Last updated: July 26, 2026
1. Scope & Roles
This DPA forms part of the Terms of Service and applies specifically to personal data you store via Viridel Plus (cloud sync). For that data you are the Controller (Data Fiduciary) and Viridel is the Processor (Data Processor). Because Viridel is a personal app, you are typically both the Controller and the Data Subject. It satisfies the requirements of GDPR Article 28, the UK GDPR, and India's DPDPA 2023.
2. Instructions & Duration
Viridel processes Customer Personal Data only on your documented instructions — embodied in the Terms, this DPA, your configuration of the service, and any written request to privacy@viridel.com. We will notify you if, in our opinion, an instruction infringes applicable data-protection law. This DPA is effective from when you enable cloud sync until your account is deleted and all data purged.
3. Annex I — Categories of Data & Data Subjects
Data Subjects
The individual Viridel user who enables cloud sync.
Categories of Personal Data
- Identity — email address, Google display name, Google user ID.
- Financial — expenses, budgets, bills, subscriptions, income, savings goals, and money calendar records you enter (no bank credentials).
- Technical — session timestamps, sync metadata, and device identifiers for conflict resolution.
Viridel is a personal finance and budgeting app and is not intended for special-category health data or similar sensitive categories. Do not upload such data. Viridel does not require special-category data to operate.
4. Annex II — Sub-processors & Objection Right
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Sub-processor — managed PostgreSQL + auth tokens for Viridel Plus sync | United States (AWS us-east-1) |
| Google LLC | Independent IdP — OAuth identity (Google's terms; not Viridel sync storage) | United States / global |
| Dodo Payments | Merchant of Record — payment processing under Dodo's terms (not sync content) | Global |
| Web host / CDN | Delivers web assets; may log IP/URL (not Plus sync payloads) | Provider region(s) |
For Customer Personal Data stored via Viridel Plus sync, Supabase is our sub-processor. We impose data-protection obligations no less protective than this DPA (GDPR Art. 28(4)) and remain responsible for Supabase's performance as our processor chain. Google and Dodo process identity and payments under their own roles and policies; they are listed for transparency, not as if Viridel directs their entire platforms. We give at least 30 days' advance notice before a new sync sub-processor begins processing your synced data; you may object on reasonable grounds within that window. If unresolved, your sole remedy is to terminate cloud sync. There is no fee refund for that termination — see the Refund Policy.
5. Annex III — Security Measures
- TLS 1.3 in transit where configured; AES-256 at rest (Supabase / AWS).
- Row-level security on every sync table — per-user isolation for application access.
- Short-lived JWT access tokens with refresh-token rotation; Google OAuth only.
- No day-to-day staff browsing of customer sync rows; privileged access only for security/abuse/legal process.
- Webhook signature verification; Edge Functions with minimal permissions.
- Electron: context isolation, Node integration disabled, contextBridge preload.
- Dependency reviews and platform audit logging where available.
Full narrative: Security page.
6. International Data Transfers
Data synced via Viridel is stored on Supabase in the United States. Transfers from the EEA/UK are covered by Standard Contractual Clauses (EU Commission Decision 2021/914). Google OAuth transfers identity data under Google's Cloud Data Processing Addendum, which incorporates SCCs. Request applicable SCCs by emailing privacy@viridel.com.
7. Assistance & Breach Notification
Since you are typically both Controller and Data Subject, most rights are self-served via the app (export, delete). For assistance beyond self-service, email us and we respond within 5 business days. In the event of a confirmed personal-data breach affecting your synced data, we will notify you without undue delay and within 72 hours of becoming aware, describing the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken.
8. Audit Rights
You may request reasonable cooperation on compliance with this DPA by emailing privacy@viridel.com (at least 30 days' notice). As a sole-proprietor operation, we typically satisfy audit rights with written documentation and recognised third-party certifications (e.g. Supabase's SOC 2 report). We do not offer on-site audits of shared infrastructure or access to other customers' data.
9. Deletion & Return of Data
- You can export your data as JSON/CSV at any time before deletion.
- On account deletion: a 48-hour soft-delete recovery window, then permanent purge; cloud data fully removed within 30 days.
- Encrypted backups are purged within 90 days, aligned with Supabase's rotation.
- We retain only what applicable law requires (e.g. transaction records for tax), stripped of personal identifiers where possible.
10. Liability & Order of Precedence
Liability under this DPA is governed by the Limitation of Liability section of the Terms (including the founder naming and the aggregate cap of the greater of amounts paid in the 12 months preceding the claim or thirty-nine U.S. Dollars (€39.00)), except where a limitation cannot apply as a matter of data-protection law. This DPA is governed by the same law, jurisdiction, and dispute-resolution terms as the Terms — including Governing Law & Jurisdiction (India; competent courts of Secunderabad, Telangana) and Mandatory Arbitration + Class-Action Waiver — without prejudice to non-waivable Data Subject or supervisory-authority rights. In any conflict between this DPA and the Terms or Privacy Policy, this DPA controls for Customer Personal Data covered by it.
11. Contact
Data-processing enquiries, breach notifications, audit requests, or sub-processor objections: Shiva Kumar Esakki Pandiyan, privacy@viridel.com (Grievance Officer: grievance@viridel.com). Related: Privacy · Security · Terms · Refund.
Disclaimer & Updates
These pages describe how Viridel operates as a product. They are not legal advice. We may update them; for material changes we notify signed-in users by email and/or post a notice on the site or in the app. The date at the top of each page is authoritative.