Legal
Data Processing Agreement
Last updated October 2026
This Data Processing Agreement (“DPA”) is part of the Terms of Service and applies automatically when you publish a website with VibeToApp that collects personal data of visitors, for example through its contact form. You don’t need to sign anything; if you need a countersigned copy, email [email protected].
1. Parties and roles
The customer (the account holder who publishes a website) is the controller. VibeToApp LLC, a Wyoming limited liability company, [REGISTERED ADDRESS], operating VibeToApp (“processor”), processes personal data on the customer’s behalf. This DPA follows Art. 28(3) GDPR and the UK GDPR. If the customer is itself a processor for someone else, the processor acts as its sub-processor on the same terms.
2. Subject matter, duration, nature and purpose
| Subject matter | Hosting the customer’s website and providing its contact form and visitor statistics. |
|---|---|
| Duration | As long as the customer uses the service, plus the deletion period in section 10. |
| Nature of processing | Receiving, storing, displaying, exporting and deleting contact-form messages; counting page views; serving the website (including transient processing of visitors’ IP addresses to deliver pages, images and fonts). |
| Purpose | Letting the customer receive and answer enquiries and see how many people visit the site. |
| Data subjects | Visitors of the customer’s website; people who contact the customer through the form. |
| Personal data | Contact-form data: name, email address, phone number, message, time sent. Technical data: IP address and request data, processed transiently to deliver pages and for rate limiting (IP kept in memory for at most 60 seconds). Page-view statistics are aggregated counts per page and day and contain no personal data. |
| Special categories | None intended. The customer must not ask visitors for special-category data (e.g. health data) through the form; if a visitor volunteers it in a message, it is processed only as part of that message. |
3. Instructions
The processor processes the personal data only on documented instructions from the customer, including regarding transfers to third countries, unless required by EU or Member State law (in which case it informs the customer first unless the law prohibits it). The Terms, this DPA and the customer’s use and configuration of the service (for example publishing a form, exporting or deleting leads) are the customer’s complete instructions. The processor informs the customer if, in its opinion, an instruction infringes data protection law.
4. Confidentiality
The processor ensures that persons authorised to process the data are bound by confidentiality and only access it where needed to provide or support the service.
5. Security (Art. 32)
The processor implements appropriate technical and organisational measures, including:
- Encryption in transit (TLS) for all sites, forms and the dashboard; HSTS on platform domains.
- Access to leads only for the site owner’s account (and platform administrators where needed for support or legal obligations); passwords hashed with scrypt; random session tokens in HttpOnly cookies; rate limiting and a honeypot on forms; rate-limited sign-in.
- Data minimisation: no cookies on published sites, no storage of visitors’ IP addresses or browser identifiers, page views stored only as aggregate counts; fonts and images served from the processor’s own servers.
- Automatic deletion of contact-form messages after 24 months (configurable by the processor; the customer can delete earlier at any time).
- Strict security headers, separation of customer data by account, and restricted administrative access. [Add hosting-provider certifications, backup and access-logging measures.]
6. Sub-processors
The customer gives general authorisation for the sub-processors listed at /legal/subprocessors. For visitor and lead data the relevant sub-processor is the hosting provider ([HOSTING PROVIDER]). The processor informs the customer at least 30 days in advance of any intended addition or replacement; the customer may object on reasonable data-protection grounds, and if no solution is found, may terminate the affected service. The processor imposes the same data protection obligations on each sub-processor by contract and remains liable for them.
7. International transfers
Lead and visitor data is stored at [HOSTING LOCATION]. Any transfer outside the EU/EEA or UK takes place only with appropriate safeguards under Chapter V GDPR (adequacy decision, EU-US Data Privacy Framework, or Standard Contractual Clauses with the UK Addendum).
8. Assisting the customer
- Data-subject requests: the dashboard lets the customer view, export (CSV) and delete leads. If a visitor contacts the processor directly, the processor forwards the request to the customer without undue delay and does not respond itself unless instructed.
- Security, breaches, DPIAs: the processor assists the customer with Art. 32–36 obligations, taking into account the nature of processing and the information available to it.
9. Personal data breaches
The processor notifies the customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting the customer’s data, with the information required by Art. 33(3) GDPR as it becomes available, and takes reasonable steps to contain it.
10. Deletion and return
The customer can export leads at any time. When the customer deletes a lead, a site or their account, the data is deleted from live systems immediately; leads are in any case deleted after 24 months. [Backups: deleted within N days — fill in once backups are configured.] Data is kept longer only where EU or Member State law requires it.
11. Audits and information
The processor makes available the information necessary to demonstrate compliance with Art. 28 GDPR (this DPA, the sub-processor list, and a description of its security measures on request) and allows for and contributes to audits by the customer or an auditor mandated by it, on reasonable notice, at most once a year unless a breach or a supervisory authority requires otherwise, and subject to confidentiality.
12. Liability, precedence and term
Liability is governed by the Terms, subject to Art. 82 GDPR. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data. This DPA ends when the customer stops using the service and all customer personal data has been deleted. This DPA is governed by the law that governs the Terms (the State of Wyoming, USA), except where the Standard Contractual Clauses or the GDPR require the law of an EU Member State or the UK. [Counsel to confirm governing law and the SCC module.]
Contact
VibeToApp LLC · [REGISTERED ADDRESS] · [email protected]