknowledges and agrees that such instruction authorizes Vercel to Process Customer Data (a) to perform its obligations and exercise its rights under the Agreement; (b) to perform its legal obligations and to establish, exercise or defend legal claims in respect of the Agreement; and (c) does not conflict with the instructions given to the Customer by the controller to Process Customer Data.

77. Subprocessing

  • 1Customer specifically authorizes Vercel to use its Affiliates as Subprocessors, and generally authorizes Vercel to engage Subprocessors to Process Customer Data. In such instances, Vercel: (i) will enter into a written agreement with each Subprocessor, imposing data protection obligations substantially similar to those set out in this Addendum to the extent applicable to the nature of the services provided by such Subprocessor; and (ii) remains liable for compliance with the obligations of this Addendum and for any acts or omissions of the Subprocessor that cause Vercel to breach any of its obligations under this Addendum.
  • 2A list of Vercel's Subprocessors, including their functions and locations, is available at https://security.vercel.com, and may be updated by Vercel from time to time in accordance with this Addendum.
  • 3Customer must email privacy@vercel.com, or other method as communicated by Vercel to Customer in the future, to subscribe to notice of new Subprocessors that will be engaged. Vercel will notify Customer by updating the list of Subprocessors and, if Customer has subscribed to notices as set forth in the preceding sentence. If, within five (5) calendar days after such notice, Customer notifies Vercel in writing that Customer objects to Vercel's appointment of a new Subprocessor based on reasonable data protection concerns, the parties will discuss such concerns in good faith and whether they can be resolved. If the parties are not able to mutually agree to a resolution of such concerns, Customer, as its sole and exclusive remedy, may terminate the Agreement for convenience with no refunds and Customer will remain liable to pay any committed fees in an order form, order, statement of work or other similar ordering document.

88. Security

  • 1Security Measures. Vercel will implement and maintain technical and organizational security measures designed to protect Customer Data from Security Incidents and to preserve the security and confidentiality of the Customer Data, in accordance with Vercel's security standards referenced in the Agreement ("Security Measures"). For more information on Vercel's security measures please see our Security FAQs at https://security.vercel.com.
  • 2Customer Responsibility.
  • 2.1Customer is responsible for reviewing the information made available by Vercel relating to data security and making an independent determination as to whether the Services meet Customer's requirements and legal obligations under Applicable Data Protection Laws. Customer acknowledges that the Security Measures provide a level of security appropriate to the risk in respect of the Customer Data and that they may be updated from time to time upon reasonable notice to Customer to reflect process improvements or changing practices (but the modifications will not materially decrease Vercel's obligations as compared to those reflected in such terms as of the Effective Date).
  • 2.2Customer agrees that, without limitation of Vercel's obligations under this Section 8, Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Customer Data; (b) securing the account authentication credentials, systems and devices Customer uses to access the Services; (c) securing Customer's systems and devices that it uses with the Services; and (d) maintaining its own backups of Customer Data.
  • 3Security Incident. To the extent required by Applicable Data Protection Laws, upon becoming aware of a confirmed Security Incident, Vercel will notify Customer without undue delay unless prohibited by applicable law. A delay in giving such notice requested by law enforcement and/or in light of Vercel's legitimate needs to investigate or remediate the matter before providing notice will not constitute an undue delay. Such notice to Customer will describe, to the extent possible, (a) the details of the Security Incident as known or as reasonable requested by Customer, and (b) the steps taken, deemed necessary and reasonable by Vercel, to mitigate the potential risks, to the extent that the remediation is within Vercel's reasonable control. Without prejudice to Vercel's obligations under this Section 8.c., Customer is solely responsible for complying with Security Incident notification laws applicable to Customer and fulfilling any third-party notification obligations related to any Security Incidents. Vercel's notification of or response to a Security Incident under this Section 8.c. will not be construed as an acknowledgment by Vercel of any fault or liability with respect to the Security Incident. These obligations will not apply to Security Incidents to the extent they are caused by Customer.

99. Audits and Reviews of Compliance

·The parties acknowledge that Customer must be able to assess Vercel's compliance with its obligations under Applicable Data Protection Laws and this Addendum, insofar as Vercel is acting as a processor on behalf of Customer.

  • 1Vercel's Audit Program. Vercel uses external auditors to verify the adequacy of its security measures with respect to its processing of Customer Data. Such audits (e.g., SOC 2 Type 2) are performed at least once annually at Vercel's expense by independent, third-party security professionals at Vercel's selection and result in the generation of a confidential audit report ("Audit Report"). For more information on Vercel's security measures please see Schedule 2.
  • 2Customer Audit. Upon Customer's written request at reasonable intervals, and subject to reasonable confidentiality controls, Vercel will make available to Customer a copy of Vercel's most recent Audit Report. Customer agrees that any audit rights granted by Applicable Data Protection Laws will be satisfied by these Audit Reports.

