Vaultivo

Legal

Data processing agreement

Version of 09.08.2026

This is a convenience translation. The German version is the binding one.

This agreement governs how Vaultivo processes the personal data contained in a business’s documents — on that business’s behalf and on its instructions.

1. Subject matter and roles

This agreement supplements the terms of service and governs processing on your behalf under Art. 28 GDPR.

The business using Vaultivo is the controller. The processor is Aurel-Mihai Botinanț, 1030 Wien, Arsenal Objekt 3/59.

It concerns the contents of archived documents only. For the account’s own registration and contract data Vaultivo is itself the controller; that is described in the privacy policy and is not covered by this agreement.

This agreement forms part of the terms of service and is entered into when they are accepted. (Terms of service)

2. Nature, purpose and duration of the processing

The subject matter is the storage, preparation and provision of invoices, receipts and comparable business documents.

Nature and purpose: accepting documents, scanning them for malware, converting them to a readable format, reading text and document data, storage, searchability, and making them available for retrieval.

The processing lasts as long as the contract for the use of Vaultivo. Its end is governed by clause 10.

3. Data subjects and categories of data

Data subjects are the people named in the documents submitted — in particular the business’s contacts, customers and suppliers — and the users of the account.

The categories of data are names, addresses, contact details, invoice and payment details, and other information contained in the documents.

Which data is transferred is determined by the business alone, through its choice of the documents it submits.

4. Instructions

Processing takes place only on the documented instructions of the business. This agreement, the terms of service and the use of the application’s features constitute those instructions.

If Vaultivo considers an instruction unlawful, the business is informed and the instruction is not carried out until the matter is resolved.

5. Confidentiality

The persons authorised to process the data are bound to confidentiality.

6. Technical and organisational measures

The measures taken include in particular:

  • Transmission over encrypted connections only.
  • Servers, database and object storage operated in the European Union (Frankfurt).
  • The connection between the application and the database runs over a private network; that traffic does not travel over the public internet.
  • Access to the servers only through the upstream service; all other access is refused.
  • Two-factor authentication for accounts with owner and administrative rights.
  • Tenant separation: every query is constrained to the business it belongs to.
  • Every incoming file is scanned for malware before any further processing.
  • Original files are stored immutably.
  • Privileged access is logged; audit entries can be neither altered nor deleted.

The measures are kept in line with the state of the art. A measure may be replaced provided the level of protection is maintained.

7. Sub-processors

The business consents to the use of the following sub-processors:

Service Role Region
DigitalOcean Server, database and object storage — where the documents live fra1 — Frankfurt, DE
Backblaze, Inc. Backup copy of the archived originals and their PDF versions, at a second provider EU Central — Amsterdam, NL
OpenAI Ireland Ltd. Reading text and document data IE / US
Mailgun Inbound document email and outbound system email EU
Stripe Payments Europe, Limited Payments and invoicing IE
Cloudflare DNS, delivery of this website, email forwarding for the contact address EU / global
Sentry Application error and operational logs — no document content EU
GitHub, Inc. Scheduled cleanup of the backup copy — processes storage paths, no document content US / global

Virus scanning, text extraction and document conversion are not carried out by third parties. They run in self-hosted components inside the same EU-hosted environment.

Changes to this list are notified 30 days in advance. If the business objects, it may terminate the contract.

Sub-processors are placed under obligations equivalent to those in this agreement.

8. Transfers outside the EU

Text extraction by OpenAI involves a transfer outside the EU; in addition, some of the sub-processors listed above process outside the EU, as shown in the list. The contracting party for text extraction is OpenAI Ireland Ltd., established in Ireland; processing also takes place in the United States.

That transfer is made on the European Commission’s Standard Contractual Clauses of 4 June 2021. A data processing agreement with OpenAI Ireland Ltd. was concluded on 8 August 2026.

According to OpenAI, content submitted through the API is not used to train models. OpenAI retains it for up to 30 days for abuse monitoring.

9. Assistance to the controller

For requests from data subjects — access, rectification, erasure, restriction, portability and objection — the business is supported through the application’s features and, beyond them, to a reasonable extent.

If a data subject approaches Vaultivo directly, they are referred to the business.

In the event of a personal data breach the business is informed without undue delay after it becomes known, and is supported with its obligations under Art. 33 and Art. 34 GDPR.

Reasonable assistance is given with data protection impact assessments and prior consultations under Art. 35 and Art. 36 GDPR.

10. End of the agreement

After cancellation the archive first becomes read-only. Documents remain viewable, downloadable and exportable.

30 days after cancellation takes effect the account is closed. All stored documents and all related data are permanently deleted.

Deleted data remains for up to 7 days — in the database backups, as a prior version in the file storage, and in the backup copy at the second provider. After that it is removed from all three.

An export of the whole archive can be requested at any time until closure.

11. Evidence and inspections

On request, the business is given the information necessary to demonstrate compliance with this agreement.

Inspections are possible on reasonable notice during normal business hours, to an extent that does not disrupt the operation of the application. The confidentiality of other businesses’ data is preserved.

12. Final provisions

In all other respects the terms of service apply. Austrian law applies.

The German version is the binding one; translations are provided for convenience.