Data Processing Addendum (DPA)
Last updated: 2026-09-12
1. Scope
This DPA applies when you use Vecaria on behalf of an organisation and we process personal data on your instructions. It forms part of the Terms of Service.
2. Roles
You are the controller; Vecaria is the processor for account data and any personal data contained in files you choose to process in the cloud. Local processing does not transmit data to us.
3. Processing instructions
We process personal data only to provide, secure and support the service, and as required by law. We do not sell personal data or use file contents to train models.
4. Subprocessors
We use the subprocessors listed at /subprocessors (Cloudflare, Stripe, Resend). We give notice of changes on that page and require equivalent data-protection commitments.
5. Security
Encryption in transit (TLS 1.2+), encryption at rest by our infrastructure providers, access control and audit logging. See the Security page.
6. International transfers
Data may be processed in the United States, the EU and other regions where our subprocessors operate. Where required, transfers rely on Standard Contractual Clauses or equivalent safeguards.
7. Retention and deletion
Cloud file contents are retained per the configured retention period (Free: ephemeral; Pro: 30 days by default, adjustable in admin) and can be deleted at any time. Account data is deleted on request, subject to legal retention obligations.
8. Data subject requests
We assist with access, rectification, erasure and portability requests. Users can self-serve export and deletion from the account page.
9. Breach notification
We notify affected controllers without undue delay and in any event within 72 hours of becoming aware of a personal-data breach.
10. Contact
To execute a signed DPA: support@vecaria.com