Data Processing Addendum
Effective date: 24 August 2026 Last updated: 25 August 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or another agreement for VaultGuard Sync (Cloud) (the “Agreement”) between the Customer and dropie s. r. o., trading as VaultGuard (“VaultGuard”).
It applies when VaultGuard processes Personal Data for Customer in providing the managed Service. Customer is the Controller and VaultGuard is the Processor. If Customer is a Processor for another Controller, VaultGuard is Customer’s Subprocessor.
1. Definitions and order
“Applicable Data Protection Law” means the GDPR, UK GDPR, Swiss Federal Act on Data Protection, CCPA/CPRA to the extent it applies to processor/service-provider activity, and other data-protection law applicable to the processing.
“Customer Personal Data” means Personal Data submitted to or generated through the Service that VaultGuard processes for Customer. “Subprocessor” means another processor engaged by VaultGuard for Customer Personal Data. Other capitalised privacy terms have the meanings in Applicable Data Protection Law.
This DPA controls over the Agreement for its subject. The applicable Standard Contractual Clauses (“SCCs”) control over this DPA where they conflict.
2. Processing instructions
VaultGuard will:
- process Customer Personal Data only on Customer’s documented instructions, including the Agreement, this DPA, authorised use of the Service, configuration, and support requests, unless law requires other processing;
- tell Customer before legally required processing unless law prohibits notice;
- promptly inform Customer if an instruction appears to infringe Applicable Data Protection Law;
- ensure people authorised to process Customer Personal Data are bound by confidentiality;
- implement and maintain the measures in Annex II;
- provide reasonable assistance with data-subject requests, security, breach notification, impact assessments, and regulator consultation, taking into account the nature of processing and information available;
- make information reasonably necessary to demonstrate compliance available as described in section 8.
VaultGuard acts as an independent Controller for its own account, billing, security, legal, and consent records as described in the Privacy Policy.
3. Customer responsibilities
Customer is responsible for its instructions, Customer Data, notices and lawful basis, responding to its data subjects, and configuring users, permissions, shares, devices, retention, and integrations. Customer will not instruct VaultGuard to process data in violation of law or the Agreement.
The Service is not designed as a system of record for payment-card numbers, government classified data, or data governed by a specialised regime such as HIPAA unless a signed addendum expressly covers it. Customer should not upload special-category or similarly sensitive data without completing its own risk assessment and applying appropriate controls.
4. Confidentiality and government requests
VaultGuard will limit access to Customer Personal Data to authorised people and systems that need it for the Service, security, support, or legal compliance. Legal or support access is controlled by policy and access controls; the managed-service architecture does not make operator access technically impossible.
If VaultGuard receives a legally binding request for Customer Personal Data, it will, where permitted, notify Customer, assess the request, and disclose only data it reasonably determines is required.
5. Subprocessors
Customer gives general written authorisation for the providers on the Subprocessor List. VaultGuard will require a Subprocessor to protect Customer Personal Data through written terms appropriate to the processing and remains responsible for its Subprocessors as required by Applicable Data Protection Law.
VaultGuard will give at least 30 days’ notice by email, admin notice, or an update mechanism agreed in an order form before a new Subprocessor begins processing Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will try to resolve the objection. If no reasonable alternative is available, Customer may terminate the affected Service and receive any unused prepaid amount for it.
Optional advertising partners and user-selected AI providers are not Customer Personal Data Subprocessors in the circumstances described on the Subprocessor List.
6. International transfers
The primary managed workload is in AWS eu-central-1 (Frankfurt, Germany). If Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country without an applicable adequacy decision, the parties use the following safeguards:
EEA transfers
The parties incorporate the European Commission SCCs in Decision (EU) 2021/914:
- Module Two applies to Controller-to-Processor transfers; Module Three applies to Processor-to-Processor transfers.
- Clause 7 docking is not used.
- Clause 9 uses Option 2, general written authorisation, with the notice period in section 5.
- Clause 11’s optional independent dispute-resolution language is not used.
- For Clause 17, the law is Slovak law.
- For Clause 18, disputes are resolved by the courts of the Slovak Republic.
- Annexes I–III below complete the SCC annexes.
UK and Swiss transfers
For restricted UK transfers, the UK International Data Transfer Addendum to the EU SCCs is incorporated and populated by this DPA. For Swiss transfers, the SCCs apply with references adapted to the Swiss Federal Act on Data Protection, the Federal Data Protection and Information Commissioner, and Swiss data subjects as required.
If a different lawful transfer mechanism applies, it controls for that transfer. VaultGuard will provide reasonable information about relevant supplementary measures on request, subject to security and confidentiality limits.
7. Personal Data Breach
VaultGuard will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will include information reasonably available about the nature of the incident, affected data and people, likely consequences, mitigation, and a contact point. VaultGuard can provide information in phases and will take reasonable steps to contain and remediate the incident.
Notification is not an admission of fault. Customer is responsible for notifying its regulators and data subjects unless law assigns that duty to VaultGuard.
8. Information and audits
VaultGuard will provide this DPA, current security documentation, relevant third-party reports it is entitled to share, and reasonable written responses to demonstrate compliance.
