Data processing addendum
Vega Ventures, LLC · Effective October 6, 2026 · Last updated October 6, 2026Between the customer ("Controller") and Vega Ventures, LLC ("Processor"). This DPA forms part of the Terms of Service and applies when Echo processes personal data on the customer's behalf under the GDPR, UK GDPR, Swiss FADP, or US state privacy laws ("Data Protection Laws"). It takes effect when the customer accepts the Terms; a countersigned copy is available on request at paris@enokseo.com. If this DPA and the Terms conflict on data protection, this DPA wins; if the Standard Contractual Clauses conflict with either, the Clauses win.
1. Scope
- Subject matter: providing the Echo Service.
- Duration: the term of the Terms of Service, plus the deletion period below.
- Nature and purpose: hosting, storage, analysis, reporting and email delivery as the customer instructs through the Service.
- Personal data: names, work emails, roles and activity of the customer's users and invited clients; any personal data the customer includes in prompts, notes or site context.
- Data subjects: the customer's employees, contractors, agency clients and client viewers.
- Special categories: none. Customers must not put sensitive data in prompts or notes.
- Frequency: continuous while the Service is used.
2. Processor obligations
The Processor will:
- Process personal data only on the Controller's documented instructions (the Terms, this DPA and use of the Service), unless the law requires otherwise, and tell the Controller if an instruction seems to break Data Protection Laws.
- Make sure people with access are bound by confidentiality.
- Keep appropriate technical and organizational measures (Annex 1).
- Use subprocessors only as set out in section 3.
- Help the Controller answer data subject requests, mostly through self-serve tools, and pass on any request it receives directly.
- Help with security, breach notification, impact assessments and prior consultations, taking into account the nature of processing.
- Delete or return personal data at the end of the Service (section 6).
- Make available information needed to show compliance, and allow audits as set out in section 7.
3. Subprocessors
The Controller gives general authorization to the subprocessors on the Subprocessors page. The Processor will give at least 30 days' notice of new subprocessors by email or in the app. The Controller may object on reasonable data protection grounds within that period; if we can't resolve it, the Controller may terminate the affected Service and receive a pro-rated refund of unused prepaid credits. The Processor binds each subprocessor to data protection terms at least as protective as this DPA and stays responsible for them.
4. International transfers
Where personal data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Decision 2021/914) are incorporated by reference, with the customer as exporter and the Processor as importer:
- Module 2 (controller to processor) applies; Module 3 (processor to processor) applies where the customer is itself a processor, such as an agency acting for its clients.
- Clause 7 (docking) applies. Clause 9: option 2 (general authorization), 30 days' notice. Clause 11: the optional wording doesn't apply. Clause 13: the supervisory authority of the exporter's EU establishment or representative, otherwise Ireland. Clauses 17 and 18: the law and courts of Ireland.
- Annex I is completed by section 1 and Annex 2 of this DPA; Annex II by Annex 1; Annex III by the Subprocessors page.
- UK: the ICO International Data Transfer Addendum applies, with the tables completed by this section. Switzerland: the Clauses apply with the FDPIC as authority and references to the GDPR read as the FADP.
5. Personal data breaches
The Processor will notify the Controller without undue delay, and within 48 hours of becoming aware of a breach affecting the Controller's personal data, with the information then available (nature, categories and approximate numbers affected, likely consequences, measures taken), and will update it as more is known.
6. Deletion
On account closure, personal data is deleted within 14 days and from backups within 30 more days, unless the law requires keeping it. Exports are available in Settings before closing.
7. Audits
The Processor will answer reasonable security questionnaires once a year and share summaries of third-party assessments when available. On-site audits are allowed where Data Protection Laws require, with 30 days' notice, during business hours, at the Controller's cost, and under confidentiality.
8. US state laws
For the CCPA/CPRA and similar laws, the Processor acts as a service provider/processor. It won't sell or share personal data, won't retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Service, won't combine it with other data except as the law allows, and will tell the Controller if it can no longer meet these obligations.
9. Liability
Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the Standard Contractual Clauses don't allow it.
Annex 1 — Security measures
In place during the private beta: encryption in transit (TLS); application and primary database hosting in the United States (Ashburn, Virginia); role-based access with least privilege, including a restricted database role for the application; sign-in codes and links for users instead of passwords; isolated workspaces, with membership checked on every request. Further measures will be listed here once they are in place and verified.
Annex 2 — Parties
- Exporter: the customer, as identified in its account. Role: controller (or processor, for agencies acting for clients).
- Importer: Vega Ventures, LLC, USA. Role: processor. Contact: paris@enokseo.com.