Data Processing Addendum
How Vistra processes personal information on behalf of customers.
Last updated: 14 September 2026
This Data Processing Addendum (“DPA”) forms part of the Vistra Terms of Service or other applicable agreement between Vistra (“Processor”) and the customer using Vistra Services (“Customer” or “Controller”).
This DPA describes how Vistra processes personal information on behalf of customers when providing the Vistra platform.
1. Purpose and scope
Vistra provides digital reporting and inspection management software that enables customers to collect, organise, process, and share information.
During the provision of Services, customers may submit information that contains personal data relating to individuals, including:
- Customers
- Property owners
- Tenants
- Employees
- Contractors
- Clients
- Other individuals connected to inspection activities
This DPA establishes the responsibilities of both parties regarding the processing of such information.
2. Definitions
Personal Data
Information relating to an identified or identifiable individual.
Processing
Any operation performed on personal data, including:
- Collection
- Storage
- Organisation
- Retrieval
- Use
- Sharing
- Deletion
Controller
The party that determines why and how personal data is processed.
Processor
The party that processes personal data on behalf of the Controller.
Subprocessor
A third-party service provider engaged by Vistra to process personal data while providing Services.
3. Roles of the parties
The parties agree that:
- Customer acts as the Controller of personal data submitted through Vistra.
- Vistra acts as the Processor and processes personal data only as necessary to provide the Services.
Customer remains responsible for:
- Determining the purpose of processing
- Ensuring lawful collection of data
- Providing required notices
- Obtaining required permissions or consent
- Ensuring uploaded information is accurate and appropriate
4. Customer instructions
Vistra will process personal data according to:
- Customer instructions
- Customer use of the Services
- Applicable agreements
- Applicable privacy laws
If Vistra believes an instruction violates applicable law, Vistra may notify the Customer and may refuse to process the instruction where legally required.
5. Types of data processed
Depending on Customer usage, Vistra may process:
Account information
- Names
- Email addresses
- User profiles
- Authentication information
Business information
- Company details
- Project information
- Inspection information
- Client information
Inspection data
- Photos
- Videos
- Notes
- Findings
- Checklists
- Reports
- Comments
- Attachments
Technical information
- Device information
- Usage information
- Security logs
6. Categories of data subjects
Depending on Customer usage, processed individuals may include:
- Customer employees
- Contractors
- Clients
- Property owners
- Tenants
- Site visitors
- Other individuals included in uploaded records
7. Vistra responsibilities
Vistra agrees to:
- Process personal data only for providing Services
- Maintain appropriate security controls
- Protect confidential information
- Assist customers where reasonably required
- Notify customers where required by applicable law
8. Customer responsibilities
Customer agrees to:
- Collect personal data lawfully
- Provide appropriate privacy notices
- Obtain required permissions
- Configure user access appropriately
- Avoid uploading unnecessary personal information
- Ensure users comply with applicable privacy obligations
9. Confidentiality
Vistra will treat customer information as confidential.
Personnel and service providers who access customer information must be subject to confidentiality obligations.
Vistra will not disclose customer information except:
- To provide Services
- With customer authorisation
- To trusted subprocessors
- Where required by law
10. Security measures
Vistra maintains reasonable technical and organisational security measures designed to protect personal data. Measures may include:
- Secure transmission
- Access controls
- Authentication protections
- Monitoring
- Backup processes
- Security reviews
- Infrastructure protections
Additional details are described on our Security page.
11. Subprocessors
Vistra may use subprocessors to support delivery of Services. Subprocessors may provide:
- Cloud hosting
- Storage
- Authentication
- Analytics
- Payment processing
- Communication services
- AI processing services
Vistra requires subprocessors to maintain appropriate obligations regarding protection of customer information. See Subprocessors & Data Infrastructure for more detail.
12. AI processing
Vistra may use artificial intelligence technologies to provide optional features. AI-assisted processing may include:
- Generating descriptions
- Improving documentation
- Structuring reports
- Assisting workflow creation
Customers acknowledge that:
- AI output requires human review
- AI results may contain errors
- Customers remain responsible for final reports
- AI features do not replace professional assessment
13. International data transfers
Where personal data is transferred internationally, Vistra will implement appropriate safeguards where required by applicable privacy laws.
14. Data subject requests
Where applicable, customers are responsible for responding to requests from individuals regarding their personal information.
If Vistra receives a request relating to personal data controlled by a customer, Vistra may direct the individual to the relevant customer.
Where legally required and reasonably possible, Vistra may assist customers with responding to such requests.
15. Security incident notification
If Vistra becomes aware of a security incident involving customer personal data, Vistra will:
- Investigate the incident
- Take reasonable containment actions
- Provide information required for customer response
- Notify customers where required by applicable law
Notification does not represent acceptance of liability.
16. Data retention and deletion
Upon termination of Services, Vistra will handle customer information according to:
- Customer instructions
- Applicable agreements
- Retention requirements
Customers may export available information before account termination.
After applicable retention periods, information may be deleted or anonymised.
If an account is inactive for 90 consecutive days, the account and associated data are automatically and permanently deleted. See Delete your account & data for what is retained and for how long.
17. Audits and security information
Where required by applicable law or agreement, Vistra may provide reasonable information demonstrating compliance with applicable security obligations.
Any audits must:
- Be reasonable
- Protect confidentiality
- Avoid unnecessary disruption
- Be subject to appropriate limitations
18. Liability
Each party remains responsible for its own obligations under applicable privacy laws.
Nothing in this DPA limits rights or obligations that cannot legally be limited.
19. Changes to this DPA
Vistra may update this DPA to reflect:
- Changes in privacy laws
- Changes to Services
- Security improvements
- Operational requirements
Material changes will be communicated where required.
20. Contact
For questions regarding this Data Processing Addendum:
- Privacy email: hello@vistra.report
- Security email: hello@vistra.report
- Company: Vistra
- Website: https://www.vistra.report/
Questions about this policy? Contact us or email hello@vistra.report.