If that information is insufficient for a specific legal requirement, Customer may conduct one further remote audit in a 12-month period, and more often after a relevant breach or regulator request. The parties will agree scope, timing, confidentiality, and safeguards for other customers. Customer pays its audit costs unless the audit identifies VaultGuard’s material breach. An on-site audit is available only where required by law and a remote review cannot reasonably satisfy the requirement.
No audit may expose another customer’s data, secrets, vulnerability details that would increase risk, or information VaultGuard is not permitted to disclose.
9. Data-subject requests
VaultGuard will, taking account of the processing, provide reasonable technical and organisational assistance for Customer to respond to rights requests. If a person contacts VaultGuard about Customer Personal Data, VaultGuard will direct the request to Customer unless law requires a response.
10. Return and deletion
During an active subscription, Customer can access and export data through available Service features. Customer should complete needed exports before termination; no post-termination self-service window is promised unless an order form provides one.
After termination or Customer’s valid written instruction, VaultGuard will delete or return Customer Personal Data unless law requires retention. Deletion follows the Service’s technical lifecycle. Service-visible records and current objects are removed or de-identified through the operational deletion process; noncurrent object versions, logs, and protected recovery copies can remain until configured lifecycle periods expire. Retained copies remain protected and are not used for ordinary service delivery.
VaultGuard can retain limited billing, fraud, dispute, security, or legal records as an independent Controller. On reasonable written request, VaultGuard will confirm completion of the applicable operational deletion process.
11. CCPA/CPRA service-provider terms
Where the CCPA/CPRA applies to Customer Personal Data, VaultGuard acts as a service provider or contractor. It will not sell or share that data, retain, use, or disclose it outside the business purposes in the Agreement, or combine it with personal information from another source, except as permitted by law. Customer may take reasonable steps to verify and stop unauthorised use.
12. Liability and term
Liability under this DPA is subject to the Agreement, except where Applicable Data Protection Law or the SCCs require otherwise. This DPA begins with the Agreement and continues while VaultGuard processes Customer Personal Data.
Annex I — Details of processing
Parties
Data exporter: the Customer identified in the Agreement, at its account or order-form contact details. Activities relevant to the transfer are its use of VaultGuard Sync (Cloud). Role: Controller or Processor as described above.
Data importer: dropie s. r. o., Gagarinova 18127/10A, 821 05 Bratislava – mestská časť Ružinov, Slovak Republic, support@vaultguard.cloud. Activities relevant to the transfer are operating and supporting the Service. Role: Processor.
Processing
Subject and purpose: provide hosted encrypted file-body storage and sync, authentication, organisation and vault administration, permissions, sharing, recovery, audit, security, transactional communications, and support.
Duration: the Agreement term plus the deletion and legal-retention periods described in section 10.
Frequency: continuous or as initiated by Customer and its users.
Data subjects: Customer personnel, contractors, students, members, guests, collaborators, and other authorised users or people described in Customer Data.
Personal Data:
- names, email addresses, organisation, role, membership, and authentication state;
- IP addresses, user agents, timestamps, sessions, verification, audit, and security events;
- vault names and identifiers, filenames, relative paths, sizes, versions, permission and share records, key references, and operational metadata;
- AES-256-GCM-encrypted file bodies, which may contain any Personal Data Customer chooses to submit;
- support content Customer elects to provide.
Sensitive data: not intended by default. Customer controls uploaded content and must apply appropriate restrictions and safeguards.
Managed-service trust boundary: ordinary object storage contains encrypted file bodies. VaultGuard uses KMS-backed server-managed key custody, so authorised operations can unwrap keys and process content transiently. Filenames, paths, sizes, versions, permissions, memberships, key references, audit, and operational metadata are service-visible.
Competent supervisory authority: determined under Clause 13 of the SCCs based on the exporter’s establishment, representative, or affected data subjects.
Annex II — Technical and organisational measures
Measures are designed for current risks and can evolve without materially reducing overall protection:
- AES-256-GCM encryption of supported file bodies on the device before upload;
- KMS-wrapped server-managed data-encryption keys, with KMS rotation enabled for the stack key;
- HTTPS using TLS 1.2 or newer, with TLS 1.3 when negotiated;
- Amazon Cognito authentication, optional MFA, session controls, and human-verification safeguards;
- organisation, vault, membership, and permission checks on content APIs; every content call is vault-scoped;
- time-bounded key leases, access revocation paths, and audited recovery and administrative operations;
- IAM service roles, secrets management, API Gateway, WAF, rate and abuse protections, and separated service responsibilities;
- S3 versioning and lifecycle controls, DynamoDB point-in-time recovery and deletion protection under production hardening, and documented disaster-recovery procedures;
- production log retention controls and customer-configurable audit retention;
- source, dependency, test, build, and release verification controls described in current engineering documentation;
- incident investigation, containment, recovery, and legally required notification processes;
- confidentiality obligations for authorised personnel and contractual protection for Subprocessors;
- customer controls for membership, roles, permissions, shares, device security, MFA policy, audit review, and exports available during the subscription.
These measures remain bounded by the current Cloud security guide and by retained versions, keys, permissions, and configured lifecycle controls.
Annex III — Subprocessors
The current list, purposes, and locations are published at vaultguard.cloud/legal/subprocessors. That page is incorporated into this DPA.