Valion OS

Valion OS Data Processing Agreement (DPA)

Effective Date: 30 July 2026
Version: 1.0

This Data Processing Agreement ("DPA") forms part of the Valion OS Terms of Service ("Agreement") entered into between Largify Solutions (SMC-Private) Limited ("Processor", "Largify Solutions", "Valion OS", "we", "our", or "us") and the customer or organisation using Valion OS ("Controller", "Customer", or "you").

This DPA applies whenever Largify Solutions processes Personal Data on behalf of the Customer while providing the Valion OS platform and related services.

Where the Customer is subject to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, or other applicable data protection legislation, this DPA forms the parties' agreement regarding the processing of Personal Data under Article 28 GDPR and comparable legal requirements.

If there is any conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA shall prevail to the extent of that conflict.

1. Definitions

Unless otherwise defined in this DPA, capitalised terms have the meanings given in the Valion OS Terms of Service.

For the purposes of this DPA:

  • "Applicable Data Protection Law" means all laws and regulations governing the processing of Personal Data, including, where applicable, the GDPR, UK GDPR, and other applicable privacy legislation.
  • "Controller" means the natural or legal person that determines the purposes and means of Processing Personal Data.
  • "Processor" means the entity that Processes Personal Data on behalf of the Controller.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, deletion, destruction, or any other operation recognised under Applicable Data Protection Law.
  • "Data Subject" means the identified or identifiable individual whose Personal Data is processed.
  • "Subprocessor" means any third party engaged by Largify Solutions to process Personal Data on behalf of the Customer.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.

2. Purpose and Scope

This DPA governs all Processing of Personal Data carried out by Largify Solutions on behalf of the Customer while providing the Valion OS platform.

This DPA applies to:

  • Valion OS web applications;
  • mobile applications;
  • APIs;
  • AI-powered services;
  • automation services;
  • customer support services;
  • hosting infrastructure;
  • integrations provided by Valion OS.

Valion OS provides software and related services only.

The Customer determines the purposes for which Personal Data is processed through the platform.

3. Roles of the Parties

For Customer Personal Data processed through Valion OS:

  • the Customer acts as the Data Controller (or Processor where applicable);
  • Largify Solutions acts as the Data Processor.

Where the Customer itself acts as a Processor for another organisation, Largify Solutions shall act as a Subprocessor.

Largify Solutions shall Process Personal Data only:

  • on documented instructions from the Customer;
  • as necessary to provide the Services;
  • as required by Applicable Data Protection Law.

Where Applicable Data Protection Law requires Processing contrary to Customer instructions, we will inform the Customer unless prohibited by law.

4. Nature of Processing

Processing activities performed by Largify Solutions may include:

  • collection;
  • recording;
  • organisation;
  • storage;
  • hosting;
  • structuring;
  • retrieval;
  • consultation;
  • transmission;
  • synchronisation;
  • AI processing requested by Customers;
  • backup;
  • restoration;
  • deletion;
  • destruction.

Processing activities depend upon how each Customer uses Valion OS.

5. Purpose of Processing

Personal Data is processed solely for purposes including:

  • providing the Valion OS platform;
  • authenticating users;
  • maintaining Customer accounts;
  • hosting Customer information;
  • synchronising business data;
  • delivering requested AI functionality;
  • processing bookings, CRM records, invoices, projects, communications, and workflows;
  • maintaining platform security;
  • preventing fraud;
  • monitoring service availability;
  • disaster recovery;
  • technical support;
  • complying with legal obligations.

Largify Solutions does not determine the Customer's business purposes for Processing Personal Data.

6. Categories of Personal Data

Depending on how Customers configure and use Valion OS, Personal Data may include:

Identity Information

  • names;
  • usernames;
  • employee identifiers;
  • customer identifiers;
  • profile photographs;
  • signatures.

Contact Information

  • email addresses;
  • telephone numbers;
  • business addresses;
  • mailing addresses.

Business Information

  • appointment records;
  • booking history;
  • invoices;
  • quotations;
  • customer relationship records;
  • projects;
  • contracts;
  • support communications;
  • uploaded documents.

Financial Information

  • payment references;
  • billing information;
  • transaction records;
  • invoices created by Customers;
  • accounting information entered by Customers.

Largify Solutions does not intentionally collect or store complete payment card information where payments are processed through third-party payment providers.

Technical Information

  • IP addresses;
  • browser information;
  • device identifiers;
  • operating system information;
  • authentication records;
  • API activity;
  • audit logs.

