Data Processing Agreement
Roles under this DPA
Data about the Customer's own account — for which VBS is Controller — is governed instead by the Privacy Policy.
1 Definitions and scope
1.1 Terms such as "personal data", "processing", "data subject", "supervisory authority" and "personal data breach" have the meanings given in the applied GDPR.
1.2 "Data Protection Law" means the applied GDPR and the Isle of Man Data Protection Act 2018 and its implementing regulations, as amended, together with any other data-protection law applicable to the processing.
1.3 This DPA applies to all processing of Customer Personal Data carried out by VBS in the course of providing Vector Velocity. Where this DPA conflicts with the Terms of Service on a data-protection matter, this DPA prevails.
2 Details of the processing (Article 28(3))
The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex A. The Customer instructs VBS to process Customer Personal Data as described in Annex A and as necessary to provide the Service.
3 VBS's obligations as Processor
VBS shall:
3.1 Documented instructions. Process Customer Personal Data only on the Customer's documented instructions — including as to international transfers — unless required to do otherwise by law, in which case VBS will inform the Customer first unless the law prohibits it. The Terms of Service, this DPA and the Customer's use of the Service's features constitute the Customer's complete and final instructions.
3.2 Confidentiality. Ensure that persons authorised to process the data are bound by an appropriate duty of confidentiality.
3.3 Security. Implement the technical and organisational measures set out in Annex C to ensure a level of security appropriate to the risk, in accordance with Article 32.
3.4 Sub-processors. Engage sub-processors only in accordance with clause 4.
3.5 Assistance with data subject rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. The Service's self-service export and edit tools are provided for this purpose.
3.6 Assistance with compliance. Assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to VBS.
3.7 Breach notification. Notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data, providing the information the Customer reasonably needs to meet its own notification obligations to the Isle of Man Information Commissioner and to affected data subjects.
3.8 Deletion or return. At the end of the Service, at the Customer's choice, delete or return all Customer Personal Data and delete existing copies, unless retention is required by law. VBS provides a self-service export for 30 days after termination, after which Customer Personal Data is deleted within 90 days, subject to backups being overwritten on their normal cycle.
3.9 Audits and information. Make available to the Customer all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits conducted by the Customer or an auditor it mandates. VBS may satisfy this by providing relevant documentation and responding to reasonable written questions; on-site inspections may be conducted on reasonable notice, no more than once per year absent a breach, subject to confidentiality.
3.10 Instructions that breach the law. Immediately inform the Customer if, in VBS's opinion, an instruction infringes Data Protection Law.
4 Sub-processors
4.1 The Customer gives general authorisation for VBS to engage the sub-processors listed in Annex B to process Customer Personal Data for the purposes stated.
4.2 VBS will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to the Customer for each sub-processor's performance.
4.3 VBS will give the Customer at least 30 days' notice of any intended addition or replacement of a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Service.
4.4 Stripe. Payment card processing is carried out by Stripe. In respect of payment data, Stripe acts as an independent (separate) controller under its own terms and privacy notice, not as VBS's sub-processor. It is listed in Annex B for transparency, marked accordingly.
5 International transfers
5.1 VBS will not transfer Customer Personal Data outside the Isle of Man or the EEA except in accordance with Annex B and subject to an appropriate transfer mechanism under Data Protection Law — such as processing in an adequate jurisdiction, Standard Contractual Clauses, or an applicable certification framework.
5.2 The Customer authorises the transfers described in Annex B on this basis.
6 Liability and term
6.1 This DPA takes effect when the Customer accepts the Terms of Service and continues for as long as VBS processes Customer Personal Data.
6.2 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where Data Protection Law does not permit such limitation.
6.3 This DPA is governed by the law of the Isle of Man.
| Item | Detail |
|---|---|
| Subject-matter | Provision of the Vector Velocity business-management platform to the Customer. |
| Duration | For the term of the Customer's subscription, plus the export and deletion periods in clause 3.8. |
| Nature and purpose | Hosting, storage, structuring, retrieval, transmission and deletion of Customer Personal Data to deliver scheduling, CRM, invoicing, payments, staff management, payroll and the customer-facing booking portal. |
| Types of personal data | Names, contact details and addresses of the Customer's clients; property/site access codes; job and service history; invoice and payment records; staff names, contact details, pay rates, hours worked, holiday/leave, and Isle of Man ITIP and National Insurance figures for payroll. |
| Special category data | The Service is not intended for the storage of special category data (Art. 9). The Customer must not enter such data into free-text fields. |
| Categories of data subjects | The Customer's clients / end-customers; the Customer's staff and contractors; the Customer's own contacts entered into the system. |
| Controller / Processor | Customer = Controller. VBS = Processor. |
| Sub-processor | Role | Location | Transfer basis |
|---|---|---|---|
| Supabase | Database hosting and storage of all application data | AWS EU (Frankfurt), EU | Within EEA — adequacy |
| Netlify | Application hosting; serverless functions; edge routing | United States (global edge network) | EU SCCs + UK IDTA (Netlify is EU–US DPF certified; SCCs are the operative basis for IOM-origin transfers) |
| Resend | Transactional email delivery | United States | SCCs / applicable framework |
| Stripe (separate controller) | Payment processing — acts as independent controller for payment data, not sub-processor | US / Ireland | Stripe's own transfer terms |
VBS maintains the following measures in accordance with Article 32:
Access control and isolation
- Row-Level Security in the database so each tenant's data is isolated and queries are filtered by organisation ID against the authenticated session
- Role-based access within the Service; least-privilege administrative access
- Multi-factor authentication for administrative and privileged access
Encryption
- Encryption of data in transit (TLS) and at rest
- Passwords stored only as salted hashes; no plaintext credential storage
Operational security
- Regular backups with a defined restore process; backups encrypted. Backups occur daily and are retained for 7 days
- Logging and monitoring of access and key events for audit and incident detection
- Timely application of security updates and patches
- Vulnerability management and periodic security testing
Organisational
- Confidentiality obligations on all personnel with access to Customer Personal Data
- A documented personal data breach response procedure aligned with clause 3.7
Acceptance of the Terms of Service constitutes acceptance of this DPA on behalf of the Customer as Controller. A separate signature is not required, but the version accepted, the accepting user, and the date, time and IP are recorded.