VECTORIA · Legal centre
Data processing agreement
For professional customers who submit third-party personal data to the service. This agreement forms part of their subscription terms.
Edition dated 25 September 20262026-09-25-subscriptions-dpa-v1
Applies to new subscriptions accepting this version.
1. Parties and priority
The Controller is the professional or entity that subscribes to or uses Vectoria and determines the purposes and means of processing Customer Data. The Processor is Juan Francisco Rodríguez del Rosario, Spanish tax identification number 78522240X, owner and operator of Vectoria, identified in the Legal notice. This Addendum forms part of the Terms of Use when the customer processes Customer Data through the Service. For that processing, this Addendum prevails over conflicting terms.
2. Definitions and scope
Customer Data means personal data that the customer or its authorised users add to projects, prompts, attachments, support or remote features and that Vectoria processes on the customer's behalf. It excludes data for which Vectoria is an independent controller—account, licence, security, technical billing, own support or legal compliance—as described in the Privacy Notice. Paddle acts as an independent controller for checkout and is not a Sub-processor under this Addendum.
The subject matter is provision of Vectoria software, account, necessary hosting, support and remote features. Duration is the contractual relationship plus the period strictly required for return, deletion, security or legal compliance. Processing may include receipt, transmission, consultation, organisation, calculation, inference, support and deletion.
The Service includes Civil and, when included in the plan, Cost Pro and Viewer Pro. Files kept exclusively on the customer’s device are not delivered to the processor merely by opening them. Remote processing starts with the corresponding authorised function or transmission.
3. Purpose, data and data subjects
The purpose is to carry out documented customer instructions: process technical projects, interpret requests, execute tools, produce results, operate the account and provide support. Data may include names, professional and contact details, project identifiers, properties or parcels linked to people, technical content, communications and other ordinary personal data lawfully supplied by the customer. Data subjects may include employees, contractors, customers, property owners, suppliers, engineers, representatives and project contacts.
4. Data prohibited in the standard service
The standard service is not authorised for GDPR Article 9 special-category data, criminal-conviction or offence data, biometric data used for unique identification, medical or health information, children's data, full payment-card numbers, authentication credentials or secrets. The customer must not enter them in prompts, attachments, projects, voice or support. Any exception requires a prior written agreement with Vectoria, a specific risk assessment and, where applicable, prior notice to and agreement with Sub-processors. Standard plans do not include this exception.
5. Instructions and customer obligations
Documented instructions are this Addendum, the Terms, selected configuration and lawful actions by authorised users. The customer warrants that it has a lawful basis, provides required notices, limits access and data to what is necessary, maintains accuracy and holds required permissions. Vectoria will inform the customer if it considers an instruction unlawful and may suspend it while the matter is resolved.
6. Vectoria obligations
- Process Customer Data only on documented instructions unless required by law, and give advance notice where legally permitted.
- Ensure confidentiality commitments and restricted access for authorised personnel.
- Apply technical and organisational measures appropriate to risk and reasonably assist with GDPR Articles 32 to 36.
- Taking account of the nature of processing, assist with data-subject requests and not answer them for the customer except on instruction or as required by law.
- Notify the customer without undue delay of a personal-data breach affecting Customer Data and provide available information for assessment.
- Make sufficient compliance information available and permit proportionate audits under section 11.
7. Security measures
Measures include TLS in transit, credentials and secrets outside source code, role-based least-privilege access, authentication and licensing, temporary signed URLs, environment separation, log minimisation and redaction, usage events without prompts or files, limited retention, service-appropriate backup and recovery, dependency review and incident-response procedures. Vectoria may improve or replace measures without materially reducing protection.
8. Sub-processors
The customer grants general authorisation for the following Sub-processors to the extent that they process Customer Data:
- Supabase: authentication, database and account services.
- Google Cloud: Cloud Run, storage, downloads, minimised logs, Google Cloud Speech when voice is enabled and Vertex AI when image generation is enabled and confirmed by the user.
- TensorX Limited, Ireland: agent inference in Dublin and Helsinki, with ephemeral processing, no prompt or completion retention and no training.
- Cloudflare: network, DNS, security, web delivery and access protection.
- Resend and Brevo: transactional email and access codes according to the product; and Gmail/Google Workspace: support when the customer chooses to send content through those channels.
Vectoria will maintain a current list and give at least fourteen calendar days' notice of a material addition or replacement, except for a security emergency or legal requirement. The customer may object on reasonable data-protection grounds; the parties will seek an alternative and, if none exists, may limit or terminate the affected feature. Vectoria will impose equivalent obligations and remains responsible for Sub-processor compliance under the GDPR.
MCP connections and external agent accounts that customers independently contract and authorise do not thereby become Vectoria subprocessors. Vectoria remains responsible for its own processing while facilitating the connection. Customers must assess their chosen provider’s terms, minimise data and have necessary agreements before sending third-party information.
9. Location and transfers
TensorX inference runs in Dublin and Helsinki and is not disclosed to the model developer. Where another Sub-processor transfers data outside the EEA without an adequacy decision, EU Standard Contractual Clauses and applicable supplementary safeguards will be used. Request the current list, region and mechanism at [email protected].
10. Return, deletion and retention
At the customer's choice and where supported, Vectoria will enable export or deletion during the relationship. On termination, it will delete or return Customer Data and copies within a reasonable period, except where law requires retention, backups remain within protected cycles, or information is needed for security and legal claims. TensorX does not retain prompts or completions. Specific log and controller-data periods appear in the Privacy Notice.
Contract, payment and reconciliation records that Vectoria must retain as controller are kept separately and limited to that purpose. Cancelling a subscription does not authorise deletion of files on the customer’s device.
11. Evidence and audit
On reasonable request, Vectoria will provide information about safeguards, Sub-processors and compliance. The customer may conduct one audit per year with thirty days' notice, during business hours, limited to its Customer Data and without compromising secrets, security or third-party data. Questionnaires, certifications and independent reports will be preferred. Extraordinary on-site audit costs are borne by the customer unless a material Vectoria breach is identified.
These organisational limits do not prevent additional audits justified by an incident, reasonable indications of non-compliance or a competent authority, nor limit GDPR Article 28 obligations.
12. Liability, term and contact
Contractual liability is governed by the Terms without limiting non-waivable data-subject rights or liability that the GDPR does not permit the parties to exclude. This Addendum remains effective while Vectoria processes Customer Data. Confidentiality, deletion and cooperation duties intended to survive continue after termination.
Privacy contact and processing instructions: [email protected]. Security incidents: [email protected]. The Spanish version controls if a translation inconsistency arises.