Data Processing Agreement

The Article 28 terms for business customers whose use of Vultax makes them a controller and us a processor. Section 1 tells you whether that is you — for most customers it is not, and signing this would not give you anything the privacy policy does not already.

In force from
Version
1.0
Issued by
OmniOS OÜ

1When this agreement applies — and when it does not

Most template DPAs are signed by customers who never needed one. This section says plainly which position you are in, because signing the wrong document does not create a protection you lack.

SituationWho is the controllerDo you need this DPA?
You buy a plan and use the terminal yourself, as a company or an individualOmniOS OÜ is the controller of your account and billing data.No. The privacy policy governs. There is no processor relationship to paper.
You integrate the API and pass us identifiers or data about your own end usersYou are the controller of that end-user data; we process it on your instructions.Yes. This agreement applies to that data.
Your staff put your customers' or counterparties' personal data into Vi AI promptsYou are the controller of what your staff enter.Yes, and please read § 6 on sub-processors before doing it.
You read public market and blockchain analytics we publishOmniOS OÜ is the controller of that processing — see § 4 of the privacy policy.No.

This agreement takes effect automatically, without signature, from the moment you first send us personal data as a controller, and forms part of the Terms of Service. If your procurement process needs a countersigned copy on your own paper, write to [email protected] and we will sign one that matches these terms.

2Particulars of the processing

Required by Article 28(3) GDPR. In this agreement "Customer Data" means personal data you transmit to us as controller; "we" and "us" mean OmniOS OÜ (registry code 17591703), acting as processor.

Subject matter
Provision of the Vultax market intelligence terminal, API and alerting service.
Duration
For as long as your subscription runs, plus the deletion window in § 9.
Nature and purpose
Receiving, storing, transmitting, querying and displaying Customer Data so that we can deliver the Service you have bought. We perform no independent analysis of Customer Data and derive no product from it.
Types of personal data
Account identifiers you supply for your end users, contact details you enter, alert routing identifiers, and whatever your staff choose to enter into free-text fields including Vi AI prompts.
Categories of data subject
Your employees, contractors and end users.
Special categories
None. The Service is not designed for special-category data under Art. 9, and you must not send it.

3Our obligations as processor

  • Instructions. We process Customer Data only on your documented instructions, which comprise this agreement, the Terms, and your configuration of the Service. If we believe an instruction breaks the GDPR or Estonian data protection law, we tell you and may suspend that processing until it is resolved.
  • Legal compulsion. If EU or member-state law requires us to process beyond your instructions, we tell you before doing so unless that law forbids the notice on important public-interest grounds.
  • Confidentiality. Everyone we authorise to access Customer Data is bound by a written confidentiality obligation that survives the end of their engagement.
  • Security. We implement and maintain the technical and organisational measures required by Art. 32, described in the security policy. We may change a measure, but not so as to materially reduce protection.
  • No secondary use. We do not use Customer Data for our own purposes, to improve our models, to build datasets, or to train anything.

4Your obligations as controller

  • Have a valid legal basis for sending us the data, and give your data subjects the information Arts. 13 and 14 require.
  • Send only data that is adequate, relevant and limited to what the Service needs. Do not send special-category data, and do not send children's data.
  • Keep your own instructions lawful, and keep your account credentials secure.
  • Respond to your own data subjects. They are yours, not ours; we assist under § 5 but do not answer for you.

5Assistance we give you

Data subject requests
Taking account of the nature of the processing, we assist you with appropriate technical and organisational measures in meeting requests under Arts. 15 to 22. If a data subject comes to us directly, we do not answer on your behalf — we refer them to you and tell you within 5 working days.
Breach notification
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information you need for your own Art. 33 notification, and we supplement it as the investigation develops.
Impact assessments
We give you the information reasonably available to us for a data protection impact assessment or prior consultation under Arts. 35 and 36.
Records
We maintain a record of processing carried out on your behalf, as Art. 30(2) requires, and make it available on request.

6Sub-processors

You give general written authorisation for us to engage sub-processors. The current list is on the sub-processors page, which forms part of this agreement.

  • We impose on each sub-processor, by written contract, data protection obligations no less protective than these.
  • We remain fully liable to you for a sub-processor's performance of its obligations.
  • We publish an intended addition or replacement at least 30 days before it takes effect, and email the notification address on your account.
  • You may object on reasonable data-protection grounds within those 30 days. If we cannot offer a workaround, you may terminate the affected subscription and we refund the unused part of what you have paid.

Note for Vi AI: prompts are processed by our model provider, currently OpenAI, in the United States under Standard Contractual Clauses. If your controller assessment does not permit that transfer, do not put Customer Data into Vi AI prompts. We cannot prevent your staff from typing it.

7International transfers

Customer Data is stored in the European Union, in Frankfurt, Germany. Where a sub-processor transfers it outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (Decision 2021/914) or another Chapter V mechanism, identified per provider on the sub-processors page.

Where the Standard Contractual Clauses apply between us, Module Three (processor to sub-processor) is incorporated into this agreement by reference, with Estonia as the supervising authority's member state, and the particulars in § 2 populating Annexes I and II.

8Audit and information

We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

  • In the first instance we answer a written security questionnaire and provide our current documentation. For most customers this settles it.
  • Where that is genuinely insufficient, you may audit on 30 days' written notice, no more than once in any 12 months unless a breach or a regulator's instruction requires more.
  • An audit takes place in business hours, does not unreasonably disrupt the Service, and is subject to confidentiality. You bear your own costs; we bear ours unless the audit finds a material breach by us, in which case we bear both.
  • We will not give an auditor access to another customer's data, or to infrastructure shared with other customers, in a way that would compromise them.

9Return and deletion

At your choice, we delete or return all Customer Data at the end of the Service, and delete existing copies, unless EU or member-state law requires us to keep it.

  • You have 30 days from termination to export Customer Data through the API or to ask us for an export.
  • After 30 days we delete it from live systems.
  • Encrypted backups age out on their normal rotation, within 90 days. Data in a backup is not restored to live use.
  • We confirm deletion in writing on request.

10General

Precedence
Where this agreement conflicts with the Terms on the processing of Customer Data, this agreement governs.
Liability
Each party's liability under this agreement is subject to the limitations in § 16 of the Terms, except where Art. 82 GDPR provides otherwise. Nothing here limits a data subject's rights against either of us.
Governing law
The same law and forum as the Terms — see § 18 of the Terms.
Changes
We may update this agreement to reflect changes in law or in the Service, on 30 days' notice. If a change materially reduces your protection you may terminate the affected subscription before it takes effect.
Contact
[email protected] for this agreement; [email protected] for data protection questions.