Data processing agreement
Version 1.0 Effective 7 October 2026
Deploy is a product of Vimonto. These documents are an agreement between you and Vimonto.
Our legal documents are available in English only. The English text is the one that applies.
This Data Processing Agreement (“DPA”) forms part of the Deploy subscription agreement between the Customer identified in the accepted order and Luuk Dahlmans, trading as Vimonto, Echterstraat 85, 6051 EZ Maasbracht, the Netherlands, Chamber of Commerce number 74936719 (“Vimonto”). It applies whenever Vimonto processes Customer Personal Data on the Customer’s behalf through Deploy.
1 Scope and roles
“Customer Personal Data” means personal data processed by Vimonto on the Customer’s instructions to provide Deploy, including personal data accessed on customer infrastructure or contained in deployment material. “Data Protection Law” means the GDPR and other data protection laws applicable to the relevant processing. Terms such as controller, processor, personal data breach and processing have their GDPR meanings.
Where the Customer determines the purposes and means of the relevant processing, the Customer is the controller and Vimonto is its processor. If the Customer is itself a processor, Vimonto is its subprocessor; references to the Customer’s controller obligations apply to the extent of its role, and the Customer warrants that the relevant controller authorised this appointment and the instructions. Vimonto’s statutory responsibilities remain unchanged.
Personal data that Vimonto processes for its own account administration, billing and legally justified platform security purposes falls under its Privacy Policy. This does not permit Vimonto to relabel project content as its own controller data to avoid this DPA.
2 Instructions and lawful processing
Vimonto shall process Customer Personal Data only on documented instructions, including instructions about international transfers, to deliver the service described in Annex 1. The agreement, chosen settings, authorised API requests, scheduled jobs and documented support requests constitute instructions. Additional instructions may be given by an authorised contact in writing.
Where EU or Member State law requires processing beyond those instructions, Vimonto shall notify the Customer before processing unless that law prohibits notice on important public-interest grounds. A demand under another country’s law does not automatically override this DPA or GDPR transfer requirements.
Vimonto shall immediately inform the Customer if it believes an instruction infringes Data Protection Law. It may pause the affected operation while the parties resolve the concern, without unnecessarily interrupting unrelated lawful processing.
The Customer shall establish the necessary lawful basis, provide required notices, obtain any required consent or client authorisation, give lawful instructions, and avoid collecting or exposing unnecessary data. Vimonto shall not sell Customer Personal Data, use it for advertising or train general-purpose AI models on it, and shall not authorise its processors to use that data for those purposes. For AI and support processing, Vimonto shall apply appropriate service terms, account settings and route restrictions to give effect to these limits. Customer access secrets shall not be included in model context merely because Deploy stores them. Any genuinely new processing purpose requires a separate lawful arrangement.
3 Confidentiality and security
Vimonto shall restrict access to authorised persons who need it for the service and are bound by contractual confidentiality or an appropriate statutory duty. Access shall be removed when no longer needed.
Vimonto shall implement and maintain appropriate technical and organisational measures under Article 32 GDPR, taking account of the state of the art, implementation costs, processing context and risks to individuals. Annex 2 specifies the agreed measures. Vimonto may improve or replace individual measures without materially reducing the overall protection. A material reduction requires prior agreement where necessary to maintain the agreed level of protection.
The Customer shall implement the customer-side measures in Annex 2. Allocation of those tasks does not remove Vimonto’s responsibility for the systems and processing under its control.
4 Subprocessors
The Customer grants general written authorisation for the subprocessors identified in the completed Annex 3 at acceptance. Vimonto shall give at least 30 days’ written notice before a proposed addition or replacement gains access to Customer Personal Data. The notice shall identify the legal entity, purpose, processing locations, relevant data and transfer safeguards.
The Customer may object within that period on reasonable data protection grounds. The parties shall work in good faith on an alternative, additional safeguards or another solution. Vimonto shall not give the proposed subprocessor access to the objecting Customer’s data until the objection is resolved. If no reasonable solution is available, either party may end the affected service before the change takes effect, with a proportionate refund of unused prepaid fees and the agreed export arrangements.
The Customer may also give specific informed written or electronic authorisation for an identified additional provider, for example an AI model provider selected for a requested task. The relevant legal entity, role, location and safeguards must be supplied before that authorisation, and a model brand alone is insufficient where the inference operator is different. An automatic fallback does not authorise an undisclosed recipient. Processing shall not begin if the required information, authorisation or safeguards are absent.
Before a subprocessor processes data, Vimonto shall enter a written agreement imposing materially equivalent data protection obligations appropriate to its task, including sufficient security guarantees. Vimonto remains fully liable to the Customer for the subprocessor’s performance of those obligations as required by Article 28(4) GDPR.
A cloud provider independently contracted by the Customer is not automatically Vimonto’s subprocessor merely because Deploy connects to it. Actual contractual arrangements and processing roles determine the classification.
5 International transfers
Vimonto shall process data only in the locations recorded in Annex 3 or otherwise authorised through the procedure above or a specific documented instruction. Remote access from another country is included when assessing transfers.
