Data Processing Addendum
Article 28 terms for customers who are controllers of personal data processed through VibeLock.
This addendum applies automatically where you are a controller and we process personal data on your behalf. Enterprise customers who need a countersigned copy can request one at legal@vibelock.ai.
1. Roles
For personal data you submit through the Service about your own users and team, you are the controller and we are the processor. For account and billing data about you, we are a controller and our Privacy Policy applies.
2. Scope of processing
- Subject matter
- Provision of the VibeLock platform.
- Duration
- The term of your subscription, plus the retention periods stated in the Privacy Policy.
- Nature and purpose
- Hosting, storage, transmission and display of security program data, and generation of documents.
- Types of personal data
- Names, email addresses, role assignments, and any personal data you choose to enter into free-text fields.
- Categories of data subject
- Your team members, and any individual referenced in a security or privacy record you create.
3. Our obligations
- Process personal data only on your documented instructions, including for transfers, unless required otherwise by law, in which case we will inform you unless legally prohibited.
- Ensure personnel authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures under Article 32, as described in the Security section of the Privacy Policy and on our security page.
- Assist you, taking into account the nature of processing, with data subject requests, and with your obligations under Articles 32 to 36 including breach notification and data protection impact assessments.
- Notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data, with the information available to us at that time and updates as the picture develops.
- Delete or return personal data at the end of the provision of services, subject to legal retention.
- Make available information necessary to demonstrate compliance and allow for audits, as set out below.
- Immediately inform you if, in our opinion, an instruction infringes the GDPR, the UK GDPR or other applicable data protection law, as required by the final paragraph of Article 28(3).
We do not use personal data processed on your behalf for our own purposes, and we do not use it, or permit our subprocessors to use it, to train machine learning models.
3a. Technical and organisational measures
The measures below are the Article 32 measures referred to above. They are stated here so this addendum is complete on its face rather than pointing at a page that may change.
- Encryption in transit
- TLS 1.3 for all connections.
- Encryption at rest
- AES-256 across the database and object storage.
- Application-layer encryption
- Vulnerability records are encrypted above the database layer, so a database compromise alone does not expose readable findings.
- Tenant isolation
- Row level security is enabled on every table, so one account cannot read another account data.
- Access control
- Role-based permissions, multi-factor authentication available to all users and required for administrative accounts, session expiry and revocation, and new device and location alerting.
- Secret handling
- API key values are never received or stored. Only key names and service types are held.
- Logging and monitoring
- Sensitive actions are recorded in an audit log with actor, action and timestamp.
- Vulnerability management
- Dependencies are monitored for known vulnerabilities and critical issues are patched on a defined timeline.
- Resilience
- Managed database backups with point-in-time recovery.
4. Subprocessors
You give general authorisation for us to engage subprocessors. The current list is published on our Subprocessors page. We will give at least 30 days notice before adding or replacing a subprocessor, and you may object on reasonable data protection grounds, in which case we will work with you in good faith or you may terminate the affected service.
We impose data protection obligations on subprocessors no less protective than those in this addendum and remain liable for their performance.
5. International transfers
Where a transfer is covered by an adequacy decision, including the EU-US Data Privacy Framework and its UK Extension and Swiss-US counterpart for certified recipients, that decision is the transfer mechanism.
Otherwise, where we process personal data subject to EU, UK or Swiss law outside those territories, the European Commission Standard Contractual Clauses (Decision 2021/914) are incorporated into this addendum by reference, with you as data exporter and us as data importer, Module Two (controller to processor). The UK International Data Transfer Addendum applies to UK transfers, and the Swiss amendments apply to Swiss transfers. Where an onward transfer to a subprocessor occurs, Module Three applies as appropriate.
We carry out and maintain a transfer impact assessment for each corridor where we rely on the Standard Contractual Clauses, in line with European Data Protection Board recommendations on supplementary measures, and we reassess when a subprocessor, corridor or adequacy decision changes. A copy is available on request.
Where the Standard Contractual Clauses conflict with any other term of this addendum or the Terms, the Standard Contractual Clauses prevail.
6. Audit
On reasonable written request, no more than once in any twelve month period unless required by a supervisory authority, we will provide information reasonably necessary to demonstrate compliance with this addendum. Where an on-site audit is legally required, the parties will agree scope and timing in advance, it will be conducted during business hours without unreasonably disrupting our operations, and the auditor must be bound by confidentiality and must not be our competitor.
7. Liability
Each party liability under this addendum is subject to the limitations and exclusions in the Terms of Service.
Data Processing Addendum · Effective 17 August 2026 · All legal documents