This DPA forms part of and is incorporated by reference into the veasybility.io Terms of Service. By creating an account and accepting the Terms, the Customer accepts this DPA.
Last updated: 13 July 2026
Where we process personal data on your behalf (see Section 3), you are the controller and we are the processor under Regulation (EU) 2016/679 (“GDPR”). For personal data we process for our own purposes (your account, billing, support), we are an independent controller and our Privacy Policy applies.
Subject matter & purpose: processing necessary to provide the veasybility.io service to you — in particular collecting website-visitor analytics via our plugin/connector, and generating and (where you enable it) publishing content to your website. Duration: for the term of the Agreement, plus the deletion period in Section 10.
We shall:
We keep personal data confidential and limit access to personnel who need it to provide the service, under appropriate confidentiality obligations.
Taking into account the state of the art and the risk, we maintain measures including: encryption in transit (TLS) and at rest; hashed passwords (bcrypt) and secrets; role-based access controls and least-privilege; row-level security on the database; segregation of customer data by account; secure EU-based hosting; and logging and monitoring. We review these measures periodically.
You give general authorisation for us to engage sub-processors to provide the service. Current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & authentication | EU |
| Vercel | Application & edge hosting | EU/US |
| Anthropic, OpenAI | AI content generation/analysis | US |
| Stripe | Payments (account/billing data) | EU/US |
| Resend, Zoho Mail | Transactional email | EU |
We impose data-protection obligations on each sub-processor no less protective than this DPA. We will inform you of intended changes (additions/replacements) with reasonable notice, giving you the opportunity to object on reasonable data-protection grounds.
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their GDPR rights (access, rectification, erasure, restriction, portability, objection). If a data subject contacts us directly regarding your data, we will refer them to you.
We notify you without undue delay (and where feasible within 72 hours) after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your own notification obligations.
On termination of the service, or on your request, we delete personal data processed on your behalf within 30 days, unless EU or Member State law requires retention (e.g. accounting records, which we retain for the legally required period). Backups are purged on their normal rotation.
We make available information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — subject to reasonable notice, confidentiality, and no more than once per year unless required by a supervisory authority or following a breach.
Where a sub-processor processes data outside the EU/EEA (e.g. in the US), such transfers are covered by the European Commission’s Standard Contractual Clauses (SCCs) and appropriate supplementary safeguards.
This DPA forms part of the Agreement. In case of conflict on data protection matters, this DPA prevails over the rest of the Agreement. Liability is subject to the limitations in the Agreement.
Data protection contact: support@veasybility.io · CREAITOR LABS EOOD, Sofia, Bulgaria.