Vimonto shall not make a restricted transfer without a valid mechanism under applicable Data Protection Law. This may include an applicable adequacy decision or properly completed European Commission Standard Contractual Clauses, accompanied by a transfer assessment and supplementary measures where necessary. The relevant module must reflect the parties’ actual roles. Appropriate UK or Swiss provisions must be added before transfers requiring them take place.
This DPA is not itself a completed set of international transfer clauses. Vimonto shall provide information about the applicable safeguard and a copy on request, subject to necessary redaction. Mandatory transfer clauses prevail over conflicting terms in this DPA. A transfer mechanism must be reviewed if its validity or suitability changes; processing shall be suspended or adjusted if no lawful alternative is available.
6 Assistance and requests
Taking account of the nature of the processing, Vimonto shall assist the Customer with appropriate measures to respond to requests for access, correction, erasure, restriction, objection and portability. It shall forward a request concerning Customer Personal Data without undue delay and shall not respond substantively unless instructed or legally required.
Taking account of the information available to it, Vimonto shall assist the Customer with security obligations, breach assessments and notifications, data protection impact assessments and prior consultation under Articles 32 to 36 GDPR. The Customer remains responsible for decisions allocated to its role, including notices to individuals and authorities.
Routine compliance assistance is included. Substantial bespoke work may be charged at a reasonable rate agreed in advance, except work required to remedy Vimonto’s own breach. Fees or commercial disagreement shall not obstruct a statutory obligation, an urgent response or a legally required audit.
7 Personal data breaches
Vimonto shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. It shall send the notice to the designated security contact or, if none has been supplied, the account owner’s email address. It shall not wait for a completed investigation before sending the initial notice.
To the extent available, the notice shall explain the breach, categories and approximate numbers of affected people and records, likely consequences, measures taken or proposed, and a contact for further information. Vimonto may provide information in stages as it becomes available without undue further delay.
Vimonto shall take reasonable steps to contain, investigate and remediate the breach, preserve relevant evidence, and cooperate with the Customer’s assessment and notifications. Notification is not an admission of liability. Vimonto shall not notify the Customer’s data subjects or issue a public statement identifying the Customer without consultation, unless law requires otherwise.
8 Information and audits
Vimonto shall make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. It shall permit and contribute to audits, including inspections, by the Customer or an independent auditor it appoints.
Audits shall normally begin with relevant documentation and remote enquiries, followed by inspection where needed. The parties shall agree reasonable notice, confidentiality and security arrangements that protect other customers and avoid unnecessary disruption. These arrangements shall not prevent a meaningful audit. Shorter notice or additional audits shall be allowed where an incident, credible compliance concern or competent authority requires them. A blanket annual limit does not apply to such circumstances.
Each party normally bears its own participation costs. Vimonto bears reasonable additional costs caused by its material non-compliance. No charge may defeat the Customer’s statutory audit rights. Vimonto shall address substantiated findings within a reasonable period appropriate to their risk.
9 Return and deletion
At the Customer’s choice, Vimonto shall return Customer Personal Data in an accessible, commonly used electronic format and then delete it, or delete it without return, following the end of processing services. Export, transition and retrieval periods are described in the Data Export and Switching Policy. A valid earlier deletion instruction shall be honoured where lawful and technically applicable; the parties shall coordinate it with any remaining export request.
After the agreed retrieval period ends, active copies shall be deleted without undue delay, ordinarily when that period ends. Residual backup copies shall be deleted or rendered irrecoverable within 90 days after deletion from active systems. During that limited period they shall be isolated from ordinary use, protected by this DPA and restored only for disaster recovery, with deletion instructions reapplied. Backup retention is limited to what the recovery architecture reasonably requires within that maximum and does not create an unrestricted right to retain data. Merely returning from Premium to the Free plan does not terminate processing needed to supply that continuing Free account. A customer may separately instruct closure, return or deletion.
Where EU or Member State law requires continued storage, Vimonto shall identify the applicable requirement to the Customer unless prohibited, restrict processing to that requirement and delete the data when it expires. Vimonto shall confirm completion of deletion on reasonable request.
This process concerns copies under Vimonto’s or its subprocessors’ control. It does not delete resources in the Customer’s independent cloud accounts unless separately instructed. The Customer must revoke connected credentials and manage its own retained copies.
10 Liability and duration
The liability provisions in the Terms apply between the parties to the extent lawful, without limiting individuals’ rights, regulators’ powers or statutory liability and recourse under Article 82 GDPR. No provision excuses a party from its own Data Protection Law obligations.
This DPA takes effect with acceptance of the agreement and continues while Vimonto or its subprocessors hold Customer Personal Data. Necessary confidentiality, security, audit and deletion obligations survive termination. Dutch law and the dispute provisions in the Terms apply except where mandatory law or applicable transfer clauses require otherwise.