1010. Impact Assessments and Consultations

·Vercel will provide reasonable cooperation to Customer, to the extent Customer does not otherwise have access to the relevant information and such information is available to Vercel, in connection with any data protection impact assessment (at Customer's expense only if such reasonable cooperation will require Vercel to assign significant resources to that effort) or consultations with regulatory authorities as required by Applicable Data Protection Laws.

1111. Data Subject Requests

·Vercel will upon Customer's request (and at Customer's expense) provide Customer with such assistance as it may reasonably require to comply with its obligations under Applicable Data Protection Laws to respond to requests from individuals to exercise their rights under Applicable Data Protection Laws (e.g., rights of data access, rectification, erasure, restriction, portability and objection) in cases where Customer cannot reasonably fulfill such requests independently by using the self-service functionality of the Services. If Vercel receives a request from a Data Subject in relation to the Processing of their Customer Data, Vercel will advise the Data Subject to submit their request to Customer, and Customer will be responsible for responding to any such request.

1212. Return or Deletion of Customer Data

  • 1Customers may delete or export Customer Data at any time while using the Services in a manner consistent with the functionality of the Service. Termination or expiration of the Agreement serves as instruction for Vercel to delete all Customer Data within a commercially reasonable timeframe.
  • 2Notwithstanding the foregoing, Customer understands that Vercel may retain Customer Data if required by law, and such data will remain subject to the requirements of this Addendum.

1313. International Provisions

  • 1Processing in the United States. Customer acknowledges that, as of the Effective Date, Vercel's primary processing facilities are in the United States. Notwithstanding the foregoing, Customer acknowledges that Vercel may in connection with the provision of Services, need to transfer and process Customer Data to and in the United States and anywhere else in the world where Vercel or its Subprocessors maintain data processing operations. Vercel will ensure such transfers are made in compliance with the requirements of Applicable Data Protection Laws and this Addendum.
  • 2Jurisdiction Specific Terms. To the extent that Vercel Processes Customer Data originating from and protected by Applicable Data Protection Laws in one of the Jurisdictions listed in Schedule 4 (Jurisdiction Specific Terms), then the terms specified therein with respect to the applicable jurisdiction(s) will apply in addition to the terms of this Addendum.
  • 3Cross Border Data Transfer Mechanism. To the extent that Customer's use of the Services requires an onward transfer mechanism to lawfully transfer personal data from a jurisdiction (i.e., the European Economic Area ("EEA"), the United Kingdom ("UK"), Switzerland or any other jurisdiction listed in Schedule 3) to Vercel located outside of that jurisdiction (a "Transfer Mechanism"), the terms and conditions of Schedule 3 (Cross Border Transfer Mechanisms) will apply.

Schedule 1Schedule 1: Subject Matter & Details of Processing

11. Nature and Purpose of the Processing

·Vercel will process Personal Data as necessary to provide the Services under the Agreement. Vercel does not sell Customer Data (or end user information within such Customer Data) and does not share Customer Data with third parties for those third parties' own business interests.

  • 1Customer Data. Vercel will process Customer Data as a processor in accordance with Customer's instructions as outlined in Section 6.a (Customer Instructions) of this Addendum.
  • 2Service-Generated Data and Contact Data. Vercel will process Service-Generated Data and Contact Data as a controller for the purposes outlined in Section 4.b (Vercel as Controller) of this Addendum.

22. Processing Activities

  • 1Customer Data. Customer Data will be subject to the following basic processing activities: the provision of Services and disclosures in accordance with the Agreement and/or as compelled by applicable laws.
  • 2Service-Generated Data and Contact Data. Personal Data contained in Service-Generated Data and/or Contact Data will be subject to the following processing activities by Vercel: Vercel may use Service-Generated Data and/or Contact Data to operate, improve and support the Services, to provide marketing and service-related messages and for other lawful business practices, such as analytics, benchmarking, and reporting.

33. Duration of the Processing

·The period for which Personal Data will be retained and the criteria used to determine that period is as follows:

  • 1Customer Data. Prior to the termination of the Agreement, Vercel will Process Customer Data in accordance with sections 3 and 12 of this Addendum.
  • 2Service-Generated Data and Contact Data. Upon termination of the Agreement, Vercel may retain, use, and disclose Service-Generated Data and/or Contact Data for the purposes set forth above in Section 2.b (Service-Generated Data and Contact Data) of this Schedule 1, subject to the confidentiality obligations set forth in the Agreement. Vercel will anonymize or delete Personal Data contained within Service-Generated Data and/or Contact Data when Vercel no longer requires it for the purpose set forth in Section 2.b (Service-Generated Data and/or Contact Data) of this Schedule 1.

44. Categories of Data Subjects

  • 1Customer Data. Individuals whose Personal Data is included in Customer Data.
  • 2Service-Generated Data and Contact Data. Customer's authorized users with access to a Vercel account, customers, suppliers, and end users.

