Legal
Data Processing Agreement (DPA)
Last updated: 13 June 2026 Effective date: 4 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Rocket Venture Labs B.V. ("Voris", "Processor") and the customer ("Customer", "Controller") and applies to the processing of personal data by Voris on the Customer's behalf in connection with the Voris analytics platform (the "Service").
Where Voris processes personal data on the Customer's instructions, the Customer is the controller and Voris is the processor under Article 28 GDPR.
1. Subject matter and duration#
Voris processes personal data to provide website and app analytics to the Customer. Processing lasts for the term of the Customer's subscription and ends when the Service relationship ends, subject to the deletion terms in Section 8.
2. Nature and purpose of processing#
Collecting, validating, enriching (coarse geolocation and device parsing), storing, aggregating, and presenting analytics events generated on the Customer's websites or apps, and generating optional AI summaries from aggregated statistics.
3. Categories of data subjects#
Visitors to, and users of, the Customer's websites and applications.
4. Categories of personal data#
The categories depend on the privacy mode the Customer configures per site:
- Mode A (default): no personal data is stored, only anonymous, aggregated counts, coarse location, device/browser categories, page paths, referrers, and UTM parameters. IP addresses are used transiently to derive location and are never stored.
- Mode B: the above, plus a short-lived, server-side pseudonymous
visitor_idderived from a daily secret that is destroyed after 48 hours. - Mode C: the above, plus an opaque
user_idsupplied by the Customer.
No special-category data (Article 9 GDPR) is intended to be processed. The Customer must not send personal data in custom event properties or in tracked URLs.
5. Obligations of Voris (Processor)#
Voris will:
- Process personal data only on the Customer's documented instructions (including those given through the Service configuration), unless required by EU or Member State law;
- Ensure persons authorized to process the data are bound by confidentiality;
- Implement appropriate technical and organizational measures (Section 9);
- Respect the conditions for engaging sub-processors (Section 6);
- Assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations under Articles 32–36 GDPR;
- Delete or return personal data at the end of the relationship (Section 8);
- Make available information necessary to demonstrate compliance and allow for audits (Section 7);
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data.
6. Sub-processors#
The Customer provides general authorization for Voris to engage sub-processors. Voris imposes data-protection obligations on each sub-processor that are no less protective than this DPA. Current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger | Hosting / virtual servers | EU |
| Bunny CDN | Content delivery, edge geolocation header | Global edge network |
| MaxMind | Geo-IP lookup (fallback) | United States |
| Paddle | Billing / payments (Merchant of Record) | EU / global |
| Resend | Transactional email (login links, digests) | United States |
| Anthropic | AI digest generation (aggregated, non-personal data only) | United States |
Voris will inform the Customer of intended changes to sub-processors, giving the Customer a reasonable opportunity to object.
7. Audits#
Voris will make available to the Customer information necessary to demonstrate compliance with Article 28 GDPR and will contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality and scheduling arrangements.
8. Return and deletion#
On expiry or termination, Voris will delete the Customer's personal data within the retention periods configured for each site (default 365 days, hard maximum 3 years), or sooner on the Customer's request, except where storage is required by EU or Member State law (for example, financial records retained for 7 years). The Mode B daily salt is destroyed within 48 hours regardless of account status.
9. Security measures#
Voris implements measures appropriate to the risk, including:
- Privacy by design, Mode A stores no personal data; IP addresses are never stored; AI features never read raw event data;
- Encryption in transit;
- Strict tenant isolation, every query is scoped to the authenticated Customer's data;
- Access control on a least-privilege basis;
- Monitoring and logging of background processing and failures.
10. International transfers#
Where Voris or a sub-processor processes personal data outside the EEA, the transfer is made under an appropriate safeguard in Chapter V GDPR, primarily the European Commission's Standard Contractual Clauses, incorporated by reference , together with supplementary measures where required. Given the design of the Service, data transferred to non-EEA sub-processors is minimized and, for analytics, typically not personal data.
11. Liability and order of precedence#
This DPA is subject to the liability provisions of the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
12. Governing law#
This DPA is governed by the laws of the Netherlands, consistent with the Terms of Service.
13. Contact#
Data-protection matters under this DPA: legal@voris.ai
Rocket Venture Labs B.V., Plantage Middenlaan 42 A, 1018 DH Amsterdam, the Netherlands.