Skip to main content
Effective date: August 6, 2026 · Last updated: August 6, 2026
This Data Processing Agreement (“DPA”) forms part of the Master Services Agreement (the “Agreement”) between Customer (“Customer”) and the VESSL entity that is the contracting party under the Agreement (“VESSL”). Under this DPA, Customer acts as a controller or processor, as applicable, and VESSL acts as a processor or sub-processor, as applicable. If Customer registers for or uses the Services without executing an Order Form, VESSL AI, Inc., a Delaware corporation (“VESSL US”), is the contracting party. If Customer executes an Order Form, the VESSL entity identified in that Order Form is the contracting party. Capitalised terms not defined here have the meaning given in the Agreement. Where there is a conflict, this DPA prevails over the Agreement with respect to the processing of Customer Personal Data; the Standard Contractual Clauses set out at Annex 2 prevail over the body of this DPA for transfers they cover.

1. Definitions

  • Applicable Data Protection Laws — all laws applicable to the processing of personal data under the Agreement, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”), the GDPR as incorporated into UK national law and supplemented by the UK Data Protection Act 2018 (“UK GDPR”), the Republic of Korea Personal Information Protection Act (“PIPA”), the California Consumer Privacy Act and California Privacy Rights Act (“CCPA/CPRA”).
  • Customer Personal Data — personal data contained in Customer Content or in Outputs, in each case to the extent processed by VESSL on the Customer’s behalf in providing the Services. For the avoidance of doubt, personal data appearing in Outputs that VESSL processes is treated as Customer Personal Data for the purposes of this DPA, even where the underlying defined term “Customer Content” in the Agreement does not, on its own, include Outputs.
  • controller, data subject, personal data, personal data breach, processing, processor — as defined in the GDPR (or, where the GDPR does not apply, the equivalent terms under Applicable Data Protection Laws).
  • Service Provider, Business, Sale/Sell, Share, Sensitive Personal Information — as defined under the CCPA/CPRA where applicable.
  • Sub-processors — means the sub-processors engaged by VESSL to process Customer Personal Data in connection with the Services, as listed in the Sub-processor List.
Other capitalised terms have the meaning given in the Agreement.

2. Roles and scope

2.1 VESSL’s role. As part of providing the Services, VESSL processes Customer Personal Data as a processor where Customer is a controller and as a sub-processor where Customer is a processor on behalf of another controller. VESSL will process Customer Personal Data only to provide, operate, support, and secure the Services and only on Customer’s documented instructions. The Agreement, this DPA, the applicable Service-Specific Terms, and a support request or other instruction submitted by an authorized Customer representative constitute documented instructions only within their express scope. A support request does not authorize access to or alteration of Customer Personal Data beyond the purpose, systems, data types, permitted actions, and duration recorded for that request. 2.2 The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex 1. 2.3 Customer responsibilities. Customer warrants that it has a lawful basis and all necessary notices, consents, rights, and authority for the processing it instructs VESSL to perform, and that its instructions comply with Applicable Data Protection Laws. If Customer acts as a processor, Customer also warrants that the relevant controller has authorized Customer to appoint VESSL and the Sub-processors and to give the documented instructions reflected in this DPA. Customer is responsible for the accuracy and legality of Customer Content and for ensuring that a person who submits a support instruction or authorizes access to, or alteration of, Customer Personal Data has authority to do so on Customer’s behalf. 2.4 Notices to Customer. If VESSL believes an instruction infringes Applicable Data Protection Laws, VESSL will inform the Customer (without obligation to provide legal advice) and may suspend processing of the affected Customer Personal Data without liability, to the extent reasonably necessary to avoid VESSL’s own non-compliance. VESSL will, to the extent legally permitted, inform Customer if VESSL receives a legally binding request for disclosure of Customer Personal Data by a law enforcement authority.

