Legal

Data Processing Agreement

Last updated: June 23, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between Vektor HQ, an enkeltmandsvirksomhed registered in Denmark, CVR 46519779, Sandkaj 17, 2150 Nordhavn, Denmark ("Processor", "Vektor"), and the Customer identified in the Agreement ("Controller"). It governs our processing of personal data on your behalf when providing the Service. Undefined terms have their GDPR meaning.

1. Roles

You (Controller) decide the purposes and means of processing the personal data you submit ("Customer Data"). Vektor (Processor) processes Customer Data only on your documented instructions, which include the Agreement and your use of the Service.

2. What we process (Annex I)

3. Our obligations

We will: (a) process Customer Data only on your documented instructions; (b) keep our staff who access it bound by confidentiality; (c) apply appropriate technical and organisational security (Annex II / §7); (d) follow the sub-processor terms in §5; (e) help you respond to data-subject requests and meet your Art. 32–36 duties, taking the nature of processing into account; (f) delete or return Customer Data at the end of services (§9); and (g) make available the information needed to show compliance (§8). We may create aggregated and de-identified data (which can't identify any person or organisation) to operate and improve the Service; this is consistent with these instructions.

4. Your obligations, consents and indemnity

Vektor does not record calls itself; you upload transcripts, recordings and notes you already hold. You warrant that: (a) you have a lawful basis to provide the Customer Data and to instruct this processing; and (b) you have obtained all notices and consents required to record those calls and to upload the transcripts, recordings and notes you submit, from the people involved. You are solely responsible for how any recording was made and for the legality of the content you upload. You will indemnify and hold Vektor harmless against any claim, loss, damage or fine arising from missing consents or from your processing instructions being unlawful. This clause operates together with, and restates as a processing instruction, your responsibilities in ToS §8. (This mirrors how comparable transcript products allocate this risk.)

5. Sub-processors

You give general authorisation for Vektor to use the sub-processors in the Sub-processor List. We'll give 30 days' notice of any addition or replacement (you can subscribe to changes on that page) and you may object on reasonable data-protection grounds; we'll work in good faith to address it. We bind every sub-processor to data-protection obligations equivalent to this DPA and remain liable for them.

Banking/bookkeeping note. Our bank (Lunar) and accounting software (Dinero) process Vektor's own financial records and are not Customer-Data sub-processors. The one exception: when we issue you a manual invoice, your billing contact details are stored in Dinero for Danish bookkeeping compliance (5-yr retention). There we act as controller of that contact data under a legal obligation, not as your processor.

6. International transfers

We process Customer Data in the EEA where possible. Where a transfer outside the EEA happens (mainly to our AI sub-processor Anthropic) we put an appropriate Chapter V GDPR safeguard in place, namely the EU Standard Contractual Clauses, incorporated by reference.

7. Security (Annex II)

We apply measures appropriate to the risk, including: encryption of data in transit and at rest; access controls and least-privilege; EU-region hosting (Render, Supabase); logging and monitoring; secure development practices; and regular review.

8. Showing compliance and audits

We'll give you the information reasonably needed to show our compliance (including a security summary, a completed security questionnaire, and any certifications we hold) and that satisfies our audit obligation. If you still need an on-site or third-party audit, it may take place once per 12 months (and after a personal data breach), on at least 30 days' written notice, by an auditor who is under NDA and is not a Vektor competitor, at your cost, without access to our network or other customers' data, and you'll share the report with us on request.

9. Deletion and return

On termination, we will, at your choice, delete or return Customer Data and delete remaining copies within 30 days, except where the law requires retention (e.g. Danish bookkeeping records), in which case we isolate and protect that data from further processing.

10. Data-subject requests

We'll promptly tell you about any data-subject request we receive about Customer Data and won't respond directly except on your instruction or as legally required, and we'll help you respond.

11. Personal data breach

We'll notify you without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting your Customer Data, with the information you need to meet your own obligations.

12. Liability

Liability under this DPA is subject to the limitation of liability in the Agreement (a single, shared cap, not a separate one).

13. Term and governing law

This DPA lasts for the Agreement's duration, is governed by Danish law, and prevails over conflicting Agreement terms about processing Customer Data.

Annexes