veasybility.io← Back
GDPR Art. 28

Data Processing Agreement

This DPA forms part of and is incorporated by reference into the veasybility.io Terms of Service. By creating an account and accepting the Terms, the Customer accepts this DPA.

Last updated: 13 July 2026

1. Parties and roles

Where we process personal data on your behalf (see Section 3), you are the controller and we are the processor under Regulation (EU) 2016/679 (“GDPR”). For personal data we process for our own purposes (your account, billing, support), we are an independent controller and our Privacy Policy applies.

2. Subject matter, duration, nature and purpose

Subject matter & purpose: processing necessary to provide the veasybility.io service to you — in particular collecting website-visitor analytics via our plugin/connector, and generating and (where you enable it) publishing content to your website. Duration: for the term of the Agreement, plus the deletion period in Section 10.

3. Types of personal data and categories of data subjects

4. Processor obligations

We shall:

  1. process personal data only on your documented instructions (including this DPA and your use of the service), unless required by EU or Member State law;
  2. ensure persons authorised to process the data are bound by confidentiality;
  3. implement the technical and organisational security measures in Section 6;
  4. respect the conditions for engaging sub-processors in Section 7;
  5. assist you, taking into account the nature of processing, in fulfilling your obligations to respond to data-subject requests (Section 8);
  6. assist you with security, breach notification and data protection impact assessments (Sections 6, 9);
  7. at your choice, delete or return the personal data at the end of the service (Section 10);
  8. make available the information necessary to demonstrate compliance and allow for audits (Section 11).

5. Confidentiality

We keep personal data confidential and limit access to personnel who need it to provide the service, under appropriate confidentiality obligations.

6. Security measures (Art. 32)

Taking into account the state of the art and the risk, we maintain measures including: encryption in transit (TLS) and at rest; hashed passwords (bcrypt) and secrets; role-based access controls and least-privilege; row-level security on the database; segregation of customer data by account; secure EU-based hosting; and logging and monitoring. We review these measures periodically.

7. Sub-processors

You give general authorisation for us to engage sub-processors to provide the service. Current sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase & authenticationEU
VercelApplication & edge hostingEU/US
Anthropic, OpenAIAI content generation/analysisUS
StripePayments (account/billing data)EU/US
Resend, Zoho MailTransactional emailEU

We impose data-protection obligations on each sub-processor no less protective than this DPA. We will inform you of intended changes (additions/replacements) with reasonable notice, giving you the opportunity to object on reasonable data-protection grounds.

8. Data-subject rights

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their GDPR rights (access, rectification, erasure, restriction, portability, objection). If a data subject contacts us directly regarding your data, we will refer them to you.

9. Personal data breach

We notify you without undue delay (and where feasible within 72 hours) after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your own notification obligations.

10. Deletion / return

On termination of the service, or on your request, we delete personal data processed on your behalf within 30 days, unless EU or Member State law requires retention (e.g. accounting records, which we retain for the legally required period). Backups are purged on their normal rotation.

11. Audit and information

We make available information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — subject to reasonable notice, confidentiality, and no more than once per year unless required by a supervisory authority or following a breach.

12. International transfers

Where a sub-processor processes data outside the EU/EEA (e.g. in the US), such transfers are covered by the European Commission’s Standard Contractual Clauses (SCCs) and appropriate supplementary safeguards.

13. Precedence and liability

This DPA forms part of the Agreement. In case of conflict on data protection matters, this DPA prevails over the rest of the Agreement. Liability is subject to the limitations in the Agreement.

14. Contact

Data protection contact: support@veasybility.io · CREAITOR LABS EOOD, Sofia, Bulgaria.

veasybility.io — Get found & recommended by AI