3. Customer Content — restrictions on use and limited access

3.1 Restrictions on use for VESSL’s own purposes. VESSL will not access, read, use, analyse, mine, disclose, or otherwise process Customer Content for VESSL’s own purposes. VESSL will process Customer Content solely to provide, operate, support, and secure the Services on Customer’s documented instructions. VESSL will not use Customer Content, Inputs, or Outputs to train, fine-tune, or update any machine learning or artificial-intelligence model, whether internal or externally available, unless Customer affirmatively opts in in writing. Applying an existing automated security, malware, fraud, or AUP-enforcement tool does not authorize training or updating that tool or another model with Customer Content. 3.2 Limited access. VESSL may access Customer Content only to the minimum extent necessary and only where: (a) automated processing or limited operational access is required to provide or operate the Services in accordance with Customer’s documented instructions; (b) an authorized Customer representative requests or authorizes support or troubleshooting, provided that access to substantive Customer Content remains within the purpose and data scope recorded in the support request; (c) access is required by applicable law or valid legal process, subject to Section 2.4 where applicable; or (d) access is reasonably necessary to detect, investigate, prevent, or respond to abuse, fraud, malware, a security incident, or a suspected AUP violation. 3.3 Data-changing and destructive support actions. Except where Section 3.2(c) or the emergency exception below applies, VESSL will not delete, move, overwrite, modify, restore, reorganize, or execute a command reasonably expected to alter Customer Content in connection with support unless an authorized Customer account owner, administrator, or designated support contact gives action-specific authorization after VESSL describes the intended action and reasonably foreseeable data impact. A general request to “fix,” “resolve,” or “clean up” an issue is not by itself authorization to delete or materially alter Customer Content. Where practicable, VESSL will allow Customer to perform the remediation. If action is reasonably necessary to prevent or contain imminent material harm to the Services, other customers, or data, VESSL may take the least intrusive action reasonably available without prior Customer authorization. VESSL will require internal escalation where practicable, record the reason, scope, actor, time, and action, and notify Customer afterward unless legally prohibited or notice would materially impair the response. VESSL will prefer suspension or isolation over deletion where it adequately contains the risk. 3.4 No routine human monitoring. VESSL will not monitor or review the substantive content of Customer Content on a routine human basis. Human access under Sections 3.2 and 3.3 must be exceptional or Customer-directed, limited to personnel with a need to know, protected by confidentiality obligations, minimized to the approved purpose, time-limited where practicable, and linked to an access and action log. 3.5 Diagnostic artifacts. VESSL may create a memory dump, diagnostic bundle, screenshot, or exported copy containing Customer Content only where technically necessary for an identified support case, incident, or investigation and permitted under Sections 3.2 or 3.3. VESSL will treat each artifact as Customer Content and Customer Personal Data, restrict and log access, store it securely, and delete it promptly after the documented purpose is complete unless applicable law requires preservation.

4. Confidentiality

VESSL will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations (contractual or statutory). Access to Customer Personal Data is limited to personnel who need it to provide the Services.

5. Security

VESSL will implement and maintain an information security program incorporating physical, technical and organisational measures commensurate with the nature and risks of processing the Customer Personal Data including protection against unauthorised or unlawful processing of Customer Personal Data and against accidental loss, destruction and damage. Such physical, technical and organisational measures will at a minimum include those described in Annex 3. VESSL may update these measures from time to time, provided the overall level of security is not materially reduced.

6. Sub-processors

6.1 The Customer hereby provides general authorisation for VESSL to engage the Sub-processors listed in the Sub-processor List (Annex 4) (as amended from time to time) to process Customer Personal Data in connection with the Services. 6.2 VESSL will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA. VESSL remains liable for its Sub-processors’ acts and omissions to the same extent VESSL would be liable if performing the services of each Sub-processor directly under the terms of this DPA. 6.3 Notice and objection. VESSL may add or replace a Sub-processor by giving Customer at least thirty (30) days’ prior written notice. Customer may object by written notice to privacy@vessl.ai within fifteen (15) days after VESSL’s notice, but only on reasonable and documented grounds relating to the protection of Customer Personal Data. VESSL will provide information reasonably necessary to evaluate the objection, and the parties will work in good faith to resolve it. If VESSL cannot reasonably avoid using the proposed Sub-processor for the affected Service or provide a commercially reasonable alternative without material burden or cost, either party may terminate only the affected Service before the proposed Sub-processor begins processing Customer Personal Data. On such termination, VESSL will refund any unused pre-paid Fees specifically paid for the terminated affected Service. Purchased Credits remaining in Customer’s account remain subject to Annex A and are not refundable except as required by applicable law. Customer’s failure to object within the fifteen-day period constitutes acceptance of the proposed change.

