Data Processing Agreement (DPA)
Last updated: 30 July 2026
This Data Processing Agreement (the “DPA”) gives effect to the obligations under Art. 28 of Regulation (EU) 2016/679 (GDPR) between the customer as controller and Veyllo GmbH (“Veyllo”) as processor. It forms part of the Terms of Service and applies where the customer uses the services as a business and Veyllo processes personal data on the customer’s behalf. Veyllo provides a signed copy on request to legal@veyllo.io.
1. Subject matter and duration
The subject matter of this DPA is the processing of personal data by Veyllo in the course of providing the Veyllo API and related services. The scope and purpose of the processing follow from the Terms of Service and from clause 2.
The term of this DPA equals the term of the service agreement. It ends when that agreement ends, without requiring separate notice.
2. Nature and purpose of processing, data types, data subjects
Purpose of the processing is the performance of the contracted services: answering text and image requests with language models and transcribing audio.
Nature of the processing: receiving the inputs the customer submits, forwarding them to the sub-processors described in Annex B, returning the results to the customer, and recording usage metrics as counters. Veyllo does not store inputs or outputs beyond the duration of the processing; the service architecture is stateless.
Types of data: the personal data contained in the customer’s inputs (text, images, audio). The customer alone determines which data is submitted. Special categories of personal data (Art. 9 GDPR) are covered only where the customer has ensured a suitable legal basis for their processing.
Categories of data subjects: the persons whose data the customer submits in its inputs, such as the customer’s employees, customers, suppliers, or other contacts.
3. Responsibility and right of instruction
The customer is the controller within the meaning of Art. 4 No. 7 GDPR. The customer is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects, and ensures that transmitting the data to Veyllo is permissible.
Veyllo processes the data only on the customer’s documented instructions. The instructions follow from this DPA, the Terms of Service, and the actual use of the services, in particular the API calls and the parameters chosen in them. Supplementary individual instructions must be in text form.
If Veyllo considers an instruction to infringe the GDPR or other data protection law, Veyllo informs the customer without undue delay and may suspend carrying out the instruction until it is confirmed or changed.
4. Confidentiality
Veyllo ensures that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of secrecy (Art. 28(3)(b) GDPR). The commitment survives the end of their engagement.
5. Security of processing
Veyllo implements the technical and organisational measures under Art. 32 GDPR described in Annex A. The measures are subject to technical progress; Veyllo may develop them further as long as the agreed level of protection is not reduced.
6. Sub-processors
The customer grants general authorisation for the use of sub-processors (Art. 28(2) GDPR). The sub-processors engaged at the conclusion of this DPA are described in Annex B by function and place of processing; Veyllo provides the named list, including registered seats, to the customer at contract conclusion and at any time on request in text form.
Veyllo informs the customer in text form in advance of intended changes, that is the addition or replacement of sub-processors. The customer may object to the change within 14 days on substantiated data protection grounds. If no amicable solution is reached, either party may terminate the affected service with effect from the date the change takes effect.
Veyllo imposes on every sub-processor, by way of a contract, the same data protection obligations as set out in this DPA (Art. 28(4) GDPR), in particular sufficient guarantees of appropriate technical and organisational measures.
7. Transfers to third countries
Processing in third countries takes place only where the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of the European Commission’s Standard Contractual Clauses or, where the recipient is certified, the EU–US Data Privacy Framework. The affected processing operations are described in Annex B and in the Privacy Policy.
8. Assistance to the customer
Taking into account the nature of the processing, Veyllo assists the customer with appropriate measures in fulfilling the rights of data subjects (Art. 12 to 23 GDPR) and the obligations under Art. 32 to 36 GDPR (Art. 28(3)(e) and (f) GDPR).
Because Veyllo does not store inputs or outputs beyond the processing, access, rectification and erasure of content data lie within the customer’s sphere. Requests from data subjects that reach Veyllo directly are forwarded to the customer without undue delay, where attribution is possible.
9. Notification of personal data breaches
Veyllo notifies the customer of any personal data breach concerning data processed under this DPA without undue delay after becoming aware of it (Art. 33(2) GDPR). The notification contains the information under Art. 33(3) GDPR available at that time; Veyllo supplies further information as it becomes available.
10. Deletion and return
Content data is, by design, not stored (clause 2). After the end of the agreement, Veyllo deletes the remaining personal data processed under this DPA or returns it, at the customer’s choice, unless a statutory retention obligation applies (Art. 28(3)(g) GDPR). Account and billing data for which Veyllo is itself the controller remain unaffected; the Privacy Policy applies to them.
11. Evidence and audits
Veyllo makes available to the customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR (Art. 28(3)(h) GDPR), in particular the description of the measures in Annex A and existing attestations and certificates of the infrastructure providers used.
The customer may additionally conduct audits, or have them conducted by an auditor bound to confidentiality and not a competitor of Veyllo. Audits take place on reasonable advance notice, at most once per calendar year, during normal business hours and without disproportionately disrupting operations; audits for cause following a breach under clause 9 remain unaffected. Each party bears its own costs.
12. Final provisions
In case of conflict between this DPA and the Terms of Service, this DPA prevails to the extent the processing of personal data on behalf of the customer is concerned. Liability is governed by the Terms of Service and Art. 82 GDPR.
The law of the main agreement applies. Should individual provisions of this DPA be invalid, the validity of the remaining provisions remains unaffected.
Annex A: Technical and organisational measures (Art. 32 GDPR)
State of the measures at the conclusion of this DPA. Veyllo develops the measures in line with the state of the art.
- Transmission control: all connections are TLS-encrypted, from the customer to Veyllo and from Veyllo to the sub-processors.
- Access control: access to production systems is limited to authorised persons on a least-privilege basis. Customers authenticate through accounts; API access uses keys that are stored exclusively as a cryptographic hash (SHA-256).
- Storage control: data at rest is stored encrypted with the infrastructure providers used. API inputs and outputs are not stored beyond the processing; audio is not retained after transcription.
- Separation control: every request is attributed to one customer account and processed separately. There is no cross-account or cross-customer storage of contexts or histories.
- Data minimisation: usage data is recorded only as counters, such as token volumes and timestamps, without content. Logs contain no content data.
- Availability control: operation on redundant cloud infrastructure with monitoring; rate limits per account, per key and per IP address protect the service against abuse.
- Organisational measures: confidentiality commitments of authorised persons, prompt installation of security updates, regular review of the measures.
Annex B: Sub-processors
Sub-processors at the conclusion of this DPA, described by function and place of processing. Veyllo provides the named list, including registered seats and transfer safeguards, to the customer at contract conclusion and at any time on request in text form to legal@veyllo.io.
- Hosting of the API gateway: Vercel Inc.; processing in the United States is possible, safeguards per clause 7.
- External AI model provider for the vision capability; the contracting entity for the EEA is established in the EU, and processing also takes place in the United States.
- Inference hosting provider based in the United States for the chat capability, where processing does not run on Veyllo’s own infrastructure within the EEA.
- Speech-recognition provider for the transcription capability; processing on infrastructure within the European Union (EU regional endpoint).
- Storage of usage metrics (counters without content data): Supabase; hosted in the European Economic Area or the United Kingdom.