55. Categories of Personal Data

  • 1Customer Data. The categories of Customer Data are: any Customer Data that Customer, or third parties acting on their behalf, may submit to Vercel in connection with the performance of the Service, to the extent of which is exclusively determined and controlled by the Customer, such as IP address and system configuration information.
  • 2Service-Generated Data and Contact Data. Vercel processes Personal Data within Service-Generated Data and/or Contact Data, such as name, email address, phone number, account preferences, and content of communications with Support Services.

66. Sensitive Data or Special Categories of Data

  • 1Customer Data. Customers are prohibited from including sensitive data or special categories of data in Customer Data.
  • 2Service-Generated Data and Contact Data. Sensitive data is not contained in Service-Generated Data and/or Contact Data.

Schedule 2Schedule 2: Technical & Organizational Security Measures

·Where applicable, this Schedule 2 will serve as Annex II to the Standard Contractual Clauses. The following provides more information regarding Vercel's technical and organizational security measures set forth below.

11. Measures of pseudonymization and encryption of personal data.

·Vercel maintains Customer Data in an encrypted format at rest using Advanced Encryption Standard (AES-256) and in transit (TLS 1.2 or higher).

22. Measures for ensuring ongoing confidentiality, integrity, and availability and resilience of processing systems and services.

·Vercel's Customer agreements contain strict confidentiality obligations. Additionally, Vercel requires Subprocessors to sign confidentiality provisions that are substantially similar to those contained in Vercel's Customer agreements. All employees (and contractors) are bound by Vercel's internal policies regarding maintaining the confidentiality of Customer Data and are contractually obligated to comply with these obligations.

·The Services operate on Amazon Web Services ("AWS"), Microsoft Azure ("Azure"), and Google Cloud Platform ("GCP") and are protected by the security and environmental controls of Amazon and Google, respectively. The infrastructure for the Vercel Services spans multiple, fault-independent AWS availability zones in geographic regions physically separated from one another, supported by various tools and processes to maintain high availability of services.

·Vercel performs regular backups of Customer Data, which is hosted in AWS, Microsoft Azure, and GCP data centers. Backups are globally replicated for resiliency against regional disasters and periodically tested by the Vercel engineering team.

·Employees complete mandatory training annually, which covers privacy and data protection, confidentiality, social engineering, password policies, and information security.

33. Measures for ensuring the ability to restore availability and access to Personal Data in a timely manner in the event of a physical or technical incident.

·Vercel performs regular backups of Customer Data, which is hosted in AWS, Microsoft Azure, and GCP data centers. Backups are retained redundantly across multiple availability zones and encrypted in transit and at rest.

·Vercel has a business continuity and disaster recovery plan that incorporates input from periodic risk assessments, vulnerability scanning, and threat analysis.

44. Processes for regular testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of processing.

·Vercel maintains a risk-based assessment security program. The framework for Vercel's security program includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the Services and confidentiality, integrity, and availability of Customer Data. Vercel's security program is intended to be appropriate to the nature of the Services and the size and complexity of Vercel's business operations.

·Vercel has a separate and dedicated security team that manages Vercel's security program. This team facilitates and supports independent audits and assessments performed by third parties to provide independent feedback on the operating effectiveness of the information security program (e.g., SOC 2 Type 2, penetration testing, and vulnerability scanning).

·Vercel's security governance program covers: Policies and Procedures, Asset Management, Access Management, Data Handling, Encryption, Logging & Monitoring, Password Management, Personnel Security, Resiliency, Responsible Disclosure, Risk Assessment, Vendor Risk Management, Vulnerability, SDLC, Incident Response, Business Continuity & Crisis Management, Acceptable Use and Code of Conduct. Information security policies and standards are reviewed and approved by management at least annually and are made available to all employees.

·Security is managed at the highest levels of the company, with security and technology leadership meeting with executive management regularly to discuss issues and coordinate company-wide security initiatives.

55. Measures for user identification and authorization.

·Vercel personnel are required to use unique user access credentials and passwords for authorization. Vercel follows the principles of least privilege through role-based and time-based access models when provisioning system access. Vercel personnel are authorized to access Customer Data based on their job function, role and responsibilities, and such access requires approval prior to access provisioning. Employee access to Customer Data is promptly removed upon role change or termination.

·Vercel uses commercially reasonable practices to identify and authenticate users who attempt to access Vercel systems.

66. Measures for the protection of data during transmission.

·Customer Data is encrypted when in transit between Customer and the Vercel Services.

77. Measures for the protection of data during storage.

·Customer Data is stored encrypted using AES-256. Vercel uses AWS Key Management System ("KMS") to encrypt data in our infrastructure. AWS KMS is a secure and resilient service that uses FIPS 140-2 validated hardware security modules to protect keys that cannot be retrieved from the service by anyone or transmitted beyond the AWS regions where they were created. AWS log-in credentials and private keys generated by the Service are for Vercel's internal use only.

88. Measures for ensuring physical security of locations at which personal data are processed.

·Vercel is a remote-first organization with limited physical presence globally. As needed, physical security controls for office space are inherited from our co-working office provider, which manages visitors, building entrances, CCTVs (closed circuit televisions), and overall office security.

