VAI.ia

Legal

Data Processing Agreement

Processing terms for business customers that provide personal data to VAI IA.

Effective: 2026-07-28Version: 2026-07-28.1
Contents
Parties and scopeProcessing detailsInstructions and dutiesSecurityRequests and incidentsSubprocessorsTransfersReturn and deletionInformation and auditsGeneral
Partes y alcanceDetallesInstrucciones y deberesSeguridadSolicitudes e incidentesSubencargadosTransferenciasDevolución y eliminaciónInformación y auditoríasGeneral

1. Parties, roles and scope

This Data Processing Agreement (“DPA”) forms part of the agreement between the business customer (“Customer”) and VAIONYX LLC, doing business as VAI IA (“Provider”), for the Services. It applies when Provider processes personal data on Customer's behalf.

For that processing, Customer is the controller or business and Provider is the processor or service provider, as those concepts apply. Each party remains independently responsible for personal data it processes for its own purposes, including account administration, security, legal compliance and billing.

If a signed order or negotiated DPA conflicts with this public DPA, the signed document controls for the conflict.

2. Processing details

Subject matter and duration

Providing configured conversational-assistant, scheduling, messaging, dashboard, support and related SaaS functions during the service term, plus limited retention needed for security, backup, dispute resolution and law.

Nature and purpose

Receiving, storing, organizing, retrieving, transmitting and deleting data to operate Customer-configured workflows, respond to end users, support appointments, deliver configured notifications, administer tenants and secure the Services.

Data subjects

Customer personnel, authorized users, prospective and current customers of Customer, website visitors, message recipients, appointment participants and other individuals whose data Customer submits.

Data categories

Names, contact details, account and tenant identifiers, messages, prompts, conversation context, appointment details, configuration, support records, technical and security metadata, and billing metadata when billing is enabled. Customer must not submit sensitive or regulated data unless expressly authorized in writing and appropriately configured.

3. Instructions and party duties

Provider will process Customer personal data only on documented instructions in the agreement, product configuration and authorized support requests, unless applicable law requires otherwise. Provider will inform Customer if an instruction appears to violate applicable data protection law, without assuming Customer's legal obligations.

Personnel authorized to process Customer personal data are subject to confidentiality obligations. Customer is responsible for lawful instructions, notices, legal bases or permissions, data accuracy, channel consents, data-subject communications and limiting submitted data to what is necessary.

4. Security measures

Taking account of the service and risk, Provider will maintain reasonable technical and organizational measures such as access controls, signed HTTP-only sessions, transport encryption for production, environment-based secret management, input validation, tenant association, restricted database permissions, logging and incident procedures. These measures evolve and do not guarantee absolute security.

Customer must implement the responsibilities described in the Security Overview.

5. Individual requests, assessments and incidents

Taking into account the nature of processing and information available, Provider will provide reasonable assistance for Customer's response to applicable requests for access, export, correction or deletion, impact assessments and regulator consultations. Customer remains responsible for determining whether and how to respond.

Provider will notify Customer without undue delay after becoming aware of a confirmed personal-data breach involving Customer personal data, to the extent required by applicable law or agreement, and provide reasonably available information. Notification is not an admission of fault.

6. Subprocessors

Customer authorizes the subprocessors below for the stated functions, including conditional providers only when Customer enables the relevant integration. “Prepared-disabled” means code exists but processing is not active by default. Provider remains responsible for its subprocessor obligations to the extent required by the agreement and applicable law.

ProviderPurposeDataStatus
SupabaseDatabase hosting and application data storage.Account, tenant and application data.active
VercelWebsite hosting and previews.Request and deployment metadata.active
GroqAI model inference.Prompts and limited conversation context.active

Provider may replace or add a subprocessor as services evolve. Provider will update this list before the new provider handles Customer personal data and, where a negotiated agreement requires advance notice or objection rights, follow that agreement.

7. International transfers

Customer acknowledges that Provider and subprocessors may process data in countries outside the Customer's country. Each party will use a legally valid transfer mechanism when required for its processing. A specific mechanism—such as contractual clauses or another recognized safeguard—must be confirmed for the applicable parties, locations and law rather than presumed universally by this page.

8. Return, deletion and retention

At Customer's documented request or service termination, Provider will delete or return Customer personal data within a commercially reasonable period, unless retention is required by law, needed to establish or defend claims, or remains in protected backups until ordinary overwrite. Customer should export needed data before termination. Deletion cannot remove data independently retained by third parties under Customer's direct relationship.

9. Information and audits

Provider will make reasonably available information needed to demonstrate the obligations in this DPA. If that information is insufficient and applicable law requires an audit, the parties will agree on a scoped, confidential audit that minimizes operational and security risk, normally no more than once per year unless a confirmed incident or regulator requires otherwise. Customer bears reasonable audit costs unless a material Provider breach is found.

10. General terms and contact

The agreement's liability limits, dispute terms, governing law and termination provisions apply to this DPA to the extent permitted by law. If this DPA conflicts with the agreement on personal-data processing, this DPA controls for that issue; mandatory law controls where it cannot be varied. Invalid provisions will be adjusted narrowly without invalidating the remainder.

Privacy requests and requests for a signed DPA: coceo@vainyx.com.

