Data Processing Agreement
These Article 28 terms govern personal data a customer puts into Veillo. They include the processing description, security measures, and current sub-processor register.
Effective and last updated 13 July 2026. This version describes Veillo’s current service and production requirements. Product guidance is not legal advice.
1. Parties and incorporation
Veillo is an Arbos Techne product, operated by Arbos Folk, a sole proprietorship registered in Denmark. You can reach us at hello@veillo.eu.
This Data Processing Agreement, or DPA, is between Arbos Folk as the processor and the customer identified in the applicable order, subscription, or account as the controller. It forms part of the Terms of Service when the customer accepts those terms or signs an order that incorporates this DPA. If an executed order contains a specific data-protection term that conflicts with this public DPA, the executed term controls.
2. Definitions and order of priority
“Customer Data” means personal data processed in the service on the customer’s behalf. “Data Protection Law” means the GDPR, applicable national GDPR laws, and other binding privacy law applicable to the processing. The terms controller, processor, data subject, personal data, processing, personal data breach, and supervisory authority have the meanings given by the GDPR.
For Customer Data, the order of priority is: an executed data-processing addendum, this DPA, the applicable order, then the Terms of Service.
3. Roles and documented instructions
The customer is the controller and Veillo is the processor for Customer Data. The customer instructs Veillo to process Customer Data to provide, secure, support, and maintain the service; carry out actions initiated by authorised users; and comply with the agreement. The agreement and ordinary product configuration are the customer’s documented instructions.
Veillo processes Customer Data only on those instructions unless EU or Member State law requires otherwise. Where legally permitted, Veillo informs the customer of that requirement before processing. If Veillo believes an instruction infringes Data Protection Law, it informs the customer and may pause the affected processing while the parties address it.
4. Customer responsibilities
The customer is responsible for the lawfulness, accuracy, and quality of Customer Data; required notices and legal bases; user access and instructions; responding to data subjects; and deciding whether the service is appropriate for the customer’s processing. The customer must avoid placing special-category, criminal-offence, payment-card, or highly sensitive identity data in free-text fields unless it has assessed the need, legal basis, risks, and safeguards.
5. Confidentiality and personnel
Veillo limits Customer Data access to people who need it for their role. Those people are bound by confidentiality obligations and receive security and data-protection guidance appropriate to their access. Access is removed or changed when duties change.
6. Security
Veillo implements and maintains technical and organisational measures appropriate to the risk, taking account of the service’s nature, implementation costs, and the state of the art. The current measures are in Annex 2. Veillo may update them as technology and risk change, provided the overall protection is not materially reduced.
7. Sub-processors
The customer gives general written authorisation for the sub-processors in Annex 3. Veillo remains responsible for each sub-processor’s performance of its data-protection obligations to the extent required by the GDPR, and puts written terms in place that provide materially equivalent protection for Customer Data.
Veillo will publish a new sub-processor before that provider begins processing Customer Data and, for active paid customers, provide notice through the service or email where the change is material. A customer may object on reasonable data-protection grounds within 14 days. The parties will try to resolve the concern. If no reasonable alternative is available, either party may terminate only the affected service without penalty for the unused prepaid period.
8. International transfers
Where Customer Data is transferred from the EEA to a country without an adequacy decision, the parties incorporate the 2021 EU Standard Contractual Clauses. Module Two applies to controller-to-processor transfers and Module Three applies where the customer acts as processor. The customer is data exporter, Veillo is data importer, the optional docking clause applies, the supervisory authority follows Clause 13, and Danish law and Danish courts govern Clauses 17 and 18. Annexes 1 to 3 of this DPA complete the relevant SCC annexes.
Where a listed provider validly relies on the EU-US Data Privacy Framework for the relevant data, that adequacy mechanism may apply. Veillo uses another valid transfer mechanism if that framework does not cover a transfer.
9. Data-subject requests
Taking account of the nature of processing, Veillo provides product functions and reasonable assistance so the customer can answer requests under Chapter III GDPR. If a data subject contacts Veillo about Customer Data, Veillo forwards the request to the customer and does not respond on the customer’s behalf unless instructed or legally required.
10. Personal data breaches
Veillo notifies the customer without undue delay after becoming aware of a personal data breach affecting Customer Data. As information becomes available, the notice describes the nature of the breach, likely consequences, affected data and people, contact point, and measures taken or proposed. Notification is not an admission of fault. The customer remains responsible for notifications it must make as controller.
11. DPIAs and regulatory consultation
Taking account of the processing and information available to Veillo, Veillo provides reasonable assistance with security obligations, data-protection impact assessments, and prior consultation under Articles 32 to 36 GDPR. Work beyond standard documentation and product functions may be charged at agreed rates unless the need results from Veillo’s breach.