·The Services operate on AWS, Microsoft, and GCP and are protected by the security and environmental controls of Amazon, Microsoft, and Google, respectively.

·Detailed information about AWS security is available at: https://aws.amazon.com/security/

·For AWS SOC Reports, please see:

·Detailed information about Azure security is available at:

·Detailed information about GCP security is available at:

99. Measures for ensuring events logging.

·Vercel monitors access to applications, tools, and resources that process or store Customer Data, including cloud services. Monitoring of security logs is centralized by the security team. Log activities are investigated when necessary and escalated appropriately.

·User activity metrics are available to Customers within the Services. For further information, visit https://vercel.com/docs/observability/activity-log.

1010. Measures for ensuring systems configuration, including default configuration.

·Vercel applies Secure Software Development Lifecycle (Secure SDLC) standards to perform numerous security-related activities for the Services across different phases of the product creation lifecycle from requirements gathering and product design all the way through product deployment. These activities include, but are not limited to, the performance of (a) internal security reviews before new Services are deployed; and (b) annual penetration testing by independent third parties.

·Vercel adheres to a change management process to administer changes to the production environment for the Services, including changes to its underlying software, applications, and systems. Monitors are in place to notify the security team of changes made to critical infrastructure and services that do not adhere to the change management processes.

1111. Measures for internal IT and IT security governance and management.

·Vercel maintains a risk-based assessment security program. The framework for Vercel's security program includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the Services and confidentiality, integrity, and availability of Customer Data. Vercel's security program is intended to be appropriate to the nature of the Services and the size and complexity of Vercel's business operations.

·Vercel has a separate and dedicated Information Security team that manages Vercel's security program. This team facilitates and supports independent audits and assessments performed by third parties to provide independent feedback on the operating effectiveness of the information security program (e.g., SOC 2 Type 2, penetration testing, and vulnerability scanning).

·Vercel's security governance program covers Policies and Procedures, Asset Management, Access Management, Data Handling, Encryption, Logging & Monitoring, Password Management, Personnel Security, Resiliency, Responsible Disclosure, Risk Assessment, Vendor Risk Management, Vulnerability, SDLC, Incident Response, Business Continuity & Crisis Management, Acceptable Use and Code of Conduct. Information security policies and standards are reviewed and approved by management at least annually and are made available to all employees.

·Security is managed at the highest levels of the company, with security and technology leadership meeting with executive management regularly to discuss issues and coordinate company-wide security initiatives.

1212. Measures for certifications/assurance of processes and products.

·Vercel conducts various third-party audits to attest to various frameworks including SOC 2 Type 2 and annual application penetration testing.

·AWS, Azure, and GCP have achieved: SOC 1, 2, and 3; ISO 27001, 27017, 27018, 27701, and 9001; Cloud Security Alliance Security, Trust, Assurance and Risk (CSA STAR); FedRAMP; and use FIPS 140-2 validated cryptographic modules, in addition to meeting compliance standards for many other legal, security, and privacy frameworks. Further information about these providers' security practices can be found on their respective websites.

1313. Measures for ensuring data minimization.

·Vercel Customers unilaterally determine what Customer Data they route through the Vercel Services and how the Services are configured. As such, Vercel operates on a shared responsibility model. Vercel provides tools within the Services that gives Customers control over exactly what data enters the platform and enables Customers with the ability to block data at the Source level. Additionally, Vercel allows Customers to delete and suppress Customer Data on demand.

1414. Measures for ensuring data quality.

·Vercel has a three-fold approach for ensuring data quality. These measures include: (i) unit testing to ensure the quality of logic used to make API calls, (ii) volume testing to ensure the code is able to scale, and (iii) daily end-to-end testing to ensure that the input values match expected values. Vercel applies these measures across the board, both to ensure the quality of any Service-Generated Data that Vercel collects and to ensure that the Vercel Services are operating in accordance with the documentation.

·Each Vercel Customer chooses what Customer Data they route through the Vercel Services and how the Services are configured. As such, Vercel operates on a shared responsibility model. Vercel ensures that data quality is maintained from the time a Customer sends Customer Data into the Services and until that Customer Data leaves Vercel to flow to a downstream destination.

·Vercel has a process that allows individuals to exercise their privacy rights, as described in Vercel's Privacy Notice available at https://vercel.com/legal/privacy-policy.

1515. Measures for ensuring limited data retention.

·Vercel Customers unilaterally determine what Customer Data they route through the Vercel Services and how the Services are configured. As such, Vercel operates on a shared responsibility model. Customers have the ability to delete Customer Data via the self-service functionality of the Services. Vercel will, within a commercially reasonable timeframe after request by Customer following the termination or expiration of the Agreement, delete all Customer Data from Vercel's systems, unless required by law.

1616. Measures for ensuring accountability.

·Vercel has adopted measures for ensuring accountability, such as implementing data protection policies across the business, publishing Vercel's Information Security Policy (available at https://security.vercel.com), maintaining documentation of processing activities, and recording and reporting Security Incidents involving Personal Data. Vercel conducts regular third-party audits to ensure compliance with our privacy and security standards.

