Legal
Data Processing Agreement
Last updated: November 2025
This Data Processing Agreement ("DPA") supplements the Vault47 Terms of Service (the "Agreement") between Vault47 ("Vault47", "we", "us") and the business customer that accepts the Terms ("Customer", "you"). This DPA applies only where and to the extent Applicable Law requires a written data-processing agreement. It becomes effective when you begin using the Service and continues while we process Customer Data on your behalf.
By using the Service you accept this DPA in the form published here. Vault47 may update this DPA from time to time to reflect changes in the Service, subprocessors, security practices, or Applicable Law; the version in effect is the version posted on this page. If you require a countersigned copy for your records, email legal@vault47.cloud, countersignature is provided as a courtesy and does not change the terms.
1. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given under Applicable Law. "Applicable Law" means the data-protection laws that mandatorily apply to Vault47's processing of Customer Personal Data under this DPA. "Customer Data" means data that you or your authorized users upload to, generate in, or transmit through the Service. "Customer Personal Data" means the subset of Customer Data that constitutes Personal Data for which you are Controller. "Aggregated Data" is defined in Section 8.
2. Roles
You are the sole Controller of Customer Personal Data and are exclusively responsible for (a) the lawful basis for collecting, uploading, and processing it, (b) providing all required notices to Data Subjects, (c) obtaining and maintaining all required consents, and (d) the accuracy, quality, and legality of Customer Personal Data. Vault47 acts as Processor solely to the extent it processes Customer Personal Data on your behalf. Vault47 acts as an independent Controller for account, billing, security, telemetry, product-improvement, fraud-prevention, and compliance data (together, "Service Operations Data"), and its processing of Service Operations Data is governed by the Privacy Policy, not by this DPA.
3. Instructions & scope of processing
The Agreement, this DPA, the configuration you choose in the Service, and any feature you enable together constitute your complete and final documented instructions to Vault47. Vault47 will process Customer Personal Data to (a) provide, operate, maintain, secure, monitor, back up, restore, migrate, and support the Service; (b) prevent, detect, and investigate fraud, abuse, security incidents, and policy violations; (c) develop, test, and improve the Service, including AI features, as further described in Section 8; (d) comply with Applicable Law, lawful requests from public authorities, and its own legal, tax, audit, and accounting obligations; and (e) enforce the Agreement. Any instruction outside the ordinary functionality of the Service is subject to Vault47's written acceptance and may incur additional fees. Vault47 is not obligated to assess whether an instruction violates Applicable Law but may refuse or suspend processing where, in its reasonable judgment, an instruction is unlawful, unsafe, or technically infeasible.
4. Customer obligations & warranties
You represent and warrant that: (a) you have all rights, consents, and lawful bases required to upload Customer Personal Data to the Service and to have Vault47 and its subprocessors process it as described in the Agreement, this DPA, the Privacy Policy, and the Subprocessors page; (b) you will not upload special-category or highly sensitive data, including government identifiers, full payment card numbers, biometric identifiers, precise geolocation, protected health information, or data of children under 13, and you accept sole responsibility for any such data you nevertheless upload; (c) your instructions to Vault47 comply with Applicable Law; (d) you will keep credentials confidential, enable available security controls (including multi-factor authentication where offered), configure roles and permissions appropriately, promptly deprovision former users, and monitor your own account activity; and (e) you will respond to Data Subject requests and regulator inquiries directed to you. Your failure to meet any obligation in this Section is a Customer breach for which Vault47 has no responsibility or liability.
5. Confidentiality & personnel
Vault47 will ensure that personnel authorized to process Customer Personal Data are bound by written or statutory confidentiality obligations and receive appropriate training on their responsibilities.
6. Security
Vault47 will maintain a written information-security program that includes technical and organizational measures commercially reasonable for a SaaS provider of similar size and function ("Security Measures"), currently including encryption in transit, encryption of data at rest for the primary database and object storage, role-based and row-level access controls, network segmentation, logging, vulnerability management, backup and restore capability, and personnel access reviews. Vault47 may modify the Security Measures at any time provided the overall level of security is not materially reduced. You are responsible for your own security controls, including credential hygiene, endpoint security, network security, third-party integrations you enable, and lawful use of any exports or downloads. Vault47 does not warrant that the Service will be uninterrupted, error-free, or free from unauthorized access, and you acknowledge that no security program can prevent every incident.
