Data Processing Addendum

How SELCOR processes personal data on your behalf when you use Envlet.

Updated 2026-09-03

Parties and scope

This addendum forms part of the Terms of Service between the customer (Controller) and SELCOR (Processor). It applies where the Controller stores personal data in Envlet or where personal data of the Controller's users is processed by the Service.

Roles

The Controller decides what data is stored in Envlet and who may read it. The Processor processes that data only to provide the Service and on the Controller's documented instructions, which are the Terms, this addendum, and the configuration the Controller sets in the dashboard and API.

Nature of processing

Storage of encrypted values and their names, resolution of values to authorized identities, recording of resolution events without values, authentication of users, and billing. Data subjects are the Controller's team members and any individuals whose data appears in stored values. Duration is the life of the account plus the retention periods in the Privacy Policy.

Security

The Processor encrypts each value with AES-256-GCM under a per-project data key, wrapped by a root key held as a Worker secret and never stored in the database. Ciphertexts are bound to their project, environment, and variable name. Tokens are stored as digests. Every resolution is recorded without values. Organization owners can require TOTP for all members. Details are at envlet.dev/security.

Subprocessors

The Processor uses the subprocessors listed at envlet.dev/legal/subprocessors and will announce additions on that page at least 14 days before they process Controller data. The Controller may object in writing within that period.

Assistance and incidents

The Processor assists the Controller with data subject requests and security assessments as far as reasonable. The Processor notifies the Controller without undue delay, and within 72 hours of confirmation, of any personal data breach affecting Controller data.

Transfers

Data is processed in the United States. For transfers from the EEA, the UK, or Switzerland, the parties rely on the Standard Contractual Clauses (Module 2) and the UK Addendum, which are incorporated by reference.

Deletion and audit

On termination the Processor deletes Controller data as described in the Terms, keeping only resolution records without values for 13 months. The Controller may request a written description of the Processor's security measures once per year at hello@envlet.dev.