Data Processing Agreement
Last updated: August 11, 2026
When you use vvault to reach your own contacts, you decide who is contacted and why - so you are the controller and we are your processor. This agreement sets out what we may do with that data, how we secure it, who else touches it, and what happens to it when you leave. It applies automatically and needs no signature.
1. When This Agreement Applies
This Data Processing Agreement ("DPA") forms part of the vvault Terms of Use and applies automatically, without separate signature, whenever you use vvault to process personal data for which you decide the purposes and the means. In that situation you act as the controller and vvault acts as your processor within the meaning of Article 4 of Regulation (EU) 2016/679 ("GDPR").
Concretely, vvault is your processor when you upload or import contacts, build groups or segments, send email campaigns or series to recipients you have chosen, and when engagement events are recorded on links, packs, tracks or pages you share. In each of those cases you decide who is contacted, why, and on what legal basis; we only execute.
vvault is not your processor, and acts as an independent controller, for everything it decides itself: your own account and profile data, authentication, billing and subscriptions, marketplace order records, fraud prevention, security logging, content moderation, and product analytics measuring how vvault itself is used. Those processing activities are described in our Privacy Policy, not here.
Where a single feature involves both roles, each party is responsible for its own part. This DPA governs only the processor part.
2. Subject-Matter, Duration, Nature and Purpose
Subject-matter: the provision of the vvault platform to you, limited to the features identified in Section 1.
Duration: for as long as your vvault account is active, and thereafter for the limited period described in Section 11.
Nature and purpose: storing contact records you supply; segmenting and organising them according to your instructions; composing, scheduling and delivering email messages you author to recipients you designate; recording engagement events generated by those messages and by links you share; and presenting the resulting analytics to you. We do not use this data for any purpose of our own.
3. Categories of Data Subjects and Types of Personal Data
Categories of data subjects: the contacts you import or create (typically artists, producers, engineers, A&Rs, label staff and other music-industry professionals), the recipients of the campaigns you send, and the visitors who open the links, pages or packs you share.
Types of personal data: email address; name or alias where you provide it; any notes, tags, group membership or custom fields you attach to a contact; the content of the messages you send; delivery and engagement events (delivered, opened, clicked, played, play duration, downloaded, saved) together with the technical data generated by those events, including IP address, approximate region, user agent and timestamps.
You must not use vvault to process special categories of personal data within the meaning of Article 9 GDPR, nor personal data relating to criminal convictions and offences under Article 10. vvault is not designed, assessed or secured for that purpose. If you do so anyway, you do it outside these instructions and at your own risk.
4. Processing Only on Your Documented Instructions
We process personal data covered by this DPA only on your documented instructions, including as regards transfers to a third country. Your instructions consist of this DPA, the Terms of Use, and the actions you take in the product itself - each import, segment, send or share is an instruction.
We will process personal data outside your instructions only where required to do so by Union or Member State law to which we are subject. In that case we will inform you of that legal requirement before processing, unless that law prohibits the notification on important grounds of public interest.
If we consider that an instruction you give infringes the GDPR or other Union or Member State data protection provisions, we will inform you without undue delay and may suspend execution of that instruction until it is withdrawn, confirmed or amended.
5. Confidentiality
vvault is operated by a sole proprietor. Access to personal data processed on your behalf is limited to the operator and to those service providers listed as sub-processors, each of which is bound by its own confidentiality obligations.
Any person authorised in the future to process personal data on our behalf will be bound by a written confidentiality undertaking, or by an appropriate statutory obligation of confidentiality, before being granted access.
6. Security Measures (Article 32)
We implement technical and organisational measures appropriate to the risk, and we will not lower them in a way that materially reduces the level of protection during the term of this DPA.
Measures currently in place include: encryption of all traffic in transit over TLS; encryption at rest for the primary database and object storage; audio and other private files served exclusively through signed, expiring URLs rather than public paths; row-level access control in the database so that one account cannot read another account's records; scoped and rotated service credentials; multi-factor authentication on administrative accounts; least-privilege separation between the public application role and the administrative role; logging of authentication and administrative events; and regular application of security updates to dependencies and platform components.
We test restoration of backups and we review access rights periodically. No system is perfectly secure, and we do not represent otherwise; what we commit to is a level of protection appropriate to the risk, and honest, prompt disclosure when it fails.
7. Sub-Processors
You give us general written authorisation to engage sub-processors. The current list is published and kept up to date on our Sub-Processors page, which forms part of this DPA.
