Data Processing Agreement

Vedomia Workspace · Version 1.0 · 14 September 2026

This agreement forms part of the Terms of Use (section 4a) and applies to every organisation that uses the Vedomia Workspace. No signature is needed; a signed PDF of the same text is available on request from contact@vedomia.com.

Pre slovenské organizácie: toto je zmluva o spracúvaní osobných údajov podľa čl. 28 GDPR medzi vašou organizáciou (prevádzkovateľ) a Vedomia Limited (sprostredkovateľ). Platí automaticky pre každý Workspace. Záväzné je anglické znenie; slovenské zhrnutie alebo podpísané PDF vám na požiadanie pošleme na contact@vedomia.com.

This Data Processing Agreement ("DPA") sets out the terms on which Vedomia Limited, a company registered in Ireland (company number 796586), registered office 4 Peatlands, Broomfield, Midleton, Co. Cork, P25 D658, Ireland ("Vedomia") processes personal data on behalf of the organisation that holds a Vedomia Workspace (the "Customer"), as required by Article 28 of Regulation (EU) 2016/679 (the "GDPR") and the Data Protection Act 2018 (Ireland).

1. Roles

1.1 The Customer is the controller of the personal data it and its members place in its Workspace. Vedomia is the processor.

1.2 Vedomia is a separate, independent controller only for the limited data it needs to run its own business: the sign-in email addresses of Workspace members as account identifiers, billing and invoicing data, security and access logs, and support correspondence. That processing is described in the Privacy Notice, not in this DPA.

2. Subject matter, duration, nature and purpose

2.1 Subject matter: hosting and processing of the Customer's process maps and related content in the Vedomia Workspace.

2.2 Duration: for as long as the Customer's Workspace exists, plus the deletion period in section 9.

2.3 Nature and purpose: storing the Customer's maps, their saved versions and change history; generating documents, views, share links and reports from them when a member asks for them; sending sign-in, welcome and invitation emails to the people the Customer invites. Vedomia processes the data only to provide the service and never for its own purposes, analytics on content, or the training of any AI model.

2.4 Categories of data subjects: the Customer's staff, volunteers, board members and contractors, as Workspace members or as roles named in a map; and, only where the Customer chooses to record them, the people the Customer's services are for.

2.5 Categories of personal data: email addresses of Workspace members; names and roles of people written into maps; and any personal data the Customer chooses to type into a map. The Workspace is designed to record how a process works — roles, steps, records and where they are kept — not the personal details of the people who pass through it (see 4.3).

3. Vedomia's obligations (Article 28(3) GDPR)

Vedomia shall:

4. Customer's obligations

4.1 The Customer is responsible for the lawfulness of the personal data it places in the Workspace, for having a lawful basis for it, and for informing its own data subjects as Articles 13 and 14 require.

4.2 The Customer decides who its Workspace members are and which role each has (owner, editor or viewer). Invitations and removals take effect immediately and are the Customer's responsibility, including removing people who leave the organisation.

4.3 The Customer shall not store in the Workspace special categories of personal data (Article 9), personal data relating to criminal convictions and offences (Article 10), or individual case records about the people it serves. If the Customer needs to describe such processing in a map, it describes the kind of data and record involved, not the data itself.

4.4 The Customer shall keep its members' sign-in email addresses accurate. Because sign-in is by a one-time link sent to that address, the Customer is responsible for the security of the mailboxes its members use.

5. Sub-processors

5.1 The Customer gives general written authorisation to the engagement of the sub-processors listed in Annex 2.

5.2 Vedomia will inform the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the Workspace owners. The Customer may object on reasonable, documented data-protection grounds within that period. If the objection cannot be resolved, the Customer may terminate the Workspace and receives a pro-rata refund of any prepaid period; Vedomia provides the export in section 9.1 before deletion.

5.3 Vedomia imposes on each sub-processor, by a written contract, data-protection obligations providing the same level of protection as this DPA, and remains fully liable to the Customer for the performance of the sub-processor's obligations (Article 28(4)).

6. International transfers

6.1 Workspace data is stored by Netlify, Inc., a company established in the United States; the transfer is made under Netlify's participation in the EU–U.S. Data Privacy Framework and, in addition, the European Commission's Standard Contractual Clauses incorporated in Netlify's data processing terms. Email delivery (Brevo) takes place within the European Union. AI analysis, where and only where a member chooses it, is performed by Anthropic, PBC in the United States under the same kind of safeguards.

6.2 No other transfer of the Customer's personal data outside the European Economic Area takes place without the safeguards required by Chapter V of the GDPR, and Vedomia informs the Customer under section 5.2 before any change.

7. Personal-data breach

7.1 Vedomia notifies the Customer's Workspace owners, by email, without undue delay and in any event within 48 hours of becoming aware of a personal-data breach affecting the Customer's data. The notification contains the information Article 33(3) requires as far as it is known at that time — the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed — and is supplemented as further information becomes available, so that the Customer can meet its own 72-hour deadline to the supervisory authority.

7.2 Vedomia documents every breach, its effects and the remedial action taken, and makes that record available to the Customer on request.

8. Audit

8.1 Once in any 12-month period, and additionally after a breach affecting the Customer, the Customer may request written information demonstrating Vedomia's compliance with this DPA, including the current Annex 1 measures, the sub-processor list and the Article 30(2) record. Vedomia answers within 30 days.

8.2 Where the written information is reasonably insufficient to demonstrate compliance, the Customer or an independent auditor bound by confidentiality may audit Vedomia's relevant processing on at least 30 days' written notice, during business hours, at the Customer's cost, no more than once a year, and without access to other customers' data.