7. Personal Data Breach
If Vault47 becomes aware of a confirmed Personal Data Breach affecting Customer Personal Data, Vault47 will notify you without undue delay after confirmation and in any event within the time frame required by Applicable Law, and will provide the information reasonably available to it to help you meet your notification obligations. Vault47's notification is not, and will not be construed as, an acknowledgment of fault, liability, or wrongdoing. You are solely responsible for notifying Data Subjects, regulators, and other third parties and for any related costs (including forensic, credit-monitoring, notification, call-center, remediation, PR, and legal costs), except to the extent Applicable Law non-waivably allocates those costs to Vault47. Vault47 has no obligation to notify Data Subjects, regulators, or the public on your behalf, and you may not do so in Vault47's name without Vault47's prior written consent. Incidents that do not compromise the confidentiality, integrity, or availability of Customer Personal Data (for example, unsuccessful log-in attempts, port scans, or pings) are not Personal Data Breaches and do not trigger notice obligations.
8. AI features, service improvement & Aggregated Data
You acknowledge and agree that Vault47's AI features may transmit Customer Data (including Customer Personal Data you choose to submit) to the AI subprocessors listed at /subprocessors to generate outputs, and that, as described in the Terms and Privacy Policy, content you submit to AI features may be used by Vault47 and its AI providers to train, evaluate, fine-tune, and improve models and to develop new features. You grant Vault47 a perpetual, irrevocable, worldwide, royalty-free right to create, use, disclose, and retain de-identified, anonymized, and aggregated data derived from Customer Data ("Aggregated Data") for any lawful purpose, including benchmarking, analytics, model training, security research, and productization. Aggregated Data is not Customer Personal Data and is not subject to deletion, return, or Data Subject rights under this DPA. You are solely responsible for not submitting content to AI features that you do not have the right to submit for these purposes.
9. Subprocessors
You provide general written authorization for Vault47 to engage the subprocessors listed at /subprocessors and any successors, replacements, and additions that Vault47 reasonably determines are necessary to operate, secure, support, or improve the Service. Vault47 will impose data-protection obligations on each subprocessor that are, in substance, no less protective than this DPA and will remain responsible for the performance of its subprocessors' obligations to the same extent Vault47 is responsible under this DPA. Vault47 will update the Subprocessors page before a new subprocessor begins processing Customer Personal Data. If you reasonably object in writing within 10 business days of the update based on a documented data-protection concern, Vault47 will, at its option, (a) accommodate the objection through commercially reasonable means, or (b) allow you to terminate the affected portion of the Service; termination under this Section is your sole and exclusive remedy for a subprocessor objection.
10. Data Subject requests
You are solely responsible for responding to Data Subject requests. Vault47 will make available in the Service self-service functionality (including export, deletion, correction, and account-closure tools) reasonably designed to help you meet your obligations. To the extent Applicable Law requires additional assistance beyond that functionality, Vault47 will provide it at your written request and, where the assistance is materially burdensome, at Vault47's then-current professional-services rates.
11. International transfers
You acknowledge and consent that Vault47 and its subprocessors are located in the United States and other jurisdictions, and that Customer Personal Data may be transferred to, stored in, and processed in those jurisdictions. Where a transfer mechanism is legally required, the parties agree that the mechanism selected by Vault47 (which may include the Standard Contractual Clauses, the UK Addendum, adequacy decisions, or other lawful mechanisms) is incorporated by reference. Vault47 may update the transfer mechanism to reflect changes in Applicable Law.
12. Audits
Vault47 will demonstrate compliance with this DPA by providing, on written request no more than once per twelve-month period, a summary of its then-current Security Measures, subprocessor list, and any third-party attestations, certifications, or penetration-test summaries reasonably available to it (collectively, "Audit Materials"). Audit Materials satisfy Vault47's audit obligations under Applicable Law. On-site audits, questionnaires, and direct inspections are not permitted except (a) where mandatorily required by Applicable Law and not adequately addressed by Audit Materials, or (b) following a confirmed material breach of this DPA by Vault47. Any permitted on-site audit must be scheduled at least 60 days in advance, conducted during business hours, limited to no more than one business day, subject to Vault47's confidentiality, safety, and security requirements, conducted by an independent auditor mutually approved by the parties, and paid for by you including Vault47's reasonable time-and-materials costs.