We will give you at least thirty (30) days' notice by email, or through a prominent in-app notice, before adding or replacing a sub-processor. During that period you may object on reasonable data protection grounds. If you object and we cannot offer a reasonable alternative, you may terminate the affected service and receive a pro-rata refund of any prepaid, unused fees; that is your exclusive remedy, because we cannot operate the platform without infrastructure providers.
We impose on every sub-processor, by contract, data protection obligations that are no less protective than those set out in this DPA. Where a sub-processor fails to fulfil those obligations, we remain fully liable to you for the performance of that sub-processor's obligations.
8. International Transfers
Our primary hosting, database and object storage are located in the European Union. Some sub-processors process personal data outside the European Economic Area, in particular in the United States.
Where personal data is transferred outside the EEA, we rely on a transfer mechanism recognised under Chapter V GDPR: an adequacy decision of the European Commission where one covers the recipient, or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, supplemented where necessary by additional technical and organisational measures.
The Sub-Processors page identifies, for each sub-processor, the processing location and the transfer mechanism relied upon.
9. Assisting You With Data Subject Rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise the rights laid down in Chapter III GDPR - access, rectification, erasure, restriction, portability and objection.
In practice, the product itself gives you direct control: you can search, edit, export and delete any contact record, and remove recipients from any list, without contacting us. In most cases you can therefore answer a data subject yourself, immediately and without our involvement.
If a data subject contacts us directly about data you control, we will not respond to the substance of the request. We will inform them that you are the controller and, where we can identify you, forward the request to you without undue delay.
Where our assistance is genuinely required beyond the self-service tools, we provide it without additional charge unless the request is manifestly unfounded, excessive or repetitive.
10. Personal Data Breaches, DPIAs and Prior Consultation
We notify you without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact for further information. Where we cannot provide all of that at once, we provide it in phases without further undue delay.
You remain responsible for notifying your supervisory authority under Article 33 and, where required, the affected data subjects under Article 34. We do not make those notifications on your behalf, because only you know the context and the risk to the individuals concerned.
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation of the supervisory authority.
11. Deletion and Return of Data
You can export the personal data you control at any time, in a structured, commonly used and machine-readable format, from your account settings. That right does not depend on termination and does not require our involvement.
At your choice, we delete or return to you all personal data processed on your behalf after the end of the provision of services, and delete existing copies, unless Union or Member State law requires storage of the personal data.
Unless you instruct otherwise before deleting your account, we delete this data. Deletion takes effect immediately in the live systems and propagates to encrypted backups within thirty (30) days, after which no copy remains beyond what is described in the following paragraph.
One important carve-out, required by law and not by our convenience: we retain records of transactions concluded through vvault - orders, invoices and issued licence documents - for the retention period imposed by Belgian accounting and tax law, currently seven (7) years for accounting records and ten (10) years for VAT records. This retention rests on Article 6(1)(c) GDPR and is expressly preserved by Article 17(3)(b). It is limited to what those obligations require, the records are not used for any other purpose, and personal identifiers are reduced to what the obligation itself needs. Licence documents are additionally retained so that a buyer who paid for rights can still prove them after a seller leaves the platform.
12. Audits and Information
We make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you.
In the first instance we will answer reasonable written questions and provide the documentation we hold, including our security description and our sub-processors' certifications and audit reports where they make them available to us. This satisfies most audit requests without an on-site visit.
Where that is genuinely insufficient, you may conduct an audit on not less than thirty (30) days' written notice, no more than once per twelve-month period except following a personal data breach affecting your data, during normal business hours, subject to confidentiality, and conducted so as not to disrupt the service or affect other customers' data. You bear the cost of the audit unless it reveals a material breach of this DPA by us.
13. Liability and Order of Precedence
Nothing in this DPA limits or excludes either party's liability towards a data subject under Article 82 GDPR, or the powers of a supervisory authority.
In the event of a conflict between this DPA and the Terms of Use, this DPA prevails in respect of the processing of personal data covered by Section 1. In the event of a conflict between this DPA and the Standard Contractual Clauses where they apply, the Standard Contractual Clauses prevail.
Each party is responsible for its own compliance with the GDPR in respect of the processing it determines. You warrant that you have a valid legal basis for the personal data you upload and for the communications you send through vvault, and that you have provided the information required by Articles 13 and 14 to the individuals concerned. We have no visibility over how you collected a contact, and cannot cure a defect in that collection.
14. Changes and Contact
We may update this DPA to reflect changes in the service or in applicable law. For material changes we give at least thirty (30) days' notice by email or in-app before they take effect, and we update the date at the top of this page.
For any question relating to this DPA, to exercise a right under it, or to notify us of a personal data breach on your side that affects data held in vvault, contact privacy@vvault.app.