• Platform
  • Solutions
  • Developers
  • Showcase
  • Pricing
  • Company
Get Started
  • Platform

    • Overview
    • Conductor
    • Architecture
    • Security
    • Status

    Capabilities

    • All 276
    • AI & ML
    • Storage
    • Auth & Identity
    • Billing
    • Search
    • Compute
    • Media

    SDK

    • SDK Overview
    • Face Modules
    • Quickstart
    • Playground
    • CLI
  • By Role

    • For Startups
    • For Enterprise
    • For Agencies
    • For Developers
    • For CTOs

    By Industry

    • Fintech
    • E-Commerce
    • Healthcare
    • Media
    • SaaS
    • Education

    By Use Case

    • AI Applications
    • Internal Tools
    • Marketplaces
    • Automation
  • Documentation

    • Getting Started
    • API Reference
    • Authentication
    • Webhooks
    • Templates
    • Sandbox

    Integrations

    • All Integrations
    • Stripe
    • OpenAI
    • AWS
    • GitHub
    • Build Your Own

    Resources

    • Technical Guides
    • Architecture Patterns
    • Project Templates
    • Glossary
    • Platform Changelog
    • SDK Changelog
  • Featured Demos

    • Showcase Gallery
    • SaaS Dashboard
    • AI Chat
    • E-Commerce Store
    • Admin Panel
    • Marketplace

    Case Studies

    • All Case Studies
    • Catalist — Fintech
    • Zumar — E-Commerce
    • Nova — AI SaaS
    • Meridian — Media
    • Atlas — Operations

    Enterprise

    • Enterprise Overview
    • Security
    • Compliance
    • SLA & Uptime
    • Deployment Options
    • Startup Program
  • Plans

    • Overview
    • Compare Plans
    • Pricing Calculator
    • Enterprise Pricing

    Compare

    • EEv3 vs Agencies
    • EEv3 vs No-Code
    • EEv3 vs Freelancers
    • EEv3 vs In-House
    • EEv3 vs Firebase

    Services

    • All Services
    • Custom Development
    • Platform Hosting
    • Consulting
    • AI Integration
  • About

    • About VertexStudio
    • Team
    • Culture
    • The Group
    • Partners
    • Testimonials

    Careers

    • Open Roles
    • Engineering

    More

    • Contact
    • Newsroom
    • Brand Assets
    • Trust Center
    • Legal
  • Get Started

On this page

  • Scope
  • Definitions
  • Processing Details
  • Data Subject Rights
  • Sub-Processors
  • Security Measures
  • Data Transfers
  • Audits
  • Term and Termination

Legal

Data Processing Agreement

Effective: January 1, 2024

This Data Processing Agreement ("DPA") forms part of the agreement between VertexStudio, Inc. ("Processor") and the customer ("Controller") for the provision of the EEv3 platform services. This DPA is entered into pursuant to Articles 28 and 29 of the General Data Protection Regulation (EU 2016/679) ("GDPR").

Scope

This DPA applies to all processing of personal data by the Processor on behalf of the Controller in connection with the provision of the EEv3 platform. The Controller determines the purposes and means of processing; the Processor processes personal data only on documented instructions from the Controller, except where required by applicable law.

Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
  • "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and erasure.
  • "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
  • "Sub-Processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "Standard Contractual Clauses" (SCCs) means the contractual clauses approved by the European Commission for transfers of Personal Data to third countries.

Processing Details

The Processor processes the following categories of Personal Data on behalf of the Controller:

  • Categories of Data Subjects: end users of the Controller's applications, employees, and business contacts.
  • Types of Personal Data: names, email addresses, IP addresses, authentication credentials, and any other data stored by the Controller through the EEv3 platform.
  • Purpose of processing: provision and maintenance of the EEv3 platform services as described in the Terms of Service.
  • Duration of processing: for the term of the agreement between the parties, plus any retention period required by applicable law.

Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. The Processor shall promptly notify the Controller of any Data Subject request received directly and shall not respond to such requests without the Controller's authorization, except as required by law.

Sub-Processors

The Controller authorizes the Processor to engage sub-processors to process Personal Data on behalf of the Controller. The Processor maintains a current list of sub-processors, available upon request. The Processor shall notify the Controller at least 30 days before adding or replacing a sub-processor. If the Controller objects to a new sub-processor, the parties shall work in good faith to resolve the objection. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.

Security Measures

The Processor implements and maintains appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption of Personal Data at rest (AES-256) and in transit (TLS 1.3).
  • Network-level isolation between tenant environments.
  • Role-based access controls with least-privilege principles for all internal systems.
  • Regular penetration testing and vulnerability assessments by independent third parties.
  • Incident detection and response procedures with defined escalation paths.
  • Employee background checks and mandatory data protection training.

Data Transfers

The Processor shall not transfer Personal Data to a country outside the European Economic Area (EEA) unless adequate safeguards are in place. For transfers to the United States, the Processor relies on the EU-U.S. Data Privacy Framework and, as a fallback mechanism, the Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision 2021/914). A copy of the executed SCCs is available upon request.

Audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Controller or an independent auditor mandated by the Controller. Audits shall be conducted with reasonable notice (no less than 30 days), during normal business hours, and shall not unreasonably interfere with the Processor's operations. The Processor maintains SOC 2 Type II certification, and audit reports are available upon request under NDA.

Term and Termination

This DPA shall remain in effect for the duration of the agreement between the parties. Upon termination, the Processor shall, at the Controller's election, return or delete all Personal Data within 30 days, unless retention is required by applicable law. The Processor shall certify deletion in writing upon request.

← All Legal
VertexStudio

The platform behind every company. 276 capabilities through one API.

Platform

  • Overview
  • Conductor
  • Capabilities
  • Architecture
  • Security
  • Status
  • Changelog

SDK & Docs

  • SDK
  • Face Modules
  • Quickstart
  • API Reference
  • Documentation
  • Integrations

Solutions

  • For Startups
  • For Enterprise
  • For Agencies
  • For Developers
  • Showcase
  • Case Studies

Services

  • Custom Development
  • Platform Hosting
  • API Access
  • Consulting
  • AI Integration

Company

  • About
  • Team
  • Careers
  • Partners
  • Newsroom
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • DPA
  • Acceptable Use
  • Trust Center
© 2026 VertexStudio. All rights reserved.
Privacy·Terms·Trust Center
Built with EEv3