Data Processing Agreement
This DPA applies where Vilkax processes personal data on behalf of a business customer - Article 28 GDPR. It forms part of the Business Terms and is accepted at business sign-up. It does not apply to consumer accounts, where Vilkaks UAB is the controller and the Privacy Policy governs.
1. Roles and scope
Vilkaks UAB (company ID 308049358, Klaipėda, Lithuania), the "Processor", processes personal data on behalf of the customer named on the Order Form, the "Controller", solely to provide the Vilkax service. Processing lasts for the term of the agreement plus the retention windows in section 7.
2. Nature and purpose
- Detecting and scoring fraud, phishing, scam, impersonation and account-takeover risk in content and signals the Controller routes to the service.
- Notifying the Controller's designated contacts when risk is detected.
- Providing administrative, reporting and audit tooling to the Controller's administrators.
3. Data subjects and personal data
Data subjects: the Controller's authorised users; individuals who correspond with them; and, where family or guardian features are enabled, designated contacts.
- Identifiers - email address, phone number, display name, account identifiers.
- Device and network metadata - operating system and version, hashed device identifier, security posture, connection type, hashed network name, country-level location.
- Content submitted for analysis - the text of messages and links, and, where the Controller enables the relevant feature, email message bodies and attachment metadata. Content is processed to produce a verdict and is not retained afterwards.
- Verdict and threat metadata - category, risk score, severity, reason codes, hashed message identifiers.
- Audit records - actor, target, IP address, timestamp, hash-chained.
Special categories. Content submitted for analysis is unstructured and may contain special-category data - including data concerning health, sex life or sexual orientation, religious or political views, or trade-union membership. The Processor does not select for, target, or derive insight from such data, does not retain the content beyond the analysis, and does not use it for training absent an express written instruction. The Controller is responsible for having an Art. 9 condition for any special-category data it routes to the service.
Criminal-offence data. A verdict that a message or sender is fraudulent is an allegation relating to a criminal offence (Art. 10). Verdicts are produced for the Controller's fraud-prevention and security purposes, are made available only to the Controller, and are not disclosed to third parties except as required by law.
4. Processor obligations
- Process personal data only on the Controller's documented instructions, and inform the Controller if an instruction appears to infringe the GDPR.
- Bind authorised personnel to confidentiality.
- Implement the measures in Annex A (Art. 32).
- Assist with Arts. 32 to 36 - security, breach notification, data protection impact assessments and prior consultation.
- Notify the Controller of a personal data breach without undue delay and in any event within 48 hours of becoming aware, with the information available at the time and updates as the investigation develops.
- Make available the information necessary to demonstrate compliance and allow for audits under section 9.
- On termination, delete or return all personal data within 30 days at the Controller's election, except where law requires retention.
5. Sub-processors
The Controller gives general written authorisation for the providers on our sub-processor page. The Processor imposes data-protection obligations on each of them no less protective than this DPA and remains fully liable for their performance. We give 30 days' notice before adding or replacing one; the Controller may object on reasonable data-protection grounds within that window, and if we cannot resolve the objection it may terminate the affected service with a pro-rata refund.
6. International transfers
EU and EEA personal data is processed in EU regions by default. Where a transfer to a third country occurs, the Processor relies on an adequacy decision where one applies, and otherwise on the EU Standard Contractual Clauses (Decision 2021/914) with a documented transfer impact assessment and supplementary measures. The mechanism relied on per provider is recorded on the sub-processor page.
7. Retention and deletion
- Content submitted for analysis - not retained once the verdict is produced.
- Verdict and threat metadata - 90 days in the EU, 180 days in other regions.
- Email verdicts (hashed message id plus rating) - 30 days.
- Audit logs - 365 days.
- Alert dispatch receipts - 30 days.
- Hash-chained event log - indefinite; metadata only, no content.
- Billing records - as required by Lithuanian tax law.
8. Data subject rights
The Processor assists the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to requests under Arts. 15 to 22, aiming to provide substantive assistance within 10 working days so the Controller can meet its own one-month deadline. Where a data subject approaches us directly about Controller data, we refer them to the Controller and inform the Controller without undue delay.
9. Audit
The Processor makes available its then-current security documentation and any third-party attestations it holds. Beyond that, the Controller may audit once in any 12-month period, and additionally after a personal data breach affecting its data, on 30 days' notice, during business hours, without unreasonable disruption, subject to confidentiality, at its own cost, using an auditor who is not a competitor of the Processor.
10. Liability
Liability under this DPA is subject to the limitation of liability in the Business Terms, save that nothing limits either party's liability to a data subject or to a supervisory authority under Art. 82 GDPR.
Annex A - technical and organisational measures
- Encryption - TLS 1.2 or above in transit; AES-256-GCM at rest for identifiers, tokens and journal content, with scheduled key rotation.
- Pseudonymisation - email, phone, device identifier and network name held as SHA-256 hashes in hot indexes; raw values encrypted or never persisted. IP and user-agent are additionally salted with a server-held secret. Hashing an identifier is pseudonymisation, not anonymisation: a hash of a low-entropy value such as an email address or phone number can be confirmed by anyone holding a candidate list, so these hashes are treated as personal data throughout.
- Access control - role-based access, least privilege, MFA for administrative access, four-eyes approval for destructive administrative actions, IP restriction on admin surfaces.
- Auditability - hash-chained, tamper-evident log of state-changing actions.
- Consent enforcement - signal intake validates persisted consent server-side and drops signals whose consent is not held, independently of client behaviour.
- Resilience - managed edge platform with regional failover; documented backup and restore.
- Testing - automated regression, security and detection-quality suites gate every release.
- Personnel - confidentiality obligations; access removed on role change or exit.
- Incident response - documented severity model, 72-hour authority notification path, breach record-keeping.
Last updated: 2026-08-22 · Version v2. For a countersigned copy, or to execute this DPA against your own paper, contact us.