13. Return & deletion
You may export your Customer Data at any time using the Service's export tools. Following termination of the Agreement, Vault47 will, subject to your account being in good standing, make Customer Data available for export for 30 days and then delete or de-identify Customer Data within 90 days, except that Vault47 may retain: (a) Aggregated Data; (b) backups and logs until they expire in the ordinary course; (c) records required to comply with Applicable Law, resolve disputes, prevent fraud and abuse, or enforce the Agreement; and (d) content that has been anonymized or incorporated into trained AI models. You acknowledge that deletion from active systems does not immediately delete data from backups, and that this Section satisfies Vault47's deletion obligations under Applicable Law.
14. Limitation of liability
EACH PARTY'S LIABILITY ARISING OUT OF OR RELATED TO THIS DPA, WHETHER IN CONTRACT, TORT, STATUTE, OR ANY OTHER THEORY, IS SUBJECT TO, AND FORMS PART OF THE SAME AGGREGATE CAP AS, THE LIMITATIONS AND EXCLUSIONS OF LIABILITY SET OUT IN THE AGREEMENT. CLAIMS UNDER THIS DPA DO NOT CREATE A SEPARATE OR ADDITIONAL CAP. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST GOODWILL, OR THE COST OF PROCURING SUBSTITUTE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. VAULT47 IS NOT LIABLE FOR ANY LOSS, LIABILITY, COST, OR DAMAGE ARISING FROM: (I) YOUR OR YOUR USERS' ACTS OR OMISSIONS; (II) YOUR FAILURE TO USE AVAILABLE SECURITY FEATURES OR TO FOLLOW REASONABLE SECURITY PRACTICES; (III) COMPROMISE OF YOUR CREDENTIALS, DEVICES, NETWORKS, OR THIRD-PARTY INTEGRATIONS YOU CONNECT; (IV) DATA YOU UPLOADED IN VIOLATION OF SECTION 4; (V) INSTRUCTIONS YOU PROVIDED; OR (VI) EVENTS BEYOND VAULT47'S REASONABLE CONTROL.
15. Indemnification
You will defend, indemnify, and hold harmless Vault47 and its affiliates, officers, directors, employees, agents, and subprocessors from and against any third-party claims, regulatory investigations, penalties, damages, and costs (including reasonable attorneys' fees) arising out of or related to: (a) Customer Data or your instructions; (b) your breach of Section 4, Section 8, or any representation or warranty in this DPA; (c) your unauthorized processing of Personal Data; (d) your use of the Service in violation of the Agreement, this DPA, or Applicable Law; or (e) any Personal Data Breach caused or contributed to by your acts, omissions, credentials, devices, personnel, or third-party integrations. This Section survives termination.
16. Order of precedence; miscellaneous
In the event of a conflict between this DPA and the Agreement with respect to the processing of Customer Personal Data, this DPA controls; in all other respects the Agreement controls. Any Standard Contractual Clauses or similar transfer mechanism incorporated by reference control over this DPA only to the extent mandatorily required by Applicable Law. Nothing in this DPA (a) grants Data Subjects direct third-party-beneficiary rights against Vault47 beyond those required by Applicable Law, (b) requires Vault47 to violate Applicable Law or a lawful order, or (c) waives any right or defense available to Vault47 under Applicable Law. If any provision of this DPA is held unenforceable, it will be modified to the minimum extent necessary and the remainder will remain in effect.
17. Governing law & venue
This DPA is governed by, and disputes will be resolved in accordance with, the governing-law and venue provisions of the Agreement, except where Applicable Law non-waivably requires otherwise.
18. Contact
Vault47, legal@vault47.cloud
This DPA is a template provided for convenience. It is not legal advice. You should have your own counsel review it before relying on it.