Data processing agreement
The Article 28 terms for customers who use Veyra to reach people. You stay the controller, Veyra processes on your instructions, and this sets out exactly what that means.
Last updated 19 August 2026
This document is maintained in English.
What this document is
Veyra contacts people on your behalf, which means it processes personal data that you decide the purpose of. Article 28 of the GDPR requires that relationship to be governed by a written agreement. This page is that agreement, in the form we intend to offer it, and it forms part of the terms of service for every customer who uses Veyra to run outreach.
If your procurement process needs a signed copy, or your own template, write to hello@veyrareach.com and we will work from yours.
Roles
You are the controller. You decide who is contacted, why, and what is said, by defining the ideal customer profile and the voice examples that Veyra runs inside.
Veyra is the processor. It acts on your instructions and does not decide the purposes of the processing. Where Veyra processes data about you, rather than about your prospects, it is a controller in its own right and the privacy policy governs that instead.
Subject matter, duration, nature and purpose
- Subject matter. Processing of personal data contained in the market sweep, the scored pipeline and the outreach Veyra runs for you.
- Duration. For as long as your subscription is active, plus the deletion window set out below.
- Nature and purpose. Collecting business contact data from public and licensed sources, scoring it against your profile, generating and sending outreach, running follow-ups, classifying replies, and booking meetings.
- Categories of data subject. Employees and representatives of the companies in your target market, acting in a professional capacity, and the users you give access to your account.
- Categories of personal data. Business contact data: name, role, employer, business email address, business phone number and public professional signals. Message content and reply content. Account data for your own users. No special categories of personal data are processed, and no profiling of a person's private life is carried out.
Processing on documented instructions
Veyra processes personal data only on your documented instructions, which are given through the terms of service, this agreement, and the configuration you set inside the product: your ideal customer profile, your channel rules, your voice examples and your suppression lists.
If we believe an instruction breaches data protection law, we will tell you and may pause that processing until it is resolved.
Confidentiality
Everyone we allow to process your data is bound by an appropriate duty of confidentiality, and only the people who need access to run the service have it.
Security measures
We take appropriate technical and organizational measures to protect personal data. What that means in practice today: access to production limited to those who need it, encryption in transit, payment data never touching our systems because card entry happens inside Stripe, secrets held server side only, and abuse protection on the public endpoints.
The measures are listed in full in the annex below, which is the version we will warrant in a signed copy. They describe what is in place today rather than an aspiration, and they change as the service does, which is why the annex carries the date it was last reviewed.
Sub-processors
You give general authorization for Veyra to engage sub-processors. Every current sub-processor is named on the sub-processors page, with what it does and what data it can touch. Each one is bound by written terms no less protective than these.
Before a new sub-processor starts processing your data we will update that page and notify you by email at the address on your account, 30 days before the change takes effect. You may object in writing within that window on reasonable data protection grounds. We will try to meet the objection by keeping your data off that processor, and where that is not possible you may cancel before the change takes effect, with the unused part of any prepaid term refunded.
Helping you answer data subjects
People whose data you process can ask you for access, correction, deletion, restriction, portability, or to object. Veyra gives you the tooling to answer them, and where a request reaches us directly we forward it to you rather than answering for you.
Opt-out requests are a special case and are not queued: when Veyra learns of one it is honored everywhere, immediately, and that person is suppressed across every channel and every future sweep.
Personal data breaches
If we become aware of a personal data breach affecting your data we will notify you without undue delay, with what we know about the nature of the breach, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. We will keep you updated as the picture clarifies, and help you meet your own notification duties.
We will tell you about a personal data breach affecting your data within 48 hours of becoming aware of it, without waiting until the picture is complete. The first notice says what we know, what we do not know yet, and what we are doing about it, and it is followed by updates as the position clarifies. Notice goes by email to the address on your account, so keep an address that somebody reads. Write to hello@veyrareach.com to nominate a different security contact, and we will use that instead.
Return and deletion
When your subscription ends you can export your data. After that, we delete it or return it at your choice, except where law requires us to keep a copy, in which case we keep only what is required and continue to protect it.
