Data Processing Addendum
Last updated 25 July 2026
This addendum applies where you use Vault to process personal data for which you are the controller under the GDPR, UK GDPR or comparable law — for example, an organisation whose staff store work credentials in Vault. It forms part of the Terms of Service. It is offered as published standard terms; a counter-signed copy is available on request to founder@dfacto.ai.
Roles
For vault contents, you are the controller and we are — at most — a processor with no access. We never receive vault data in readable form, hold no key to it, and operate no server that stores it. For the account data we hold to run your subscription (email address, licence identifier, purchase history, support correspondence), we act as controller and the Privacy Policy governs.
Subject matter and scope
- Nature and purpose: providing a zero-knowledge password manager, an optional revision-notification relay and an optional public-key sharing directory.
- Duration: for as long as your subscription is active, plus any statutory retention period for billing records.
- Data subjects: your authorised users.
- Categories of data we can access: account email addresses, licence identifiers, purchase history, support correspondence, and — where sharing is used — user identifiers and public keys. Not vault contents, which are ciphertext to us.
Our obligations
- Process personal data only on your documented instructions, including for transfers.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organisational measures — described on the security page. The primary measure is architectural: we hold no vault data and no key to it, so it cannot be exposed by a compromise of ours.
- Assist you with data subject requests, security, breach notification and DPIAs, taking into account the nature of the processing and the fact that we cannot access vault contents.
- Notify you without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting data we process for you.
- Delete or return the account data we hold on termination, except where law requires retention. We cannot delete or return vault data, because we never held it.
- Make available the information reasonably necessary to demonstrate compliance.
Sub-processors
You give general authorisation for the sub-processors listed on the subprocessors page. We will give notice before adding or replacing one, and you may object on reasonable data-protection grounds, in which case you may terminate the affected service.
Transfers
Where account data is transferred out of the EEA, UK or Switzerland, the transfer relies on the EU Standard Contractual Clauses and the UK Addendum, incorporated here by reference. Vault contents are never transferred to us at all.
Audits
We will respond to reasonable written information requests to verify compliance. We are a sole proprietorship and do not hold a SOC 2 report, an ISO 27001 certificate, or an independent security audit, and we will not imply otherwise.
Liability
Liability under this addendum is subject to the limitations in the Terms of Service, except where applicable data protection law does not permit it.