Legal
Data Processing Agreement (DPA)
Template for GDPR data processing engagements with clients.
Last updated: 12 July 2026
Scope of processing
This Data Processing Agreement (DPA) template applies when Vexoris Development processes personal data on behalf of a client in connection with agreed services (e.g. building or operating a platform).
Subject matter, duration, nature, and purpose of processing are defined in the main service agreement and any statement of work. Processing is limited to what is necessary to deliver those services.
Data controller and processor roles
The client is generally the data controller for end-user or customer personal data processed in the delivered solution. Vexoris Development acts as data processor when handling that data solely on the client's documented instructions.
For Vexoris Development's own website, account administration, and studio operations, Vexoris Development is the controller — see our Privacy Policy.
Processing instructions
We process personal data only on documented instructions from the controller, including regarding transfers, unless required by EU or member state law. We inform the controller if we believe an instruction infringes applicable data protection law.
Sub-processors
The controller authorises use of sub-processors necessary to deliver the service. Current categories include:
- Application hosting and content delivery — our site and applications are served through third-party hosting infrastructure with appropriate data processing agreements in place.
- Database hosting — personal data is stored in an encrypted, distributed database service.
- File storage — uploaded files are stored using object storage infrastructure with access controls.
- Email delivery — transactional and support email is sent via a third-party email delivery service under a data processing agreement.
Sub-processor transparency
A full sub-processor list with provider names can be provided to clients and regulators on request via a private security appendix. This satisfies transparency obligations without publishing vendor names on this public page.
Security measures
We implement appropriate technical and organisational measures, including access controls, encrypted transport (HTTPS), hashed passwords, session security, rate limiting, and least-privilege access to production systems.
Details can be expanded in a security appendix upon request.
Breach notification
We notify the controller without undue delay after becoming aware of a personal data breach affecting data we process on their behalf, and provide information reasonably required to meet the controller's obligations under Articles 33 and 34 GDPR.
We cooperate with the controller in investigating and mitigating incidents.
Return and deletion
Upon termination of services, we delete or return personal data per the controller's instructions and applicable law, unless retention is required by law.