7. Data subject requests

VESSL will, to the extent legally permitted, inform Customer if VESSL receives a request to exercise data subject rights pursuant to Applicable Data Protection Laws (“Data Subject Request”) in respect of any Customer Personal Data. Taking into account the nature of the processing, VESSL will provide reasonable assistance to the Customer, at Customer’s cost, by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject Requests. If VESSL receives a request directly from a data subject regarding Customer Personal Data, it will not respond on the merits but will, where permitted, redirect the data subject to the Customer and notify the Customer without undue delay.

8. Personal Data Breach

VESSL will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. VESSL will provide reasonable assistance to Customer, at Customer’s cost, to help Customer comply with its obligations under Applicable Data Protection Laws in respect of such personal data breach.

9. Assistance to Customer

VESSL will (i) where legally required, and at Customer’s cost, provide reasonable assistance to Customer as necessary for Customer to meet its obligations under Applicable Data Protection Laws including, where appropriate, the preparation of data protection impact assessments or similar assessments with respect to VESSL’s processing of Customer Personal Data, and (ii) on Customer’s reasonable written request, and at Customer’s cost, provide the information reasonably necessary for Customer to conduct a Transfer Impact Assessment under EDPB Recommendations 01/2020 (or equivalent), provided that such information will be VESSL’s Confidential Information.

10. International transfers

10.1 Region-based processing. For Self-Service, VESSL processes Customer Personal Data in the region or regions selected by Customer through the VESSL console or the applicable Services configuration. For B2B, VESSL processes Customer Personal Data in the region or regions selected in the applicable Order Form or the applicable Services configuration. Backup, disaster-recovery, support-engineer access, billing, and operational metadata may be processed in other regions as set out in the Documentation or the applicable Order Form. VESSL may transfer Customer Personal Data outside the selected region or regions as necessary to (a) provide the Services as instructed by Customer, (b) provide global support functions and operational continuity, (c) comply with applicable law, or (d) respond to a security incident. 10.2 EEA. Where processing involves transfers of Customer Personal Data subject to the GDPR to a country without an adequacy decision, the SCCs are incorporated by reference and apply with the elections in Annex 2: Module Two applies where Customer is a controller, and Module Three applies where Customer is a processor. For transfers from any other jurisdiction with transfer restrictions not otherwise addressed in this Section 10, the parties cooperate in good faith as set out in Section 10.5. 10.3 UK. Where processing involves transfers of Customer Personal Data subject to the UK GDPR to a country without an adequacy decision, the UK Addendum to the SCCs, incorporated herein at Schedule 1, applies. 10.4 Republic of Korea. Where processing involves overseas transfers from the Republic of Korea, VESSL will provide the information required under PIPA Article 28-8 and assist the Customer in obtaining consent or otherwise relying on a lawful ground for the transfer. VESSL maintains internal procedures sufficient to fulfil this Section 10.4 and provides the Customer with reasonable documentation of those procedures on written request. 10.5 Other jurisdictions. For other jurisdictions imposing transfer restrictions, the parties will cooperate in good faith to implement appropriate safeguards.

11. Audit

VESSL will, upon Customer’s reasonable request, provide to Customer third-party audit reports and certifications relating to VESSL’s compliance with this DPA. If, after reviewing such reports and/or certifications, the Customer reasonably requests a further audit, the parties will discuss in good faith the scope, timing, and conditions of any audit. Any audit agreed under this DPA must be: (i) conducted no more than once per year (except where a competent supervisory authority requires), (ii) with at least 60 days’ prior written notice (or shorter where an authority directly requires), (iii) during normal business hours, (iv) conducted in a manner that is minimally disruptive to VESSL’s operations, (v) subject to an appropriate confidentiality agreement between the parties, and (vi) at Customer’s sole cost and expense.