AI Inputs

Where Customers use AI-powered features, submitted prompts, uploaded content, and related business information necessary to provide requested AI functionality may be processed.

Industry-Specific Information

Depending on the Valion OS product edition, Customers may choose to upload:

  • healthcare appointment information;
  • salon treatment records;
  • legal case information;
  • HR information;
  • CRM records;
  • inventory information;
  • marketing information;
  • documents;
  • images;
  • voice recordings.

Customers remain solely responsible for determining which Personal Data is uploaded to the platform.

7. Categories of Data Subjects

Personal Data processed through Valion OS may relate to:

  • business owners;
  • directors;
  • employees;
  • contractors;
  • freelancers;
  • vendors;
  • suppliers;
  • customers;
  • patients;
  • clients;
  • website visitors;
  • applicants;
  • authorised users;
  • other individuals whose information is uploaded by the Customer.

8. Duration of Processing

Largify Solutions will Process Personal Data for the duration of the Customer's subscription to Valion OS unless:

  • Applicable Data Protection Law requires longer retention;
  • the Customer instructs otherwise where legally permitted;
  • retention is necessary to establish, exercise, or defend legal claims;
  • retention is necessary for fraud prevention, security, taxation, or regulatory compliance.

Upon termination of the Services, Customer Personal Data will be retained and deleted in accordance with our Privacy Policy, Terms of Service, and documented data retention procedures.

9. Processing Instructions

Largify Solutions shall Process Personal Data only:

  • in accordance with this DPA;
  • in accordance with the Terms of Service;
  • under documented instructions from the Customer;
  • where required by Applicable Data Protection Law.

If Largify Solutions believes that a Customer instruction infringes Applicable Data Protection Law, we may suspend implementation of that instruction until the matter has been clarified or resolved.

We are not responsible for verifying whether Customer instructions comply with laws applicable to the Customer's organisation or industry.

10. Processor Obligations

Largify Solutions shall process Personal Data only on behalf of the Customer and in accordance with this DPA, the Terms of Service, and documented Customer instructions, unless otherwise required by Applicable Data Protection Law.

As Processor, Largify Solutions agrees to:

  • process Personal Data only for the purposes of providing the Services;
  • ensure that authorised personnel are bound by confidentiality obligations;
  • implement appropriate technical and organisational security measures;
  • assist the Customer in fulfilling applicable data protection obligations where reasonably possible;
  • maintain appropriate records relating to Processing activities where required by law;
  • notify the Customer of confirmed Personal Data Breaches as required by this DPA;
  • ensure that Subprocessors are subject to appropriate contractual data protection obligations;
  • delete or return Personal Data following termination of the Services where required under this DPA;
  • cooperate with supervisory authorities where legally required.

Largify Solutions shall not sell Customer Personal Data or process Personal Data for advertising or profiling purposes unrelated to providing the Services unless expressly authorised by the Customer or required by law.

11. Customer Obligations

The Customer remains solely responsible for determining the purposes and legal basis for Processing Personal Data through Valion OS.

The Customer represents and warrants that it:

  • has all necessary rights and authority to provide Personal Data to Largify Solutions;
  • has identified an appropriate lawful basis for Processing;
  • has provided all required privacy notices;
  • has obtained any necessary consents where applicable;
  • complies with Applicable Data Protection Law;
  • will not instruct Largify Solutions to process Personal Data unlawfully;
  • will respond to Data Subject requests as required by law;
  • will configure user permissions appropriately within Valion OS;
  • will maintain appropriate security measures within its own organisation.

Largify Solutions is not responsible for determining whether the Customer's Processing activities comply with laws applicable to the Customer's business.

12. Confidentiality

Largify Solutions shall ensure that every employee, contractor, consultant, or authorised individual with access to Personal Data:

  • is subject to contractual or statutory confidentiality obligations;
  • receives access only where reasonably necessary;
  • accesses Personal Data solely for authorised business purposes;
  • follows internal security and privacy procedures.

Confidentiality obligations continue after employment or contractual relationships end.

13. Technical and Organisational Measures (TOMs)

Largify Solutions implements technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access.

Security measures may include:

Organisational Measures

  • information security governance;
  • documented security policies;
  • employee confidentiality agreements;
  • role-based responsibilities;
  • security awareness practices;
  • access approval procedures;
  • incident response planning;
  • vendor risk management.

