/legal/dpa

Data Processing Agreement

This standard DPA governs how Vulos Labs (Pty) Ltd (“Vulos”) processes Personal Data on behalf of customers (“Controllers”). It is incorporated by reference into the Vulos Terms of Service. No per-customer negotiation below Enterprise tier — SMB customers accept this standard agreement at checkout or via the acceptance box below.

Version 1.0Effective 2026-05-23POPIA · GDPR · UK GDPR · CCPA

Section 1

Definitions

TermDefinition
ControllerThe customer — the natural or legal person, agency, or body that determines the purposes and means of processing Personal Data.
ProcessorVulos Labs (Pty) Ltd, operating vulos.cloud — processes Personal Data on behalf of the Controller under this DPA.
Data SubjectAn identified or identifiable natural person whose Personal Data is processed.
Personal DataAny information relating to an identified or identifiable natural person.
ProcessingAny operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or erasure.
Sub-ProcessorA third party engaged by Vulos to assist in processing Personal Data on behalf of the Controller. See /legal/subprocessors.
Applicable LawPOPIA (South Africa), GDPR (EU/EEA), UK GDPR, CCPA (California) — as applicable to the Controller's jurisdiction.

Section 2

Roles and Responsibilities

The customer acts as the Controller. Vulos acts as a Processor when handling Personal Data that the customer stores in, transmits through, or generates within the Vulos platform. Vulos does not sell Personal Data and does not process it for its own commercial purposes.

The Controller is responsible for ensuring a lawful basis for processing exists, for providing required notices to Data Subjects, and for configuring Vulos features (access controls, retention periods, bucket region) to meet applicable obligations.

Section 3

Processing Instructions

Vulos processes Personal Data only on documented instructions from the Controller, which includes the Vulos Terms of Service, this DPA, and in-product configuration. Vulos will inform the Controller if it believes an instruction infringes Applicable Law.

Vulos personnel with access to Personal Data are subject to confidentiality obligations. Vulos will not disclose Personal Data to third parties except as required by Applicable Law (in which case Vulos will notify the Controller unless legally prohibited) or as necessary to provide the service via authorised Sub-Processors.

Section 4

Security Measures

Vulos implements and maintains appropriate technical and organisational measures to protect Personal Data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 via bucket provider)
  • Per-tenant data isolation — customer data is stored in logically separated buckets
  • TOTP 2FA and passkey authentication on all control-plane accounts
  • Session registry with individual session revocation
  • HIBP breach detection on password changes
  • Append-only audit log of admin actions and login events (shipped to retention bucket)
  • Regular security reviews; vulnerability disclosure policy at vulos.org/security

Vulos will notify the Controller without undue delay (and within 72 hours where required by GDPR/POPIA) after becoming aware of a Personal Data breach affecting the Controller's data.

Section 5

Sub-Processors

Vulos engages Sub-Processors to deliver the service. The current authorised Sub-Processor list is maintained at /legal/subprocessors. Vulos provides 30-day advance notice of any addition or material change to the Sub-Processor list (see Section 6). By accepting this DPA, the Controller provides general authorisation for Vulos to engage Sub-Processors subject to the notice mechanism.

Vulos imposes data-protection obligations on Sub-Processors equivalent to those in this DPA and remains liable to the Controller for Sub-Processor compliance.

Section 6

Sub-Processor Change Notice (30 Days)

When Vulos intends to add a new Sub-Processor or materially change an existing one, Vulos will publish the change at /legal/subprocessors and send notice to the Controller's registered account email at least 30 days before the change takes effect.

If the Controller objects on data-protection grounds, the Controller must notify Vulos within the 30-day window. Vulos will work in good faith to resolve the objection. If no resolution is possible and the Controller cannot accept the change, the Controller may terminate the service on reasonable notice before the effective date without penalty.

Section 7

Data Subject Rights

Vulos will assist the Controller in responding to Data Subject requests (access, rectification, erasure, portability, restriction) to the extent technically feasible. The Controller is responsible for managing Data Subject rights directly where the data is within the Controller's instance or bucket.

Vulos provides data portability by design: customer data is stored in standard formats in the customer's own bucket; egress via Tigris Object Storage is free. Vulos does not impose lock-in at the data layer.

Section 8

Data Retention and Deletion

Upon termination of service, Vulos will retain Customer Personal Data in the customer's bucket for 30 days post-termination, after which Vulos will delete or anonymize all copies accessible to it. The customer may export their data at any time during or after this period (bucket access credentials remain valid for the 30-day window).

Audit logs stored in the retention bucket are retained for the period required by Applicable Law or as configured by the Controller.

Section 9

International Data Transfers

Vulos supports per-org data residency (see COMPLY-01). Where the Controller selects a specific bucket region (af-south / eu-west / us-east), Vulos stores and processes that data in that region. Control-plane metadata (account credentials, billing records) is processed in the region where the Vulos control plane is deployed.

For transfers of EU/EEA Personal Data to countries without an adequacy decision, Vulos relies on Standard Contractual Clauses (Module 2: Controller-to-Processor) incorporated by reference into this DPA.

Section 10

Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Vulos Terms of Service. Nothing in this DPA restricts either party's liability to a Data Subject or a supervisory authority as required by Applicable Law.

Section 11

Governing Law

This DPA is governed by the laws of the Republic of South Africa. Disputes are subject to the exclusive jurisdiction of the courts of South Africa, except where Applicable Law requires otherwise (e.g., GDPR supervisory authority in the Controller's EU member state).


Acceptance

Sign this DPA

Acceptance is recorded per account. At checkout, acceptance of the Terms of Service and this DPA is bundled. You may also accept here directly.

Accept the Standard DPA

By checking the box and clicking Accept, you confirm that you are authorised to bind your organisation and that your organisation agrees to the terms of this DPA (version 1.0). This acceptance is tied to your Vulos account.


Enterprise

Need a redlinable MSA?

Enterprise customers only

On the Enterprise tier, Vulos provides a Master Services Agreement (MSA) that can be redlined. This covers custom DPA terms, dedicated SLAs, named CSM, and optional HIPAA/PCI scope documentation. Standard (SMB/Pro/Team) customers use this DPA without modification.

Contact legal@vulos.org

Related: Sub-Processor List with 30-day change notice · privacy@vulos.org for data-protection inquiries.