Data Processing Agreement

This DPA applies where Vilkax processes personal data on behalf of a business customer - Article 28 GDPR. It forms part of the Business Terms and is accepted at business sign-up. It does not apply to consumer accounts, where Vilkaks UAB is the controller and the Privacy Policy governs.

1. Roles and scope

Vilkaks UAB (company ID 308049358, Klaipėda, Lithuania), the "Processor", processes personal data on behalf of the customer named on the Order Form, the "Controller", solely to provide the Vilkax service. Processing lasts for the term of the agreement plus the retention windows in section 7.

2. Nature and purpose

3. Data subjects and personal data

Data subjects: the Controller's authorised users; individuals who correspond with them; and, where family or guardian features are enabled, designated contacts.

Special categories. Content submitted for analysis is unstructured and may contain special-category data - including data concerning health, sex life or sexual orientation, religious or political views, or trade-union membership. The Processor does not select for, target, or derive insight from such data, does not retain the content beyond the analysis, and does not use it for training absent an express written instruction. The Controller is responsible for having an Art. 9 condition for any special-category data it routes to the service.

Criminal-offence data. A verdict that a message or sender is fraudulent is an allegation relating to a criminal offence (Art. 10). Verdicts are produced for the Controller's fraud-prevention and security purposes, are made available only to the Controller, and are not disclosed to third parties except as required by law.

4. Processor obligations

5. Sub-processors

The Controller gives general written authorisation for the providers on our sub-processor page. The Processor imposes data-protection obligations on each of them no less protective than this DPA and remains fully liable for their performance. We give 30 days' notice before adding or replacing one; the Controller may object on reasonable data-protection grounds within that window, and if we cannot resolve the objection it may terminate the affected service with a pro-rata refund.

6. International transfers

EU and EEA personal data is processed in EU regions by default. Where a transfer to a third country occurs, the Processor relies on an adequacy decision where one applies, and otherwise on the EU Standard Contractual Clauses (Decision 2021/914) with a documented transfer impact assessment and supplementary measures. The mechanism relied on per provider is recorded on the sub-processor page.

7. Retention and deletion

8. Data subject rights

The Processor assists the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to requests under Arts. 15 to 22, aiming to provide substantive assistance within 10 working days so the Controller can meet its own one-month deadline. Where a data subject approaches us directly about Controller data, we refer them to the Controller and inform the Controller without undue delay.

9. Audit

The Processor makes available its then-current security documentation and any third-party attestations it holds. Beyond that, the Controller may audit once in any 12-month period, and additionally after a personal data breach affecting its data, on 30 days' notice, during business hours, without unreasonable disruption, subject to confidentiality, at its own cost, using an auditor who is not a competitor of the Processor.

10. Liability

Liability under this DPA is subject to the limitation of liability in the Business Terms, save that nothing limits either party's liability to a data subject or to a supervisory authority under Art. 82 GDPR.

Annex A - technical and organisational measures

Last updated: 2026-08-22 · Version v2. For a countersigned copy, or to execute this DPA against your own paper, contact us.