Data Processing Overview
High-level overview of how customer and tenant data is processed.
Parties and scope
For customer workforce, candidate, vendor, and payroll-operational data, the customer generally acts as controller and Varajen LLC acts as processor. The signed DPA defines the parties, services, duration, data categories, data subjects, and processing instructions.
Documented instructions
Varajen processes customer data only to deliver, secure, support, and improve contracted functionality; comply with documented customer instructions; or meet applicable legal obligations. Varajen will notify the customer if an instruction appears unlawful where legally permitted.
Confidentiality and access
Personnel access is limited by role and business need and subject to confidentiality obligations. Tenant and role authorization, privileged access controls, audit records, and secret management protect processing operations.
Security measures
Measures include encrypted transport, managed encryption at rest where configured, tenant-scoped authorization, least privilege, logging and monitoring, controlled releases, backup and durability controls, vulnerability management, and incident response.
Subprocessors
Varajen may use vetted providers for cloud infrastructure, storage, communications, identity, monitoring, support, payment, and integration services. The signed DPA governs subprocessor obligations, notice, objections, and Varajen's responsibility for authorized subprocessors.
International transfers
Where personal data crosses borders, Varajen uses the transfer mechanism required by the applicable DPA and law, which may include standard contractual clauses and supplementary measures. Data location commitments require an executed order form or DPA.
Data-subject requests
Varajen assists customers with access, correction, deletion, restriction, portability, and objection requests as required by the DPA. Individuals should normally contact the customer controller first so identity and authority can be verified.
Retention, return, and deletion
During the service term, retention follows customer configuration, service needs, and legal requirements. On termination or a valid instruction, Varajen returns or deletes customer data according to the signed agreement, subject to controlled backup rotation and mandatory legal retention.
Incidents and audits
Varajen investigates confirmed personal-data incidents and notifies affected customers as required by contract and law. Reasonable audit information and available evidence may be provided under confidentiality without compromising other customers or platform security.
Request a DPA
This page is a public summary, not the executed DPA. Authorized customer representatives can request the applicable DPA and subprocessor information through /contact/request/?type=legal.
For vendor onboarding, security questionnaires, compliance review, data processing questions, or contract review, contact the Varajen team.