1717. Measures for allowing data portability and ensuring erasure.

·Vercel's Customers have direct relationships with their end users and are responsible for responding to requests from their end users who wish to exercise their rights under Applicable Data Protection Laws.

·Vercel has self-service functionality that allows Customers to delete and suppress their Customer Data.

·Vercel specifies in the Addendum that it will provide assistance to such Customer as may reasonably be required to comply with Customer's obligations under Applicable Data Protection Laws to respond to requests from individuals to exercise their rights under Applicable Data Protection Laws (e.g., rights of data access, rectification, erasure, restriction, portability and objection). If Vercel receives a request from a Data Subject in relation to their Customer Data, Vercel will advise the Data Subject to submit their request to Customer, and Customer will be responsible for responding to any such request.

·Vercel has a process that allows individuals to exercise their privacy rights, as described in Vercel's Privacy Notice available at https://vercel.com/legal/privacy-policy.

1818. For transfers to [sub]-processors, also describe the specific technical and organisational measures to be taken by the [sub]-processor to be able to provide assistance to the controller and, for transfers from a processor to a [sub]-processor, to the data exporter.

·When Vercel engages a Subprocessor under this Addendum, Vercel and the Subprocessor enter into an agreement with data protection terms substantially similar to those contained herein. Each Subprocessor agreement must ensure that Vercel is able to meet its obligations to Customer. In addition to implementing technical and organisational measures to protect personal data, Subprocessors must a) notify Vercel in the event of a Security Incident so Vercel may notify Customer; b) delete data when instructed by Vercel in accordance with Customer's instructions to Vercel; c) not engage additional Subprocessors without authorization; d) not change the location where data is processed; or e) process data in a manner which conflicts with Customer's instructions to Vercel.

Schedule 3Schedule 3: Cross Border Data Transfer Mechanism

11. Definitions

  • 1"Standard Contractual Clauses" means the 2021 Standard Contractual Clauses approved by the European Commission in decision 2021/914.
  • 2"UK IDTA" means the UK international data transfer addendum (Schedule 5).

22. UK IDTA

·For data transfers from the United Kingdom, the UK IDTA will be deemed entered into (and incorporated into this Addendum by reference) together with the Standard Contractual Clauses as set forth in Section 3 of this Schedule below.

33. The 2021 Standard Contractual Clauses

·For data transfers from the EEA, the UK, and Switzerland that are subject to the Standard Contractual Clauses, the Standard Contractual Clauses will apply in the following manner:

  • 1Module One (Controller to Controller) will apply where Customer is a controller of Service-Generated Data and/or Contact Data and Vercel is a controller of Service-Generated Data and/or Contact Data under Section 4.b of the Addendum.
  • 2Module Two (Controller to Processor) will apply where Customer is a controller of Customer Data and Vercel is a processor of Customer Data.
  • 3Module Three (Processor to Processor) will apply where Customer is a processor of Customer Data and Vercel is a processor of Customer Data.
  • 4For each Module, where applicable:

·i. In Clause 7, the option docking clause will not apply; ii. In Clause 9, Option 2 will apply, and the time period for prior notice of Subprocessor changes will be as set forth in Section 7 (Subprocessing) of this Addendum; iii. In Clause 11, the optional language will not apply; iv. In Clause 17 (Option 1), the 2021 Standard Contractual Clauses will be governed by Irish law. v. In Clause 18(b), disputes will be resolved before the courts of Ireland; vi. In Annex I, Part A:

·Data Exporter: Customer and authorized Affiliates of Customer. Contact Details: Customer's account owner email address, or to the email address(es) for which Customer elects to receive privacy communications. Data Exporter Role: The Data Exporter's role is outlined in Section 4 of this Addendum. Signature & Date: By entering into the Agreement, Data Exporter is deemed to have signed these Standard Contractual Clauses incorporated herein, including their Annexes, as of the Effective Date of the Agreement. Data Importer: Vercel Inc. Contact Details: Vercel Privacy - privacy@vercel.com Data Importer Role: The Data Importer's role is outlined in Section 4 of this Addendum. Signature & Date: By entering into the Agreement, Data Importer is deemed to have signed these Standard Contractual Clauses, incorporated herein, including their Annexes, as of the Effective Date of the Agreement.

·vii. In Annex I, Part B: The categories of data subjects are described in Schedule 1, Section 4.

·The sensitive data transferred is described in Schedule 1, Section 6. The frequency of the transfer is a continuous basis for the duration of the Agreement. The nature of the processing is described in Schedule 1, Section 1. The purpose of the processing is described in Schedule 1, Section 1. The period of the processing is described in Schedule 1, Section 3. For transfers to Subprocessors, the subject matter, nature, and duration of the processing is outlined at https://security.vercel.com.

·viii. In Annex I, Part C: The Irish Data Protection Commission will be the competent supervisory authority. ix. Schedule 2 serves as Annex II of the Standard Contractual Clauses.

