Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between Vektor HQ, an enkeltmandsvirksomhed registered in Denmark, CVR 46519779, Sandkaj 17, 2150 Nordhavn, Denmark ("Processor", "Vektor"), and the Customer identified in the Agreement ("Controller"). It governs our processing of personal data on your behalf when providing the Service. Undefined terms have their GDPR meaning.
1. Roles
You (Controller) decide the purposes and means of processing the personal data you submit ("Customer Data"). Vektor (Processor) processes Customer Data only on your documented instructions, which include the Agreement and your use of the Service.
2. What we process (Annex I)
- Subject matter: providing the Vektor sales-intelligence Service.
- Duration: the term of the Agreement plus the deletion period in §9.
- Nature and purpose: generating sales briefs, research and coaching from your inputs using AI; and storing the call transcripts and meeting notes you upload or paste, plus an AI-extracted summary of them, as durable per-deal memory.
- Types of personal data: business contact details of your prospects/contacts; your users' account data; the contents of call transcripts and notes you submit (which may include personal data about call participants); and anything else you choose to input.
- Data subjects: your users, and your prospects/contacts, including people participating in or named in submitted transcripts and notes.
- No sensitive data. You agree not to submit special-category data (Art. 9 GDPR: health, racial/ethnic origin, political/religious beliefs, sexual orientation, biometric/genetic data, trade-union membership), data on criminal offences, government ID numbers, payment card numbers, or passwords. The Service isn't intended for it.
3. Our obligations
We will: (a) process Customer Data only on your documented instructions; (b) keep our staff who access it bound by confidentiality; (c) apply appropriate technical and organisational security (Annex II / §7); (d) follow the sub-processor terms in §5; (e) help you respond to data-subject requests and meet your Art. 32–36 duties, taking the nature of processing into account; (f) delete or return Customer Data at the end of services (§9); and (g) make available the information needed to show compliance (§8). We may create aggregated and de-identified data (which can't identify any person or organisation) to operate and improve the Service; this is consistent with these instructions.
4. Your obligations, consents and indemnity
Vektor does not record calls itself; you upload transcripts, recordings and notes you already hold. You warrant that: (a) you have a lawful basis to provide the Customer Data and to instruct this processing; and (b) you have obtained all notices and consents required to record those calls and to upload the transcripts, recordings and notes you submit, from the people involved. You are solely responsible for how any recording was made and for the legality of the content you upload. You will indemnify and hold Vektor harmless against any claim, loss, damage or fine arising from missing consents or from your processing instructions being unlawful. This clause operates together with, and restates as a processing instruction, your responsibilities in ToS §8. (This mirrors how comparable transcript products allocate this risk.)
5. Sub-processors
You give general authorisation for Vektor to use the sub-processors in the Sub-processor List. We'll give 30 days' notice of any addition or replacement (you can subscribe to changes on that page) and you may object on reasonable data-protection grounds; we'll work in good faith to address it. We bind every sub-processor to data-protection obligations equivalent to this DPA and remain liable for them.
Banking/bookkeeping note. Our bank (Lunar) and accounting software (Dinero) process Vektor's own financial records and are not Customer-Data sub-processors. The one exception: when we issue you a manual invoice, your billing contact details are stored in Dinero for Danish bookkeeping compliance (5-yr retention). There we act as controller of that contact data under a legal obligation, not as your processor.
6. International transfers
We process Customer Data in the EEA where possible. Where a transfer outside the EEA happens (mainly to our AI sub-processor Anthropic) we put an appropriate Chapter V GDPR safeguard in place, namely the EU Standard Contractual Clauses, incorporated by reference.
7. Security (Annex II)
We apply measures appropriate to the risk, including: encryption of data in transit and at rest; access controls and least-privilege; EU-region hosting (Render, Supabase); logging and monitoring; secure development practices; and regular review.
8. Showing compliance and audits
We'll give you the information reasonably needed to show our compliance (including a security summary, a completed security questionnaire, and any certifications we hold) and that satisfies our audit obligation. If you still need an on-site or third-party audit, it may take place once per 12 months (and after a personal data breach), on at least 30 days' written notice, by an auditor who is under NDA and is not a Vektor competitor, at your cost, without access to our network or other customers' data, and you'll share the report with us on request.
9. Deletion and return
On termination, we will, at your choice, delete or return Customer Data and delete remaining copies within 30 days, except where the law requires retention (e.g. Danish bookkeeping records), in which case we isolate and protect that data from further processing.
10. Data-subject requests
We'll promptly tell you about any data-subject request we receive about Customer Data and won't respond directly except on your instruction or as legally required, and we'll help you respond.
11. Personal data breach
We'll notify you without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting your Customer Data, with the information you need to meet your own obligations.
12. Liability
Liability under this DPA is subject to the limitation of liability in the Agreement (a single, shared cap, not a separate one).
13. Term and governing law
This DPA lasts for the Agreement's duration, is governed by Danish law, and prevails over conflicting Agreement terms about processing Customer Data.
Annexes
- Annex I, Details of processing: as in §2.
- Annex II, Security measures: as described in §7.
- Annex III, Sub-processors: the current Sub-processor List.