Data Processing Agreement (DPA)
Last updated: 2026-05-31.
When you use Veylan to process personal data of EU residents, GDPR Article 28 requires a Data Processing Agreement between you (the controller) and Veylan (the processor). This page summarises the terms; the executable PDF is available on request.
How to get a counter-signed DPA
Email dpa@veylanai.com with your company's legal name and registered address. We'll send a counter-signed PDF within one business day.
Summary of terms
Roles
- You are the data controller.
- Veylan is the data processor.
- Sub-processors are listed on the Trust Center (public list, kept current).
Scope
We process personal data only on your documented instructions — i.e., to provide the Veylan service as described in the Terms.
Security
We implement technical and organisational measures appropriate to the risk:
- Encryption at rest (AES-256) and in transit (TLS 1.3).
- Access controls with MFA for all Veylan staff.
- Annual penetration testing.
- Backup with documented RPO/RTO targets.
- Documented incident response plan.
Full detail on the Security page.
Sub-processors
Current sub-processors:
- Supabase (Frankfurt) — managed Postgres + auth.
- Vercel — web hosting (EU edge).
- Resend — transactional email (EU region).
Standard Contractual Clauses are in place where applicable. We'll notify you at least 30 days before adding a new sub-processor.
Data subject requests
If a data subject contacts us directly, we'll forward the request to you within five business days. We help you fulfil DSRs through the product's built-in DSR module.
Data breaches
We notify you of any personal-data breach affecting your data within 72 hours of awareness.
International transfers
Primary data storage is in the EU. Where any transfer outside the EEA occurs, SCCs (2021/914) plus a Transfer Impact Assessment are in place.
Termination
On termination, we delete or return your personal data within 30 days of your request.