44. As to the specific modules, the parties agree that the following modules apply, as the circumstances of the transfer may apply: Controller-Controller - Module One Controller-Processor - Module Two Processor-Processor - Module Three

55. To the extent there is any conflict between the Standard Contractual Clauses or the UK IDTA and any other terms in this Addendum, including Schedule 4 (Jurisdiction Specific Terms), the provisions of the Standard Contractual Clauses or the UK IDTA, as applicable, will prevail.

Schedule 4Schedule 4: Jurisdiction Specific Terms

11. California

  • 1The definition of "Applicable Data Protection Laws" includes the California Consumer Privacy Act ("CCPA").
  • 2The terms "business", "commercial purpose", "service provider", "sell", "share", and "personal information" have the meanings given in the CCPA.
  • 3To the extent Vercel processes personal information as a Processor under Section 4.a of the Addendum:
  • 3.1With respect to Customer Data, Vercel is a service provider under the CCPA with the Customer as the business.
  • 3.2Vercel will not (a) sell or share Customer Data; (b) retain, use, or disclose any Customer Data for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing the Customer Data for a commercial purpose other than providing the Services; or (c) retain, use, or disclose the Customer Data outside of the direct business relationship between Vercel and Customer.
  • 3.3The parties acknowledge and agree that the Processing of Customer Data authorized by Customer's instructions described in Section 6 of this Addendum is integral to and encompassed by Vercel's provision of the Services and the direct business relationship between the parties.
  • 3.4Notwithstanding anything in the Agreement or any Order Form entered in connection therewith, the parties acknowledge and agree that Vercel's access to Customer Data does not constitute part of the consideration exchanged by the parties in respect of the Agreement.
  • 4To the extent that Vercel Processes personal information as a Controller under Section 4.b of the Addendum:
  • 4.1Vercel is the business under the CCPA with respect to such data.
  • 4.2Vercel will process such data for the purposes described in the Agreement, or as otherwise permitted by the CCPA.
  • 4.3Vercel will comply with applicable provisions of the CCPA, including providing the same level of privacy protection required of businesses under the CCPA, and notify Customer if Vercel determines it can no longer meet these obligations.
  • 4.4Upon reasonable written notice, Vercel will take reasonable and appropriate steps to make available to Customer information to demonstrate, in relation to such data, Vercel's compliance with applicable provisions of the CCPA.
  • 4.5Upon reasonable written notice from Customer that Customer reasonably believes Vercel is using such data in an unauthorized manner, Vercel will take reasonable and appropriate steps to work with Customer to remediate the allegedly unauthorized use, if necessary.
  • 5Vercel implements and maintains reasonable security and privacy practices appropriate to the nature of the personal information that it processes as set forth in section 8 of this Addendum.

22. EEA

  • 1The definition of "Applicable Data Protection Laws" includes the General Data Protection Regulation (EU 2016/679) ("GDPR").
  • 2When Vercel engages a Subprocessor under Section 7 (Subprocessing), it will:
  • 2.1require any appointed Subprocessor to protect Customer Data to the standard required by Applicable Data Protection Laws, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR; and
  • 2.2require any appointed Subprocessor to agree in writing to only process data in a country that the European Union has declared to have an "adequate" level of protection; or to only process data on terms equivalent to the Standard Contractual Clauses.
  • 3GDPR Penalties. Notwithstanding anything to the contrary in this Addendum or in the Agreement (including, without limitation, either party's indemnification obligations), neither party will be responsible for any GDPR fines issued or levied under Article 83 of the GDPR against the other party by a regulatory authority or governmental body in connection with such other party's violation of the GDPR.

33. Switzerland

  • 1The definition of "Applicable Data Protection Laws" includes the Swiss Federal Act on Data Protection.
  • 2When Vercel engages a Subprocessor under Section 7 (Subprocessing), it will:
  • 2.1require any appointed Subprocessor to protect Customer Data to the standard required by Applicable Data Protection Laws, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR; and
  • 2.2require any appointed Subprocessor to agree in writing to only process data in a country that the European Union has declared to have an "adequate" level of protection; or to only process data on terms equivalent to the Standard Contractual Clauses.

44. United Kingdom

  • 1References in this Addendum to GDPR will to that extent be deemed to be references to the corresponding laws of the United Kingdom (including the UK GDPR and Data Protection Act 2018).
  • 2When Vercel engages a Subprocessor under Section 7 (Subprocessing), it will:
  • 2.1require any appointed Subprocessor to protect Customer Data to the standard required by Applicable Data Protection Laws, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR; and
  • 2.2require any appointed Subprocessor to agree in writing to only process data in a country that the European Union has declared to have an "adequate" level of protection; or to only process data on terms equivalent to the Standard Contractual Clauses and the UK IDTA.

55. Australia

  • 1As the definition of "Applicable Data Protection Laws" includes the Australian Privacy Principles and the Australian Privacy Act (1988), the following applies:
  • 1.1The definition of "Personal Data" includes "Personal Information" as defined under the Australian Privacy Principles and the Australian Privacy Act (1988).
  • 1.2The definition of "sensitive data" includes "Sensitive Information" as defined under the Australian Privacy Principles and the Australian Privacy Act (1988).