Technical Measures

  • HTTPS encryption;
  • TLS encryption;
  • encryption at rest where supported;
  • secure password hashing;
  • Role-Based Access Control (RBAC);
  • tenant isolation;
  • authentication controls;
  • Multi-Factor Authentication where available;
  • audit logging;
  • infrastructure monitoring;
  • automated alerting;
  • secure backups;
  • vulnerability management;
  • secure software development practices.

Physical Measures

Where infrastructure is operated by third-party cloud providers, physical security controls are implemented by those providers in accordance with their own security programmes.

Security measures may evolve over time as technology, threats, and industry practices develop, provided such changes do not materially reduce the overall level of protection for Customer Personal Data.

14. Artificial Intelligence Processing

Valion OS provides AI-powered features that Customers may choose to use.

Where AI functionality is enabled:

  • Personal Data is processed only to provide requested AI functionality;
  • Customer prompts and uploaded information are processed only as necessary to generate requested outputs;
  • AI outputs are generated automatically and may contain inaccuracies;
  • Customers remain responsible for reviewing all AI-generated content before relying upon it.

Largify Solutions does not intentionally use Customer Business Data to train publicly available artificial intelligence models without the Customer's authorisation.

Trusted AI service providers engaged to support Valion OS are required to maintain appropriate contractual, security, and privacy safeguards.

15. Subprocessors

The Customer authorises Largify Solutions to engage Subprocessors where reasonably necessary to provide the Services.

Subprocessors may provide services including:

  • cloud infrastructure;
  • hosting;
  • authentication;
  • payment processing;
  • email delivery;
  • artificial intelligence services;
  • monitoring;
  • logging;
  • analytics;
  • customer communications.

Largify Solutions shall:

  • conduct reasonable due diligence before engaging material Subprocessors;
  • require Subprocessors to implement appropriate security measures;
  • impose data protection obligations substantially equivalent to those contained in this DPA;
  • remain responsible for the performance of Subprocessors to the extent required by Applicable Data Protection Law.

An up-to-date list of Subprocessors may be published on the Valion OS website or made available upon reasonable request.

Where required by Applicable Data Protection Law, Customers will be given notice of material changes to Subprocessors and, where legally applicable, an opportunity to raise reasonable objections.

16. International Data Transfers

Customer Personal Data may be processed or stored outside the Customer's country of residence where necessary to provide the Services.

Where Personal Data is transferred internationally and Applicable Data Protection Law requires additional safeguards, Largify Solutions will implement appropriate transfer mechanisms, which may include:

  • Standard Contractual Clauses (SCCs);
  • UK International Data Transfer Addendum;
  • adequacy decisions recognised by competent authorities;
  • other lawful transfer mechanisms permitted under Applicable Data Protection Law.

Customers acknowledge that cloud infrastructure providers and authorised Subprocessors may process Personal Data in multiple jurisdictions.

17. Data Subject Rights

Taking into account the nature of the Processing, Largify Solutions shall provide reasonable assistance to the Customer in responding to Data Subject requests where technically feasible.

Such requests may relate to:

  • the right of access;
  • rectification;
  • erasure;
  • restriction of Processing;
  • objection to Processing;
  • data portability;
  • withdrawal of consent;
  • automated decision-making rights where applicable.

Where Largify Solutions receives a request directly from a Data Subject relating to Customer Personal Data, we may:

  • refer the request to the Customer;
  • notify the Customer where legally permitted;
  • respond only where required by Applicable Data Protection Law.

The Customer remains responsible for determining how requests should be handled and for complying with applicable legal obligations.

18. Data Protection Impact Assessments (DPIAs)

Where required by Applicable Data Protection Law, Largify Solutions shall provide reasonable assistance to the Customer in carrying out Data Protection Impact Assessments and prior consultations with supervisory authorities.

Such assistance shall take into account:

  • the nature of the Processing;
  • information available to Largify Solutions;
  • the technical and organisational measures implemented;
  • the Customer's intended use of the Services.

Largify Solutions may charge reasonable fees for extensive assistance that exceeds standard support obligations, where permitted under the applicable agreement.

19. Personal Data Breaches

Largify Solutions maintains documented procedures for identifying, investigating, containing, and responding to Personal Data Breaches.

If Largify Solutions becomes aware of a confirmed Personal Data Breach affecting Customer Personal Data, we will notify the Customer without undue delay where required by Applicable Data Protection Law.