12. Return and deletion

12.1 Return or deletion. Subject to Sections 12.2 and 12.3, on termination or expiry of the Agreement, VESSL will return or delete Customer Personal Data in accordance with Customer’s documented choice or the lifecycle selected by Customer under the applicable Annex or Order Form, unless applicable law requires retention. 12.2 Recovery/export period. For a voluntary Self-Service account termination, ordinary account, credential, workload, and console access ends immediately. For fourteen (14) days after termination, Customer may request controlled account recovery or export of eligible Customer Content through the process stated in Annex A and the Support Policy. VESSL is not required to restore billable workloads or ordinary account access solely to provide an export. A B2B Customer may receive a different period expressly stated in its private Order Form, including up to ninety (90) days. 12.3 Deletion and limited retention. At the end of the applicable period, VESSL will delete or de-identify Customer Personal Data from active systems, except that: (a) data belonging to an organization with another authorized member is not deleted solely because one user withdraws; (b) temporary or ephemeral data may be deleted earlier under an applicable Service-Specific Term; (c) separately managed storage remains subject to its expressly stated lifecycle; and (d) limited data in backups, security or audit records, transaction records, or a legal hold may be retained only for so long as required by applicable law or a documented retention schedule made available to Customer. Data retained under clause (d) remains protected under this DPA, is unavailable for ordinary use, and will be deleted or de-identified when the applicable requirement or schedule expires.

13. CCPA / CPRA and US state-law commitments

13.1 CCPA/CPRA. Where the Customer is a “Business” (or a service provider acting for a Business) under the CCPA/CPRA, VESSL acts as a “Service Provider” for Customer Personal Data and will comply with the following additional provisions:
  • No sale, share, or unauthorised use. VESSL will not “Sell” or “Share” Customer Personal Data, and will not retain, use, or disclose it for any purpose other than the business purposes in the Agreement and this DPA, or outside the direct business relationship with Customer. VESSL will not combine it with personal information from other sources except as permitted under CCPA §1798.140(ag)(1)(D).
  • Same level of protection. VESSL will provide the same level of privacy protection as the CCPA/CPRA requires of a Business.
  • Notice on inability to comply. VESSL will notify the Customer if it determines it can no longer meet its CCPA/CPRA obligations; the Customer may then take reasonable steps to stop and remediate unauthorised use, including suspending the relevant processing of Customer Personal Data.
  • Sub-processors. VESSL will flow down commitments substantially similar to this Section to any Sub-processor.
13.2 Other US states. Where a comparable comprehensive US state privacy law applies, VESSL acts in its equivalent processor capacity under that law as mutually agreed by the parties, and will be subject to the other provisions of this DPA.

14. General

14.1 Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. 14.2 This DPA is governed by the governing law and forum specified in Section 14.1 of the Agreement, except that the SCCs are governed by the law and subject to the forum they specify. 14.3 If any provision is held invalid, the remainder continues in effect. 14.4 Subject to Section 6.3, VESSL may update this DPA from time to time in accordance with Section 14.10 of the Agreement.

15. Term and termination

This DPA is effective from execution of the Agreement (“Effective Date”) and remains in effect for as long as VESSL processes Customer Personal Data. Obligations relating to confidentiality and return/deletion survive termination.

Annex 1 — Details of processing

A. List of parties

Data exporter (Customer — controller or processor, as applicable): for Self-Service, the individual or organization identified as Customer under the Agreement and in VESSL’s account and console records, with the contact details associated with that account; for B2B, the entity identified as Customer in the applicable Order Form, with its contact details, contact role, and signature, if any, as set out in that Order Form. Data importer (VESSL — processor or sub-processor, as applicable): The identity of the data importer depends on which VESSL entity is party to the Agreement. (a) If the contracting entity is VESSL Korea, the data importer is VESSL Korea. (b) If the contracting entity is VESSL US, the data importer is VESSL US.

B. Description of processing

C. Competent supervisory authority

The supervisory authority determined under Clause 13 of the SCCs based on the data exporter’s circumstances.

Annex 2 — Standard Contractual Clauses

The EU SCCs (Decision (EU) 2021/914) are incorporated as follows:
  • Module selection: Module Two (controller-to-processor) where Customer is a controller; Module Three (processor-to-processor) where Customer is a processor.
  • Clause 7 (docking): applies.
  • Clause 9 (sub-processors): Option 2 (general written authorisation); minimum notice period 30 days (Section 6.3).
  • Clause 11 (redress): the optional independent-dispute-resolution body does not apply.
  • Clause 13 (competent supervisory authority): the competent supervisory authority is determined in accordance with Clause 13 and Annex 1, Part C.
  • Clause 17 (governing law) & 18 (forum): the law and courts of Ireland.
  • Annex I.A/B/C, II, III of the SCCs: completed by reference to Annex 1, Annex 3, and the Sub-processor List of this DPA.