66. Canada

  • 1As the definition of "Applicable Data Protection Laws" includes the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), the following applies:
  • 1.1Vercel's Subprocessors, as described in this Addendum, are third parties under the PIPEDA, with whom Vercel has entered into a written contract that includes terms substantially similar to this Addendum. Vercel has conducted appropriate due diligence on its Subprocessors.
  • 1.2Vercel will implement technical and organizational measures as set forth in Schedule 2.

Schedule 5Schedule 5: UK IDTA

·This Addendum has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.

Part 1Part 1: Tables

·Table 1: Parties

Start date | the Effective Date of the Agreement
The PartiesExporter (who sends the Restricted Transfer)Importer (who receives the Restricted Transfer)
Parties' detailsSee the AgreementFull legal name: Vercel Inc. Trading name (if different): n/a Main address (if a company registered address): 440 N Barranca Ave #4133, Covina, CA 91723 Official registration number (if any) (company number or similar identifier): Delaware, 5857312
Key ContactSee the AgreementContact details including email: privacy@vercel.com
Signature (if required for the purposes of Section 2)By entering into the Agreement, Exporter is deemed to have signed this Addendum.By entering into the Agreement, Importer is deemed to have signed this Addendum.

·Table 2: Selected SCCs, Modules and Selected Clauses

Addendum EU SCCsThe Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum: See Schedule 3, Section 3

·Personal data received from the Importer may be combined with personal data collected by the Exporter.

·Table 3: Appendix Information

·"Appendix Information" means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:

Annex 1A:List of Parties: See Table 1
Annex 1B:Description of Transfer: See Schedule 1
Annex II:Technical and organisational measures including technical and organisational measures to ensure the security of the data: See Schedule 2
Annex III:List of Sub processors (Modules 2 and 3 only): See https://security.vercel.com

·Table 4: Ending this Addendum when the Approved Addendum Changes

Ending this Addendum when the Approved Addendum changesWhich Parties may end this Addendum as set out in Section 19: Importer

Part 2Part 2: Mandatory Clauses

·Entering into this Addendum

11. Each Party agrees to be bound by the terms and conditions set out in this Addendum, in exchange for the other Party also agreeing to be bound by this Addendum.

22. Although Annex 1A and Clause 7 of the Approved EU SCCs require signature by the Parties, for the purpose of making Restricted Transfers, the Parties may enter into this Addendum in any way that makes them legally binding on the Parties and allows data subjects to enforce their rights as set out in this Addendum. Entering into this Addendum will have the same effect as signing the Approved EU SCCs and any part of the Approved EU SCCs.

·Interpretation of this Addendum

33. Where this Addendum uses terms that are defined in the Approved EU SCCs those terms shall have the same meaning as in the Approved EU SCCs. In addition, the following terms have the following meanings:

AddendumThis International Data Transfer Addendum which is made up of this Addendum incorporating the Addendum EU SCCs.
Addendum EU SCCsThe version(s) of the Approved EU SCCs which this Addendum is appended to, as set out in Table 2, including the Appendix Information.
Appendix InformationAs set out in Table 3.
Appropriate SafeguardsThe standard of protection over the personal data and of data subjects' rights, which is required by UK Data Protection Laws when you are making a Restricted Transfer relying on standard data protection clauses under Article 46(2)(d) UK GDPR.
Approved AddendumThe template Addendum issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18.
Approved EU SCCsThe Standard Contractual Clauses set out in the Annex of Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
ICOThe Information Commissioner.
Restricted TransferA transfer which is covered by Chapter V of the UK GDPR.
UKThe United Kingdom of Great Britain and Northern Ireland.
UK Data Protection LawsAll laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.
UK GDPRAs defined in section 3 of the Data Protection Act 2018.

44. This Addendum must always be interpreted in a manner that is consistent with UK Data Protection Laws and so that it fulfils the Parties' obligation to provide the Appropriate Safeguards.

55. If the provisions included in the Addendum EU SCCs amend the Approved SCCs in any way which is not permitted under the Approved EU SCCs or the Approved Addendum, such amendment(s) will not be incorporated in this Addendum and the equivalent provision of the Approved EU SCCs will take their place.

66. If there is any inconsistency or conflict between UK Data Protection Laws and this Addendum, UK Data Protection Laws applies.

77. If the meaning of this Addendum is unclear or there is more than one meaning, the meaning which most closely aligns with UK Data Protection Laws applies.

88. Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after this Addendum has been entered into.

·Hierarchy

99. Although Clause 5 of the Approved EU SCCs sets out that the Approved EU SCCs prevail over all related agreements between the parties, the parties agree that, for Restricted Transfers, the hierarchy in Section 10 will prevail.