When a subscription ends you have 30 days to export your data, and we will help if the volume makes that awkward. At the end of that window the live records are deleted. Encrypted backups holding the same data are overwritten on a 90 day rotation, so a deleted record is gone from backups within 90 days of deletion at the latest. We do not keep a copy for our own purposes, and nothing is retained to train anything.
Information and audits
We will give you the information you reasonably need to demonstrate that we meet Article 28, and allow an audit or inspection carried out by you or an auditor you mandate, on reasonable notice, no more than once a year unless an incident or a regulator requires otherwise.
We hold no independent certification today. There is no ISO 27001 certificate and no SOC 2 report, and we would rather say so than imply one with a badge. What we offer instead is the written description of measures in the annex below, answers to a security questionnaire in writing, and a call with the people who actually run the infrastructure. If a certification becomes necessary for your procurement, tell us: it is a question of when it is worth the cost, not of whether we would refuse.
International transfers
Veyra is built and hosted in the EU, and your pipeline data is processed there. Where a sub-processor processes personal data outside the EEA, that transfer is covered by the European Commission standard contractual clauses and any supplementary measures a transfer impact assessment calls for.
The application, the database and the market sweep run on hardware we own and operate in Portugal, so the processing itself does not leave the EEA. The encrypted off-site backup sits in a European region of Google Cloud Storage, also inside the EEA.
Four sub-processors can involve processing outside the EEA, and each is covered by the European Commission standard contractual clauses: Stripe for payments, Cloudflare for bot protection, Resend for our own transactional mail, and Anthropic for drafting. WhatsApp messages reach recipients over Meta's platform, which also processes outside the EEA under the same clauses. Where a transfer happens we rely on those clauses together with the technical measures in the annex, principally encryption in transit and at rest and sending the minimum data the task needs.
Liability and term
This agreement runs for as long as Veyra processes personal data on your behalf. It is governed by the same law as the terms of service, and liability under it is subject to the same limits.
Liability under this agreement is the liability set out in the terms of service, and the cap there applies to both taken together rather than separately. Nothing in this agreement limits liability that cannot lawfully be limited, and neither of us can contract away what the GDPR places directly on a controller or a processor.
Annex: details of the processing
The subject matter, duration, nature, purpose, categories of data subject and categories of personal data set out above form this annex. It is written to be dropped into a signed copy without rewriting.
Annex: technical and organizational measures
This is the annex most security reviews read first, so it is written as description rather than reassurance. Every measure below is one we operate today.
Physical security. The application and its database run on hardware we own, in a facility we control, rather than on rented capacity. Physical access is limited to the people who operate it.
Encryption. Data is encrypted in transit using current TLS. Backups are encrypted at rest before they leave our facility for the off-site copy. Card details are never encrypted by us because they are never held by us: entry happens inside Stripe.
Access control. Production access is limited to the people who need it to run the service, is individually attributed rather than shared, and is reviewed when somebody's role changes. Application secrets are held server side only and are never shipped to a browser.
Logging and monitoring. Request and access logs are kept for security and troubleshooting, and sending reputation is monitored continuously with automatic pausing when it degrades.
Backup and restore. Backups run on a schedule to encrypted off-site storage in a European region, on a 90 day rotation. Restores are tested rather than assumed, because a backup nobody has restored is a hope rather than a control.
Secure development. Changes are reviewed before they reach production, dependencies are kept current, and the public endpoints carry bot protection and rate limiting.
Personnel. Everyone with access is bound by a confidentiality obligation that survives the end of their engagement, and access is removed when it ends.
Incident response. There is a named route for reporting a suspected incident, a defined path for assessing it, and the notification commitment set out above.
Last reviewed 19 August 2026.
Annex: sub-processors
The current list lives on the sub-processors page and is maintained there rather than restated here, so that a signed copy never falls out of date with the live list.
How to put this in place
Write to hello@veyrareach.com with the legal entity name and address of the controller, and we will return a countersigned copy. If your legal team needs to work from your own template, send it over and we will review it rather than insist on ours.
The rest of the legal set
Send us your paper
If your legal team works from its own template, we would rather review yours than argue for ours.