1. Partes, roles y alcance

Este Acuerdo de Tratamiento de Datos (“DPA”) forma parte del acuerdo entre el cliente empresarial (“Cliente”) y VAIONYX LLC, que opera como VAI IA (“Proveedor”). Aplica cuando el Proveedor trata datos personales por cuenta del Cliente.

Para ese tratamiento, el Cliente es responsable o negocio y el Proveedor es encargado o proveedor de servicios, según resulten aplicables esos conceptos. Cada parte responde independientemente por datos tratados para fines propios, como administración de cuentas, seguridad, cumplimiento y facturación.

Si una orden firmada o DPA negociado contradice este DPA público, el documento firmado prevalece respecto de la contradicción.

2. Detalles del tratamiento

Objeto y duración

Prestación de asistentes conversacionales, agendamiento, mensajería, paneles, soporte y funciones SaaS configuradas durante el servicio, más retención limitada por seguridad, respaldos, disputas y ley.

Naturaleza y finalidad

Recibir, almacenar, organizar, consultar, transmitir y eliminar datos para operar flujos configurados, responder usuarios, apoyar citas, entregar notificaciones, administrar tenants y proteger el servicio.

Titulares

Personal y usuarios del Cliente, clientes potenciales y actuales, visitantes, destinatarios de mensajes, participantes de citas y otras personas cuyos datos suministre el Cliente.

Categorías

Nombres, contactos, identificadores, mensajes, prompts, contexto limitado, citas, configuración, soporte, metadatos técnicos y de seguridad, y metadatos de cobro cuando billing esté activo. El Cliente no debe suministrar datos sensibles o regulados sin autorización escrita y configuración apropiada.

3. Instrucciones y deberes

El Proveedor tratará datos solo conforme a instrucciones documentadas en el acuerdo, configuración y solicitudes autorizadas, salvo obligación legal. Informará si una instrucción parece infringir la ley aplicable, sin asumir obligaciones jurídicas del Cliente.

El personal autorizado está sujeto a confidencialidad. El Cliente responde por instrucciones lícitas, avisos, bases o permisos, exactitud, consentimientos de canales, comunicaciones a titulares y minimización.

4. Medidas de seguridad

Considerando servicio y riesgo, el Proveedor mantendrá medidas razonables como controles de acceso, sesiones HTTP-only firmadas, cifrado en tránsito en producción, secretos en entorno, validación, asociación de tenant, permisos restringidos, logs y respuesta a incidentes. Estas medidas evolucionan y no garantizan seguridad absoluta.

El Cliente debe aplicar las responsabilidades de la Descripción de Seguridad.

5. Solicitudes, evaluaciones e incidentes

Según la naturaleza del tratamiento y la información disponible, el Proveedor dará asistencia razonable para solicitudes aplicables de acceso, exportación, corrección o eliminación, evaluaciones y consultas regulatorias. El Cliente determina si y cómo responde.

El Proveedor notificará sin dilación indebida al conocer una violación confirmada de datos del Cliente, en la medida exigida por ley o acuerdo, y facilitará información razonablemente disponible. La notificación no admite culpa.

6. Subencargados

El Cliente autoriza los proveedores siguientes para las funciones indicadas. Los proveedores condicionales solo intervienen si se habilita la integración; “prepared-disabled” indica código preparado sin tratamiento activo por defecto.

ProveedorFinalidadDatosEstado
SupabaseAlojamiento de base de datos.Datos de cuenta, tenant y aplicación.active
VercelAlojamiento del sitio y previews.Metadatos de solicitudes y despliegue.active
GroqInferencia de IA.Prompts y contexto limitado.active

El Proveedor actualizará la lista antes de que un nuevo subencargado trate datos y respetará derechos de aviso u objeción cuando un acuerdo negociado los exija.

7. Transferencias internacionales

Las partes reconocen que puede existir tratamiento fuera del país del Cliente. Cada parte usará un mecanismo válido cuando sea exigible. El mecanismo específico debe confirmarse según partes, ubicaciones y ley; esta página no presume cláusulas u otras salvaguardas universales.

8. Devolución, eliminación y retención

Ante solicitud documentada o terminación, el Proveedor eliminará o devolverá datos en un plazo comercial razonable, salvo retención legal, defensa de reclamaciones o respaldos protegidos hasta su sobreescritura ordinaria. El Cliente debe exportar datos necesarios antes de terminar.

9. Información y auditorías

El Proveedor facilitará información razonablemente disponible para demostrar estas obligaciones. Si fuera insuficiente y la ley exige auditoría, las partes acordarán un alcance confidencial que minimice riesgo, normalmente no más de una vez al año salvo incidente confirmado u orden regulatoria. El Cliente asume costos razonables salvo incumplimiento material del Proveedor.

10. Términos generales y contacto

Los límites de responsabilidad, disputas, ley aplicable y terminación del acuerdo aplican a este DPA en lo permitido. Este DPA prevalece en tratamiento de datos; la ley imperativa prevalece cuando no pueda modificarse. Disposiciones inválidas se ajustarán de forma limitada.

Solicitudes de privacidad o de un DPA firmado: coceo@vainyx.com.

VAI IATermsPrivacySecurityCookiesDPA

© 2026 VAIONYX LLC · VAI IA