Annex 1 Processing details
| Item | Agreed description |
|---|---|
| Subject matter | Remote server administration and application deployment through Deploy, including selected integrations, instructed AI operations and authorised support |
| Duration | The subscription, any agreed transition and retrieval period, and the limited deletion period in section 9 |
| Nature of operations | Receiving and storing configuration and operational information; accessing systems; executing authorised deployment and administration tasks; transmitting commands and results; retrieving and displaying logs; troubleshooting; returning and deleting data. Platform backups cover Deploy management data. Customer application repositories, databases and application backups are not copied to Vimonto infrastructure as part of the service; they remain with the Customer or its independent providers. Authorised remote operations can still access their contents, and customer-submitted prompts, logs or tickets can include extracts |
| Purpose | Providing the server and deployment operations requested by the Customer and the necessary security and support for those operations |
| Categories of people | Customer staff, contractors and client personnel; repository contributors; application users, customers and visitors whose personal data is encountered during authorised operations |
| Types of personal data | Names, contact details, usernames, author identifiers, IP addresses, timestamps, operational and error records, management configuration, prompts, relevant AI responses and support extracts. SSH keys, API tokens and environment values are included where they are personal data or enable access to it. Remote operations may access personal data on connected servers without retaining a hosted repository or database copy |
| Frequency | Continuous while connected features run, or intermittent and event-based for manual actions, deployments, scheduled jobs and support |
| Sensitive data | No intended routine ingestion of special-category or criminal-offence data. Before connecting a workload that requires Vimonto to process such data, the Customer must obtain a written agreement covering its categories, legal basis, risks and additional safeguards. General privileged server access must be considered in that assessment even if data is not copied into Deploy |
| Controller rights and obligations | Determining lawful purposes, categories, retention and instructions; authorising processors; responding to individuals; exercising information, audit, return and deletion rights under this DPA |
| Customer identity and contacts | The legal name, address, authorised representative and email in the accepted order; the security contact designated in the account or, if none is designated, the account owner’s email |
| Vimonto contact | info@vimonto.nl; postal details above |
Annex 2 Technical and organisational measures
The following measures apply to Deploy’s management platform. They are proportionate safeguards and contractual commitments, not certifications or a guarantee that every incident will be prevented.
- Access. Restrict production access to authorised persons with a task-related need, use individual accounts and MFA for privileged access, and remove permissions when no longer needed. Apply customer and project authorisation checks to dashboard, API and background operations.
- Connections. Use HTTPS for dashboard and API communication and encrypted authenticated connections for remote server administration. Protect authentication credentials against unauthorised use.
- Secrets. Encrypt stored SSH private keys, API tokens and secret configuration values; restrict access to the keys and systems needed to decrypt them. Avoid placing reusable secrets in ordinary logs, analytics, prompts or support tools. Revoke or remove obsolete connection credentials through the agreed disconnection process.
- Logging. Maintain security and operational logging proportionate to the risk, restrict access to it, and apply the 90-day ordinary log-retention limit. Necessary incident extracts can be preserved separately with a documented purpose and access restriction.
- Maintenance and tests. Maintain the platform, assess security-relevant updates and defects according to risk, and use automated unit tests to support development. Unit testing is not represented as a penetration test or proof that backups have been successfully restored.
- Platform backups. Back up the Deploy data needed for platform recovery using EU-hosted Hetzner infrastructure and protect backup access. Isolate expired data from ordinary use and remove residual copies within 90 days of active deletion. Periodically assess recovery arrangements as part of evaluating security effectiveness; no quantified recovery target is promised.
- AI and support. Limit shared information to the authorised purpose, minimise or redact unnecessary personal data and secrets, and use processor agreements, transfer safeguards and provider/account settings appropriate to the data. Do not use a route or support account that cannot meet the DPA for Customer Personal Data. Disclose and authorise the actual model recipient before transmission.
- People and suppliers. Require confidentiality from authorised personnel and appropriate privacy and security obligations from suppliers. Review material changes and do not give new subprocessors access before the authorisation procedure has been satisfied.
- Incident response and rights. Investigate relevant incidents, contain and remediate them, notify the Customer without undue delay when required, and provide the assistance, information, audits and return/deletion arrangements described above.
- Lifecycle and review. Apply data minimisation and retention controls, evaluate their effectiveness at appropriate intervals and after material incidents or changes, and keep processing and access records where law requires them.
- Customer responsibilities. Protect customer devices and credentials, configure appropriate permissions, minimise information in logs and prompts, maintain independent administrator access and independent application/database backups, and verify important scripts and AI-generated operations before use.
Annex 3 Providers and processing locations
Version 1.0 dated 7 October 2026 of the Subprocessors and Service Providers register forms this annex, together with processing-specific supplier and AI-route information supplied before authorisation. The register identifies hosting, email, support and AI providers and distinguishes independent controllers from processors. The exact legal entity and relevant location and transfer information must be provided for the processing entrusted to it; a generic supplier category alone does not authorise an unidentified processor.
The Deploy application, management database and platform backups are hosted in Hetzner EU datacentres. External email, support and AI services can involve processing outside the EEA and require the safeguards in section 5. The DPA does not promise that every third-party activity takes place in the EU. Later provider changes follow section 4; publication of a revised page alone is insufficient.