Legal
Version of 09.08.2026
This is a convenience translation. The German version is the binding one.
This agreement governs how Vaultivo processes the personal data contained in a business’s documents — on that business’s behalf and on its instructions.
This agreement supplements the terms of service and governs processing on your behalf under Art. 28 GDPR.
The business using Vaultivo is the controller. The processor is Aurel-Mihai Botinanț, 1030 Wien, Arsenal Objekt 3/59.
It concerns the contents of archived documents only. For the account’s own registration and contract data Vaultivo is itself the controller; that is described in the privacy policy and is not covered by this agreement.
This agreement forms part of the terms of service and is entered into when they are accepted. (Terms of service)
The subject matter is the storage, preparation and provision of invoices, receipts and comparable business documents.
Nature and purpose: accepting documents, scanning them for malware, converting them to a readable format, reading text and document data, storage, searchability, and making them available for retrieval.
The processing lasts as long as the contract for the use of Vaultivo. Its end is governed by clause 10.
Data subjects are the people named in the documents submitted — in particular the business’s contacts, customers and suppliers — and the users of the account.
The categories of data are names, addresses, contact details, invoice and payment details, and other information contained in the documents.
Which data is transferred is determined by the business alone, through its choice of the documents it submits.
Processing takes place only on the documented instructions of the business. This agreement, the terms of service and the use of the application’s features constitute those instructions.
If Vaultivo considers an instruction unlawful, the business is informed and the instruction is not carried out until the matter is resolved.
The persons authorised to process the data are bound to confidentiality.
The measures taken include in particular:
The measures are kept in line with the state of the art. A measure may be replaced provided the level of protection is maintained.
The business consents to the use of the following sub-processors:
| Service | Role | Region |
|---|---|---|
| DigitalOcean | Server, database and object storage — where the documents live | fra1 — Frankfurt, DE |
| Backblaze, Inc. | Backup copy of the archived originals and their PDF versions, at a second provider | EU Central — Amsterdam, NL |
| OpenAI Ireland Ltd. | Reading text and document data | IE / US |
| Mailgun | Inbound document email and outbound system email | EU |
| Stripe Payments Europe, Limited | Payments and invoicing | IE |
| Cloudflare | DNS, delivery of this website, email forwarding for the contact address | EU / global |
| Sentry | Application error and operational logs — no document content | EU |
| GitHub, Inc. | Scheduled cleanup of the backup copy — processes storage paths, no document content | US / global |
Virus scanning, text extraction and document conversion are not carried out by third parties. They run in self-hosted components inside the same EU-hosted environment.
Changes to this list are notified 30 days in advance. If the business objects, it may terminate the contract.
Sub-processors are placed under obligations equivalent to those in this agreement.
Text extraction by OpenAI involves a transfer outside the EU; in addition, some of the sub-processors listed above process outside the EU, as shown in the list. The contracting party for text extraction is OpenAI Ireland Ltd., established in Ireland; processing also takes place in the United States.
That transfer is made on the European Commission’s Standard Contractual Clauses of 4 June 2021. A data processing agreement with OpenAI Ireland Ltd. was concluded on 8 August 2026.
According to OpenAI, content submitted through the API is not used to train models. OpenAI retains it for up to 30 days for abuse monitoring.
For requests from data subjects — access, rectification, erasure, restriction, portability and objection — the business is supported through the application’s features and, beyond them, to a reasonable extent.
If a data subject approaches Vaultivo directly, they are referred to the business.
In the event of a personal data breach the business is informed without undue delay after it becomes known, and is supported with its obligations under Art. 33 and Art. 34 GDPR.
Reasonable assistance is given with data protection impact assessments and prior consultations under Art. 35 and Art. 36 GDPR.
After cancellation the archive first becomes read-only. Documents remain viewable, downloadable and exportable.
30 days after cancellation takes effect the account is closed. All stored documents and all related data are permanently deleted.
Deleted data remains for up to 7 days — in the database backups, as a prior version in the file storage, and in the backup copy at the second provider. After that it is removed from all three.
An export of the whole archive can be requested at any time until closure.
On request, the business is given the information necessary to demonstrate compliance with this agreement.
Inspections are possible on reasonable notice during normal business hours, to an extent that does not disrupt the operation of the application. The confidentiality of other businesses’ data is preserved.
In all other respects the terms of service apply. Austrian law applies.
The German version is the binding one; translations are provided for convenience.