Subject to the information reasonably available at the time, the notification may include:

  • the nature of the Personal Data Breach;
  • the categories and approximate number of affected Data Subjects;
  • the categories and approximate volume of affected Personal Data;
  • the likely consequences of the breach;
  • measures taken or proposed to contain and remediate the incident;
  • recommendations for actions the Customer may consider taking.

Where all information cannot reasonably be provided at the time of the initial notification, additional information may be supplied as it becomes available.

Notification of a Personal Data Breach does not constitute an admission of fault or liability.

20. Audit Rights

Where required by Applicable Data Protection Law, Customers may request reasonable information demonstrating Largify Solutions' compliance with this DPA.

Evidence of compliance may include:

  • completed security questionnaires;
  • security documentation;
  • published security policies;
  • independent audit reports where available;
  • compliance documentation;
  • certifications obtained by Largify Solutions or relevant service providers.

Where additional audit rights are required by law or written agreement:

  • audits must be conducted during normal business hours;
  • reasonable prior written notice must be provided;
  • audits must not interfere with normal business operations;
  • auditors must be subject to appropriate confidentiality obligations;
  • Customers shall bear their own audit costs unless otherwise agreed.

Largify Solutions may decline audit requests that would:

  • compromise the security of other Customers;
  • expose confidential information belonging to third parties;
  • conflict with legal obligations;
  • create unreasonable operational disruption.

21. Government and Law Enforcement Requests

If Largify Solutions receives a legally binding request from a government authority, court, regulator, or law enforcement agency requiring disclosure of Customer Personal Data, we may disclose the requested information where legally required.

Where legally permitted, we will make reasonable efforts to:

  • notify the Customer before disclosure;
  • provide sufficient information to allow the Customer to seek protective measures;
  • limit disclosure to the minimum information legally required.

Nothing in this DPA prevents Largify Solutions from complying with applicable laws or legally binding governmental requests.

22. Assistance with Compliance

Taking into account the nature of the Processing and the information available to us, Largify Solutions shall provide reasonable assistance to Customers in meeting obligations under Applicable Data Protection Law, including where appropriate:

  • responding to supervisory authority enquiries;
  • supporting Data Protection Impact Assessments (DPIAs);
  • assisting with prior consultations;
  • providing information regarding implemented security measures;
  • supporting investigations relating to Customer Personal Data.

Assistance extending beyond ordinary operational support may be subject to reasonable charges where permitted under the applicable commercial agreement.

23. Data Retention

Largify Solutions retains Customer Personal Data only for as long as reasonably necessary to:

  • provide the Services;
  • fulfil contractual obligations;
  • maintain platform security;
  • resolve disputes;
  • comply with legal, regulatory, accounting, taxation, or fraud prevention requirements.

Retention periods may vary depending upon:

  • Customer configuration;
  • applicable legal requirements;
  • operational needs;
  • backup schedules;
  • security requirements.

Security logs, audit records, and operational information may be retained separately from Customer Business Data where necessary for legitimate operational or legal purposes.

24. Return and Deletion of Personal Data

Upon termination or expiration of the Services, and subject to Applicable Data Protection Law, Largify Solutions shall, upon the Customer's request or in accordance with our standard retention procedures:

  • provide Customers with the opportunity to export available Customer Data where technically feasible;
  • delete Customer Personal Data from active production systems following applicable retention periods;
  • securely destroy Customer Personal Data where continued retention is no longer required.

Customer Data contained within encrypted backups may remain temporarily until normal backup rotation and secure deletion procedures are completed.

Largify Solutions may retain limited Personal Data where required:

  • by law;
  • for taxation;
  • for accounting;
  • for fraud prevention;
  • for security investigations;
  • for legal claims;
  • for regulatory compliance.

Any retained information shall remain subject to the confidentiality obligations contained in this DPA.

25. Customer Responsibilities

The Customer acknowledges that compliance with Applicable Data Protection Law is a shared responsibility.

The Customer is responsible for:

  • determining the lawful basis for Processing;
  • providing legally required privacy notices;
  • obtaining any necessary consents;
  • ensuring uploaded Personal Data is accurate and lawfully obtained;
  • determining retention periods for Customer information;
  • configuring access permissions within Valion OS;
  • maintaining appropriate internal security controls;
  • responding to Data Subject requests;
  • ensuring the lawful use of AI-generated outputs where applicable.

Largify Solutions is not responsible for the Customer's internal compliance programme or legal obligations unrelated to providing the Services.

26. Liability

Each party's liability arising under this DPA shall be subject to the liability provisions contained within the Valion OS Terms of Service except where Applicable Data Protection Law prohibits such limitation.

