Data Processing Agreement (DPA)

Last updated: 2026-05-31.

When you use Veylan to process personal data of EU residents, GDPR Article 28 requires a Data Processing Agreement between you (the controller) and Veylan (the processor). This page summarises the terms; the executable PDF is available on request.

How to get a counter-signed DPA

Email dpa@veylanai.com with your company's legal name and registered address. We'll send a counter-signed PDF within one business day.

Summary of terms

Roles

  • You are the data controller.
  • Veylan is the data processor.
  • Sub-processors are listed on the Trust Center (public list, kept current).

Scope

We process personal data only on your documented instructions — i.e., to provide the Veylan service as described in the Terms.

Security

We implement technical and organisational measures appropriate to the risk:

  • Encryption at rest (AES-256) and in transit (TLS 1.3).
  • Access controls with MFA for all Veylan staff.
  • Annual penetration testing.
  • Backup with documented RPO/RTO targets.
  • Documented incident response plan.

Full detail on the Security page.

Sub-processors

Current sub-processors:

  • Supabase (Frankfurt) — managed Postgres + auth.
  • Vercel — web hosting (EU edge).
  • Resend — transactional email (EU region).

Standard Contractual Clauses are in place where applicable. We'll notify you at least 30 days before adding a new sub-processor.

Data subject requests

If a data subject contacts us directly, we'll forward the request to you within five business days. We help you fulfil DSRs through the product's built-in DSR module.

Data breaches

We notify you of any personal-data breach affecting your data within 72 hours of awareness.

International transfers

Primary data storage is in the EU. Where any transfer outside the EEA occurs, SCCs (2021/914) plus a Transfer Impact Assessment are in place.

Termination

On termination, we delete or return your personal data within 30 days of your request.