Data Processing Agreement

Last updated: June 2025

1. Purpose and Scope

This Data Processing Agreement ("DPA") forms part of the agreement between Volgrei ("Data Processor") and the user or entity ("Data Controller") using the Volgrei Service. This DPA governs the processing of personal data by Volgrei on behalf of the Data Controller in connection with the provision of the Service, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).

2. Definitions

For the purposes of this DPA:

  • "Personal Data" means any information relating to an identified or identifiable natural person as defined in Article 4(1) GDPR.
  • "Processing" means any operation performed on personal data as defined in Article 4(2) GDPR.
  • "Data Subject" means the natural person to whom the personal data relates.
  • "Sub-processor" means any third party engaged by Volgrei to process personal data in connection with the Service.

3. Nature and Purpose of Processing

Volgrei processes personal data solely for the purpose of providing the Service as described in the Terms of Service and Privacy Policy. Processing activities include storage of user-generated content, authentication, subscription management, and AI-assisted features. Volgrei shall not process personal data for any purpose other than those documented herein or as instructed in writing by the Data Controller.

4. Obligations of Volgrei as Data Processor

Volgrei agrees to:

  • Process personal data only on documented instructions from the Data Controller, including with regard to transfers outside the EEA;
  • Ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations;
  • Implement appropriate technical and organizational security measures pursuant to Article 32 GDPR;
  • Assist the Data Controller in responding to requests from data subjects exercising their rights under Chapter III GDPR;
  • Notify the Data Controller without undue delay, and no later than 72 hours, upon becoming aware of a personal data breach;
  • Delete or return all personal data to the Data Controller upon termination of the Service, and delete existing copies unless retention is required by applicable law;
  • Make available all information necessary to demonstrate compliance with Article 28 GDPR obligations.

5. Sub-processors

The Data Controller grants Volgrei general authorization to engage sub-processors. Volgrei currently engages the following sub-processors:

  • Supabase Inc. — database and authentication (United States)
  • Anthropic PBC — AI inference processing (United States)
  • RevenueCat Inc. — subscription management (United States)
  • Cloudflare Inc. — network and delivery infrastructure (United States)

Volgrei shall impose data protection obligations on each sub-processor equivalent to those set out in this DPA. Volgrei will notify the Data Controller of any intended changes to sub-processors, giving the Data Controller the opportunity to object. Transfers to sub-processors outside the EEA are conducted under Standard Contractual Clauses or equivalent safeguards.

6. Security Measures

Volgrei implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including: encryption of personal data in transit using TLS 1.2 or higher; encryption of personal data at rest; access controls and authentication mechanisms; regular review of security measures; and procedures for testing and evaluating the effectiveness of security measures.

7. Data Subject Rights Assistance

Taking into account the nature of the processing, Volgrei shall assist the Data Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Data Controller's obligations to respond to requests for the exercise of data subjects' rights under Chapter III of the GDPR, including rights of access, rectification, erasure, restriction, portability, and objection.

8. Data Breach Notification

In the event of a personal data breach, Volgrei will notify the Data Controller without undue delay and within 72 hours of becoming aware of the breach. Such notification shall include, to the extent available: a description of the nature of the breach; the categories and approximate number of data subjects concerned; the likely consequences of the breach; and the measures taken or proposed to address the breach.

9. Term and Termination

This DPA remains in effect for the duration of the Service agreement. Upon termination of the Service, Volgrei shall, at the choice of the Data Controller, delete or return all personal data processed under this DPA, and certify such deletion in writing, unless applicable law requires continued storage.

10. Contact

For questions regarding this DPA or to exercise your rights, please contact us at [email protected].