12. Information and audits
Veillo makes information reasonably necessary to demonstrate compliance with Article 28 available to the customer. No more than once per year, unless a breach or authority requires more, the customer may request an audit by an independent qualified auditor under confidentiality. The audit must use existing reports first, take place on reasonable notice, avoid access to other customers’ data, and avoid unreasonable disruption. The customer bears its costs unless the audit identifies a material Veillo breach.
13. Return and deletion
During the subscription, the customer can use available exports. At the end of the service and on the customer’s documented choice, Veillo deletes or returns Customer Data unless law requires storage. Deletion covers live production records and then provider backups as those backups expire under the production retention schedule. Veillo may retain billing, security, and contract evidence in its controller capacity where law or legitimate legal claims require it.
14. Liability and term
This DPA starts with the agreement and continues while Veillo processes Customer Data. Liability under this DPA follows the liability provisions in the Terms of Service, without limiting rights or liabilities that cannot lawfully be limited.
Annex 1: processing details
| Subject matter | Provision, security, maintenance, and support of the Veillo AI-governance service. |
|---|---|
| Duration | The subscription term plus the agreed deletion and backup-expiry period. |
| Nature and purpose | Collection, storage, organisation, retrieval, classification, document generation, review, export, integration, support, and deletion at the customer’s instruction. |
| Data subjects | Customer users, staff, contractors, applicants, clients, vendors, contacts, and other people the customer chooses to reference in its governance records. |
| Personal data | Names, work contact data, roles, identifiers, employment or business context, free-text descriptions, audit records, and other personal data entered by authorised users. |
| Sensitive data | Not required for ordinary use. It may appear only if the customer chooses to enter it, subject to section 4. |
| Frequency | Continuous or on demand during use of the service. |
| Controller rights | As provided by the GDPR and the agreement. |
Annex 2: technical and organisational measures
- Access control: authenticated sessions, organisation membership, product roles, separate staff qualification, least-privilege expectations, and access removal procedures.
- Transport and credentials: HTTPS in production, password hashing through Better Auth, HTTP-only Secure session cookies, environment-managed secrets, and encrypted Google connector refresh tokens.
- Application security: server-side authorisation, input validation, OAuth state checks, security response headers, blocked indexing of private routes, and dependency patching through the maintained application stack.
- Tenant separation: organisation-scoped application queries and role checks. The current database does not claim PostgreSQL row-level security.
- Logging and traceability: material actions produce audit rows; restricted staff access is separately recorded. The current audit table is not claimed to be cryptographically immutable.
- Availability: EU-region production compute, managed database backup and recovery controls as configured in the production provider, and documented restoration checks before launch.
- Vendor management: a named register, data-processing terms, location and transfer review, conditional activation, and change notification.
- Incident handling: reporting channel, triage, containment, investigation, documentation, and customer notification under section 10.
- Data minimisation: structured workspace fields, no card storage, optional integrations, human review of AI suggestions, and Basic Consent Mode for Analytics.
- Review: production configuration, access, backups, vendors, and this annex are reviewed after material architecture changes and at least annually.
Annex 3: authorised sub-processors
Only the providers whose activation condition is met process data for the matching feature.
| Provider | Purpose | Location and condition |
|---|---|---|
| Vercel, Inc. | Application hosting, deployment, delivery, security, and logs | Primary server-function region is Frankfurt, Germany (fra1). Vercel also operates global delivery, security, support, and control-plane services. Production website and application. |
| Neon, Inc. | Managed PostgreSQL database | Veillo's production standard is an EU database region in Frankfurt. The selected Neon project region must be checked before launch and after any database migration. Production DATABASE_URL uses Neon. |
| Stripe Payments Europe, Limited | Subscription checkout, billing, payment, invoicing, and tax support | European Economic Area and other locations described in Stripe's privacy documentation A customer buys or manages a paid subscription. |
| SMTP2GO Pty Ltd | Transactional email delivery | Locations described in SMTP2GO's privacy and data processing terms SMTP2GO is the configured email provider. |
| Resend, Inc. | Transactional email delivery | United States and other locations described in Resend's terms Resend is configured and SMTP2GO is not configured. |
| Amazon Web Services EMEA SARL | Claude model access through Amazon Bedrock | EU Bedrock region, configured as eu-central-1 by default, plus AWS operational support locations A Bedrock model is configured and the user invokes an AI-assisted feature, or the article job runs. |
| Functional Software, Inc. d/b/a Sentry | Application error monitoring | Sentry's EU data storage location in Frankfurt, Germany. Veillo's code refuses any Sentry key that is not on the EU ingest host, so error data cannot be sent to Sentry's US region. Error monitoring is enabled (NEXT_PUBLIC_SENTRY_DSN is configured). |
| Google Ireland Limited | Google Analytics 4; optional Google sign-in and Google Workspace discovery | Google operates globally. International transfers may occur under Google's applicable transfer safeguards. Analytics consent is granted or a user chooses a Google integration. |
Contact and signed copies
Questions, procurement requests, or a countersigned copy can be sent to hello@veillo.eu.