Data Processing Agreement (DPA)
Last updated: 30 September 2026
This Data Processing Agreement forms Annex 1 to Vibee's Terms of Service and governs the processing of personal data for which the Customer is controller and Daniel Rataj, Company ID (IČO) 71818871, registered at U měšťanského pivovaru 11, 170 00 Prague 7, Czech Republic ("Operator") is processor, within the meaning of Art. 28 GDPR. By creating an account or buying an app extension the Customer accepts this DPA together with the Terms of Service. Terms not defined here have the meaning given in the Terms of Service.
1. Subject-matter and nature of processing
The Operator stores, displays and otherwise processes content (database rows, uploaded files, app users) that the Customer or its connected AI assistant enters into the Service, for the Customer. Processing is automated by the Service's own means (database, file storage, web and MCP/API server) for as long as the account or the given app exists. For the Customer the Operator also counts visits to the public pages of its apps: it uses a visitor's IP address and browser identification only at the moment of the visit to compute a fingerprint with a random value that changes daily and is then discarded, stores none of it, and keeps only anonymous daily totals (views, an estimated number of visitors, pages, visit sources) for 400 days.
2. Purpose of processing
Solely the provision of the Service to the Customer under the Terms of Service — storing, displaying and processing the content the Customer creates, and nothing else.
3. Duration of processing
For as long as the Customer's account, or the given app, exists. After deletion, processing is governed by Section 9 of the Terms of Service (disaster-recovery backups retained up to 30 days, then permanently removed).
4. Categories of data subjects and personal data
Data subjects are people whose data the Customer enters into the Service (typically its employees, customers or business partners) and users of the Customer's apps, and for visit statistics the visitors of its apps' public pages (IP address and browser identification, only while the visit is processed). The categories of data correspond to the content the Customer enters into its tables and forms. Special categories of personal data under Art. 9 GDPR (e.g. racial or ethnic origin, political opinions, religious belief, trade union membership, genetic or biometric data, health data, or data on sex life or sexual orientation) are not permitted in the Service — see Section 4 of the Terms of Service. If the Operator finds such data in the Service, it may remove the content or suspend the app under Section 14 of the Terms of Service.
5. Customer's instructions
The Operator processes personal data only on the Customer's documented instructions, meaning operations carried out by the Customer or its AI assistant through the dashboard, the Service's MCP tools or API, and otherwise under this DPA and the Terms of Service. If the Operator considers an instruction to infringe the GDPR or other data-protection law, it will inform the Customer without delay.
6. Confidentiality
The Operator ensures that persons authorised to process personal data (itself and any sub-processors) are bound by confidentiality, whether contractually or by statute.
7. Security
The Operator implements technical and organisational measures appropriate to the risk under Art. 32 GDPR, in particular: encryption in transit (TLS), hashing of passwords and access tokens (argon2id), logical separation of each customer's data via its own database schema, and parameterised database queries to prevent injection. See Section 6 of the Privacy Policy for details.
8. Sub-processors
The Customer gives the Operator general authorisation to engage the sub-processors listed in Section 3 of the Privacy Policy (currently Hetzner Online GmbH – servers and storage; Stripe Payments Europe, Ltd. – payments; Let's Encrypt – TLS certificates; and the AI assistant provider the Customer connects – OpenAI or Anthropic). The Operator imposes the same data-protection obligations on these sub-processors as it bears under this DPA. The Operator will inform the Customer of an intended change of sub-processor at least 15 days in advance via the dashboard or e-mail; the Customer may raise a reasoned objection within the same period, failing which it is deemed to consent to the change.
9. Assistance
The Operator provides the Customer reasonable assistance in responding to data subject requests (access, rectification, erasure, portability) through the dashboard and MCP tool features described in Section 5 of the Privacy Policy, and with data protection impact assessments (DPIAs) and consultations with the supervisory authority where reasonably required.
10. Security incidents
If the Operator becomes aware of a breach of security of personal data processed for the Customer, it will notify the Customer without undue delay and no later than 48 hours after becoming aware, with the available information on the nature of the incident, the categories and approximate number of data subjects and records affected, and measures taken or proposed.
11. Audit
On the Customer's request, and no more than once a year, the Operator will provide information and documentation reasonably demonstrating compliance with this DPA. A physical inspection or audit by the Customer or an auditor it mandates will be accommodated by prior agreement on timing and scope and at the Customer's expense, unless requested by a supervisory authority.
12. Transfers to third countries
The infrastructure on which the Operator processes the Customer's content is located in the European Union (Germany, Hetzner Online GmbH) — see Data Portability and Infrastructure. Should personal data exceptionally be transferred to a sub-processor outside the EU/EEA, the Operator will ensure appropriate safeguards under Art. 46 GDPR (in particular standard contractual clauses).
13. Termination of processing
Once the Service ends for the Customer (by deleting the account or app, or by the Operator discontinuing the Service under Section 14 of the Terms), the Operator will, at the Customer's choice, delete the personal data processed or return it in a machine-readable format, unless retention is required by EU or Member State law. Export and deletion timelines follow Section 9 of the Terms of Service.
14. Relationship to the Terms of Service
This DPA is an integral annex to the Terms of Service. On matters of processing the Customer's personal data as controller, this DPA prevails over the Terms of Service; in all other respects the Terms of Service apply. Questions about this DPA: info@vibee.one.
Vibee