Annex 3 — Technical and organisational measures

VESSL maintains the following measures, which VESSL may update provided the level of security is not materially reduced:
  • Information security program — documented policies and procedures aligned with industry standards (e.g., ISO/IEC 27001, SOC 2 criteria).
  • Access control & key management — role-based, least-privilege access; SSO with mandatory multi-factor authentication for personnel; periodic access reviews and prompt revocation on role change; dedicated key-management services (HSM-backed where supported) with documented rotation, separation of duties, and least-privilege key access.
  • Encryption — encryption in transit (TLS 1.3 by default; TLS 1.2 for legacy clients pending deprecation) and at rest (AES-256 or equivalent); passwords stored as one-way hashes; user secrets encrypted.
  • Network & endpoint security — network segmentation, firewalls, intrusion detection/prevention, and DDoS protection at VESSL-controlled edge layers (additional protections at the underlying infrastructure layer depend on the relevant sub-processor’s certifications); hardened images, patch management, and endpoint protection on personnel devices; automatic masking of sensitive fields (passwords, tokens, keys, secrets) in logs.
  • Logging, monitoring & log retention — centralised logging, anomaly detection, SIEM, and security operations; security/audit logs retained for a period appropriate to risk (typically 12 months for security/audit logs and 90 days for operational telemetry), with integrity controls against unauthorised modification or deletion.
  • Vulnerability management & audit — periodic vulnerability scanning, penetration testing, secure SDLC, dependency management; periodic third-party audits (e.g., SOC 2 Type II, ISO/IEC 27001/27017/27018/27701) and an internal audit program.
  • Personnel security — background checks (where permitted), confidentiality obligations, and periodic security and privacy training.
  • Physical security — Services provisioned on data centres operated by sub-processors with industry-recognised certifications (e.g., ISO 27001, SOC 2), each onboarded under VESSL’s vendor-risk management program; controlled office access.
  • Incident response — documented incident-response plan, on-call rotation, post-incident review, and breach-notification procedures (Section 8).
  • Business continuity & disaster recovery — backup, restoration, and failover procedures; multi-availability-zone backups.
  • Data segregation — logical separation of Customer Personal Data between tenants.
  • Data minimisation — practices designed to limit processing to what is necessary to provide the Services and honour Customer instructions.
  • Secure disposal — media sanitisation per industry standards (e.g., NIST SP 800-88) before reuse or disposal, and secure destruction of decommissioned media managed by VESSL or its sub-processors.
  • Support and diagnostic access — named support roles; individual non-shared administrator accounts; strong authentication; least-privilege and, where practicable, just-in-time or time-limited elevation; ticket-linked Customer authorization; access and action logging; separate confirmation for destructive actions; secure handling and prompt deletion of diagnostic artifacts; periodic access review; and training for Support and Engineering personnel.

Annex 4 — Sub-processors

The current list of sub-processors is maintained at the Sub-processor List and forms part of this DPA. SCHEDULE 1 — UK ADDENDUM TO SCCS

Part 1: Tables

Table 1: Parties

Table 2: Selected SCCs, Modules and Selected Clauses

Addendum EU SCCs
  • ☐ The version of the Approved EU SCCs which this Addendum is appended to, detailed below, including the Appendix Information:
Date: Reference (if any): Other identifier (if any): Or
  • ☒ the Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum:

Table 3: Appendix Information

Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:
  • Annex 1A: List of Parties: See Annex 1, Part A of this DPA
  • Annex 1B: Description of Transfer: See Annex 1, Part B of this DPA
  • Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data: See Annex 3 of this DPA
  • Annex III: List of Sub processors (Modules 2 and 3 only): See Annex 4 of this DPA

Table 4: Ending this Addendum when the Approved Addendum Changes

Ending this Addendum when the Approved Addendum changes Which Parties may end this Addendum as set out in Section 19:
  • ☒ Importer
  • ☐ Exporter
  • ☐ neither Party
Part 2: Mandatory Clauses Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.