1010. Where there is any inconsistency or conflict between the Approved Addendum and the Addendum EU SCCs (as applicable), the Approved Addendum overrides the Addendum EU SCCs, except where (and in so far as) the inconsistent or conflicting terms of the Addendum EU SCCs provides greater protection for data subjects, in which case those terms will override the Approved Addendum.

1111. Where this Addendum incorporates Addendum EU SCCs which have been entered into to protect transfers subject to the General Data Protection Regulation (EU) 2016/679 then the Parties acknowledge that nothing in this Addendum impacts those Addendum EU SCCs.

·Incorporation of and changes to the EU SCCs

1212. This Addendum incorporates the Addendum EU SCCs which are amended to the extent necessary so that:

  • 1together they operate for data transfers made by the data exporter to the data importer, to the extent that UK Data Protection Laws apply to the data exporter's processing when making that data transfer, and they provide Appropriate Safeguards for those data transfers;
  • 2Sections 9 to 11 override Clause 5 (Hierarchy) of the Addendum EU SCCs; and
  • 3this Addendum (including the Addendum EU SCCs incorporated into it) is (1) governed by the laws of England and Wales and (2) any dispute arising from it is resolved by the courts of England and Wales, in each case unless the laws and/or courts of Scotland or Northern Ireland have been expressly selected by the Parties.

1313. Unless the Parties have agreed alternative amendments which meet the requirements of Section 12, the provisions of Section 15 will apply.

1414. No amendments to the Approved EU SCCs other than to meet the requirements of Section 12 may be made.

1515. The following amendments to the Addendum EU SCCs (for the purpose of Section 12) are made:

  • 1References to the "Clauses" means this Addendum, incorporating the Addendum EU SCCs;
  • 2In Clause 2, delete the words: "and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679";
  • 3Clause 6 (Description of the transfer(s)) is replaced with: "The details of the transfers(s) and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred) are those specified in Annex I.B where UK Data Protection Laws apply to the data exporter's processing when making that transfer.";
  • 4Clause 8.7(i) of Module 1 is replaced with: "it is to a country benefiting from adequacy regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer";
  • 5Clause 8.8(i) of Modules 2 and 3 is replaced with: "the onward transfer is to a country benefiting from adequacy regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer;"
  • 6References to "Regulation (EU) 2016/679", "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)" and "that Regulation" are all replaced by "UK Data Protection Laws". References to specific Article(s) of "Regulation (EU) 2016/679" are replaced with the equivalent Article or Section of UK Data Protection Laws;
  • 7References to Regulation (EU) 2018/1725 are removed;
  • 8References to the "European Union", "Union", "EU", "EU Member State", "Member State" and "EU or Member State" are all replaced with the "UK";
  • 9The reference to "Clause 12(c)(i)" at Clause 10(b)(i) of Module one, is replaced with "Clause 11(c)(i)";
  • 10Clause 13(a) and Part C of Annex I are not used;
  • 11The "competent supervisory authority" and "supervisory authority" are both replaced with the "Information Commissioner";
  • 12In Clause 16(e), subsection (i) is replaced with: "the Secretary of State makes regulations pursuant to Section 17A of the Data Protection Act 2018 that cover the transfer of personal data to which these clauses apply;";
  • 13Clause 17 is replaced with: "These Clauses are governed by the laws of England and Wales.";
  • 14Clause 18 is replaced with: "Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts."; and
  • 15The footnotes to the Approved EU SCCs do not form part of the Addendum, except for footnotes 8, 9, 10 and 11.

·Amendments to this Addendum

1616. The Parties may agree to change Clauses 17 and/or 18 of the Addendum EU SCCs to refer to the laws and/or courts of Scotland or Northern Ireland.

1717. If the Parties wish to change the format of the information included in Part 1: Tables of the Approved Addendum, they may do so by agreeing to the change in writing, provided that the change does not reduce the Appropriate Safeguards.

1818. From time to time, the ICO may issue a revised Approved Addendum which:

  • 1makes reasonable and proportionate changes to the Approved Addendum, including correcting errors in the Approved Addendum; and/or
  • 2reflects changes to UK Data Protection Laws; The revised Approved Addendum will specify the start date from which the changes to the Approved Addendum are effective and whether the Parties need to review this Addendum including the Appendix Information. This Addendum is automatically amended as set out in the revised Approved Addendum from the start date specified.

1919. If the ICO issues a revised Approved Addendum under Section 18, if any Party selected in Table 4 "Ending the Addendum when the Approved Addendum changes", will as a direct result of the changes in the Approved Addendum have a substantial, disproportionate and demonstrable increase in:

  • 1its direct costs of performing its obligations under the Addendum; and/or
  • 2its risk under the Addendum,

·and in either case it has first taken reasonable steps to reduce those costs or risks so that it is not substantial and disproportionate, then that Party may end this Addendum at the end of a reasonable notice period, by providing written notice for that period to the other Party before the start date of the revised Approved Addendum.

2020. The Parties do not need the consent of any third party to make changes to this Addendum, but any changes must be made in accordance with its terms.

·Alternative Part 2 Mandatory Clauses:

Mandatory ClausesPart 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.