Nothing in this DPA excludes or limits liability where exclusion or limitation is not permitted by applicable law.

27. Term and Termination

This DPA becomes effective on the earlier of:

  • the Customer's acceptance of the Terms of Service;
  • the Customer's first use of the Services involving Personal Data.

This DPA remains in effect for as long as Largify Solutions Processes Personal Data on behalf of the Customer.

Termination of the Terms of Service automatically terminates this DPA, except for provisions which by their nature survive termination, including:

  • confidentiality;
  • liability;
  • data deletion;
  • audit obligations;
  • governing law;
  • dispute resolution.

28. Governing Law

This DPA shall be governed by the governing law specified in the Valion OS Terms of Service, unless mandatory provisions of Applicable Data Protection Law require otherwise.

Nothing in this DPA limits the rights of Data Subjects or supervisory authorities under Applicable Data Protection Law.

29. Annex I – Details of Processing

Subject Matter

Processing of Personal Data necessary to provide the Valion OS platform and related services.

Nature of Processing

  • collection;
  • storage;
  • organisation;
  • hosting;
  • retrieval;
  • transmission;
  • synchronisation;
  • AI-assisted processing;
  • backup;
  • deletion.

Purpose of Processing

Providing, maintaining, securing, supporting, and improving the Valion OS platform in accordance with Customer instructions.

Duration

For the duration of the Customer's subscription and any applicable retention period required by law or legitimate operational necessity.

Categories of Personal Data

Including, where applicable:

  • identity information;
  • contact details;
  • customer records;
  • employee records;
  • booking information;
  • invoices;
  • CRM data;
  • uploaded documents;
  • communications;
  • technical identifiers;
  • AI prompts submitted by Customers.

Categories of Data Subjects

Including:

  • Customers;
  • employees;
  • contractors;
  • suppliers;
  • vendors;
  • patients;
  • clients;
  • authorised users;
  • website visitors;
  • other individuals whose Personal Data is uploaded by the Customer.

30. Annex II – Technical and Organisational Measures

Largify Solutions implements technical and organisational measures including, where appropriate:

  • secure software development lifecycle;
  • HTTPS and TLS encryption;
  • encryption at rest where supported;
  • logical tenant isolation;
  • Role-Based Access Control (RBAC);
  • Multi-Factor Authentication where available;
  • password hashing;
  • audit logging;
  • infrastructure monitoring;
  • vulnerability management;
  • incident response procedures;
  • disaster recovery planning;
  • secure backup procedures;
  • employee confidentiality obligations;
  • least-privilege administrative access;
  • security awareness practices;
  • vendor security assessments.

These measures may evolve over time provided that the overall level of protection is not materially reduced.

31. Annex III – Approved Subprocessors

Largify Solutions may engage trusted Subprocessors to support operation of the Services.

Categories of approved Subprocessors include:

  • cloud infrastructure providers;
  • managed database providers;
  • authentication providers;
  • artificial intelligence providers;
  • payment processors;
  • email delivery providers;
  • monitoring and observability providers;
  • customer support providers;
  • analytics providers.

An up-to-date list of specific Subprocessors will be maintained on the Valion OS website or made available upon reasonable request.

32. Contact Information

For privacy, GDPR, or data protection enquiries, please contact:

Largify Solutions (SMC-Private) Limited
Lahore, Punjab, Pakistan
Valion OS Website: https://www.valionos.com
Privacy Team: privacy@valionos.com
General Support: support@valionos.com
Company Contact: support@largifysolutions.com

Effective Date: 30 July 2026
Version: 1.0
© 2026 Largify Solutions (SMC-Private) Limited. All rights reserved.

Valion OS

The complete business operating system. Apps, AI Workforce, automation, and Workspace Studio in one platform. AI that operates on your live business data and workflows.

Secured by Paddle, our global Merchant of Record, localized checkout, automated tax compliance, and enterprise-grade billing security.

support@valionos.com · +966 59 736 9443

Platform
OverviewValion AppsAIIntegrationsPricing
Solutions
AgencyOSBeautyOSCleaningOSComing soonAll templates
Resources
BlogInformation HubCase studiesHelp & FAQChangelogRoadmap
Company
AboutCustomersCareersPartnersContact
Legal
PrivacyTermsSecurityCookie PolicyRefund
Stay in touch

Get product updates and launch notes, no spam.

© 2026 Valion OS. All rights reserved.

Powered by Largify Solutions