9. Return and deletion

9.1 At any time during the service, the Customer can request a complete export of its Workspace — the maps, every kept version, the change history, members and share links — in a machine-readable JSON file, and can generate the Word documents from its maps itself. Vedomia provides the export within 10 working days.

9.2 When the Workspace closes — because the Customer ends it, or the access period ends and is not renewed — Vedomia deletes the Customer's data within 90 days, or sooner on request, except where EU or Member State law requires retention, in which case only that data is kept, only for that purpose and only for that period. Vedomia keeps no separate backup copies of Workspace data; deletion at the storage provider is final, which is why the Customer is advised to export its Workspace before closure.

9.3 Copies of a map the Customer chose to share by a read-only link are deleted together with the Workspace; the Customer can switch any link off at any time before that.

10. Liability

Liability under this DPA is subject to section 7 (Limitation of liability) of the Terms of Use. Nothing in this DPA limits either party's liability towards data subjects under Article 82 GDPR, and each party is liable for administrative fines imposed on it under Article 83.

11. Term, changes and precedence

11.1 This DPA applies for as long as Vedomia processes personal data for the Customer and survives the end of the Terms until every copy has been deleted or returned.

11.2 Vedomia may update Annex 1 to strengthen or update its measures without reducing the level of protection, and Annex 2 only under section 5. Any other change is announced by email to the Workspace owners 30 days before it takes effect.

11.3 If this DPA conflicts with the Terms of Use on a data-protection matter, this DPA prevails. The English text is the binding version; any translation is provided for convenience.

12. Governing law, supervisory authority and contact

12.1 This DPA is governed by the laws of Ireland, and the courts of Ireland have exclusive jurisdiction, without prejudice to the rights of data subjects and supervisory authorities under the GDPR.

12.2 Vedomia's lead supervisory authority is the Data Protection Commission, Ireland (dataprotection.ie). Vedomia has not designated a data protection officer, because its core activities do not meet the conditions of Article 37(1); all data-protection matters are handled by the company's director and reach us at contact@vedomia.com.

Annex 1 — Technical and organisational measures (Article 32)

AreaMeasure in place as of 14 September 2026
Access to a WorkspacePasswordless sign-in by a one-time email link, valid 20 minutes and usable once; a session cookie (__Host-vd_workspace) that is HttpOnly, Secure, SameSite=Lax and expires after 30 days; membership re-checked on the server on every request, so removal is immediate.
AuthorisationThree roles — owner, editor, viewer. Only owners invite or remove people; every server function checks membership and role before reading or writing.
Separation between customersEvery stored key carries the Workspace identifier; a request for another Workspace's data returns "not found". Automated tests cover this isolation and run before every deployment.
EncryptionTLS 1.2 or higher for every request between the browser, the functions and the storage; data encrypted at rest by the storage provider.
Integrity and historyEvery save is a new version and the last 40 versions of each map are kept; a save based on an outdated version is refused (HTTP 409) instead of overwriting a colleague's work; restoring an old version never deletes history.
Availability and restoreAny kept version can be restored by the Customer; a full export can be produced on request. Vedomia keeps no separate off-site backup, and relies on the redundancy of the storage provider; the Customer is advised to export at milestones.
Minimisation in sharingA read-only link carries only the fields its audience may see; internal notes, risks and data-protection detail are removed on the server before the shared copy is stored.
Abuse limitsRate limits on sign-in requests, invitations and report generation; when the limiter's store is unavailable, requests are refused rather than allowed.
Secrets and tokensNo credentials in source code; production secrets held only in the hosting provider's environment; sign-in tokens are signed for a single purpose, so an administrative token can never open a Workspace and a Workspace session can never reach administration.
LoggingServer logs record events — sign-in, provisioning, export, member changes, deletion — with time and Workspace identifier, never map content.
Portability and erasureAn administrative export (complete JSON) and an administrative erasure (memberships, maps, versions, share links, the record itself) exist as tested functions; erasure requires the organisation's name to be typed back.
PeopleOne person — the company's director — holds administrative access, which itself requires a one-time link to the director's own mailbox. Any contractor works under a written confidentiality obligation.
Development and deploymentAutomated tests for authentication, membership, isolation, share stripping and retention run before every deployment; the deployment script refuses to publish when production secrets are missing.

Annex 2 — Sub-processors

Sub-processorPurposeLocationTransfer safeguard
Netlify, Inc.Hosting of the Workspace functions; storage of maps, versions, members and share copies (Netlify Blobs)United StatesEU–U.S. Data Privacy Framework; Standard Contractual Clauses in Netlify's data processing terms
Brevo (Sendinblue SAS)Delivery of sign-in, welcome and invitation emails to Workspace membersEuropean Union (France)Not a transfer; Brevo's data processing agreement
Google Ireland Limited (Google Workspace)Support correspondence with the Customer at contact@vedomia.com, which may contain personal data the Customer includes in a requestEuropean Union / United StatesEU–U.S. Data Privacy Framework; Standard Contractual Clauses in Google's data processing terms
Anthropic, PBCOnly when a Workspace member chooses AI analysis of a document in the builder: the text is sent once for that request and is not used to train models. Never automatic.United StatesEU–U.S. Data Privacy Framework; Standard Contractual Clauses in Anthropic's commercial terms

Not a sub-processor of Workspace content: Stripe Payments Europe, Ltd. processes the Customer's billing data as an independent controller for payment services and never receives map content; it is described in the Privacy Notice.