Vesence Data Processing Agreement

Version 1.1.0 · Effective 2 October 2026

This DPA forms part of the Vesence Terms of Service for the Service, comprising the workspace at desktop.vesence.com, the Vesence desktop app and related features and support. It applies automatically when a Customer accepts the Terms, through any Order, online or signed. No separate signature is needed. The Vesence add-ins for Microsoft Word, Excel, PowerPoint and Outlook, and the web application at app.vesence.com, remain subject to their separate data processing agreement.

Vesence AB, reg. no. 559456-6902 ("Vesence"), and the Customer named in the Agreement ("Customer"). Capitalized terms not defined here have the meaning given in the Terms.

1. Scope and roles

1.1 This DPA applies to personal data in Customer Content that Vesence processes for the Customer in providing the Service ("Customer Personal Data").

1.2 The Customer is the controller and Vesence is the processor. Where the Customer acts as a processor for its Affiliates or clients, Vesence is its sub-processor, and the Customer remains Vesence's single point of contact.

1.3 Vesence is an independent controller of account, billing and usage data that it processes for its own purposes. The Privacy Notice describes that processing. This DPA does not cover it.

1.4 "Data Protection Law" means the GDPR (Regulation (EU) 2016/679), the Swedish Data Protection Act, and, where they apply, the UK GDPR, the Swiss Federal Act on Data Protection, and US state privacy laws. Terms such as "controller", "processor", "personal data breach" and "processing" have the meanings given in the GDPR.

1.5 For content in a shared drive, Vesence acts as processor for the drive's Host Customer (Terms clause 5.6). A Customer whose Users add content to another Customer's shared drive discloses that content to the Host Customer, which receives it as an independent controller.

2. Customer's obligations

2.1 The Customer confirms that it has a lawful basis for the processing, and has given any notices and obtained any consents needed, for Vesence to process Customer Personal Data under the Agreement.

2.2 The Customer is responsible for the accuracy and lawfulness of Customer Personal Data. It is also responsible for its configuration choices, including its choice of primary region, the AI models it enables, the Connected Services it connects, and with whom Users share content.

3. Vesence's obligations

3.1 Instructions. Vesence processes Customer Personal Data only on the Customer's documented instructions. These instructions are the Agreement, the Customer's configuration of the Service, and the actions Users take in it. The only exception is processing that EU or Member State law requires. In that case Vesence tells the Customer first, unless the law prohibits it. Vesence will inform the Customer if it believes an instruction infringes Data Protection Law.

3.2 Confidentiality. Vesence ensures that personnel authorized to process Customer Personal Data are bound by confidentiality. Personnel access Customer Content only as clause 9.7 of the Terms allows.

3.3 Security. Vesence implements the measures in Annex 2, as Article 32 GDPR requires. Vesence may update those measures, but will not materially reduce the overall level of protection.

3.4 No training. Vesence does not use Customer Personal Data to train AI models, and it contractually prohibits its subprocessors from doing so.

3.5 Assistance. Taking into account the nature of the processing, Vesence assists the Customer with data subject requests (section 6). It also assists with the Customer's obligations under Articles 32–36 GDPR, including impact assessments and prior consultations.

4. Personal data breaches

4.1 Vesence notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

4.2 The notice describes, as far as is then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Vesence provides further information as it becomes available, and investigates and remedies the breach.

4.3 Notifying a breach is not an admission of fault. If a breach is caused by the Customer or its Users, Vesence still informs the Customer, but may charge for assistance beyond that.

5. Audits

5.1 On request, Vesence makes available the information needed to demonstrate compliance with this DPA. This includes its security documentation and any third-party audit reports it holds.

5.2 If that information is not enough, the Customer may audit Vesence once a year, or after a personal data breach. Audits may be carried out by the Customer or by an independent auditor bound by confidentiality, with 30 days' notice, during business hours, and at the Customer's cost. The audit may not compromise other customers' data or Vesence's security. Audits of subprocessors are carried out through their own audit reports.

6. Data subject requests

If Vesence receives a request from a data subject about Customer Personal Data, it refers the requester to the Customer and does not respond itself, unless the law requires it. Users can delete chats and files in the Service. As set out in clause 14.6 of the Terms, an administrator may request an export, by emailing support@vesence.com, during the Agreement or within 30 days after termination. Vesence provides the export within 30 days after receiving the request and carries out requested deletion from active systems within 30 days after receiving the request, subject to completing any timely requested export before deletion. Backup deletion follows the separate period in clause 14.6 of the Terms.

7. Subprocessors

7.1 The Customer gives general authorization for Vesence to engage subprocessors. The current list is at vesence.com/legal/subprocessors. Each subprocessor is bound by data protection obligations that are at least as protective as this DPA. Vesence remains liable for its subprocessors.

7.2 Vesence gives at least 30 days' notice before a new subprocessor starts processing Customer Personal Data. It does so by updating the list and by emailing the Workspace's account owner. Exceptions are emergencies needed to keep the Service secure or available. In those cases Vesence gives notice as soon as possible.

7.3 The Customer may object on reasonable data protection grounds within that notice period. The parties will discuss the objection in good faith. If Vesence cannot offer a reasonable alternative, the Customer may terminate the affected subscription and receive a refund of prepaid Fees for the remaining period.

8. International transfers

8.1 Vesence and its subprocessors may process Customer Personal Data outside the EEA, as described in the subprocessor list. This includes processing by Cloudflare, Inc. in the United States and elsewhere on its global network.

8.2 Every transfer outside the EEA relies on a valid transfer mechanism. These are: an adequacy decision, including the EU–US Data Privacy Framework for certified recipients, or the EU Standard Contractual Clauses (Commission Decision 2021/914) entered into with the subprocessor, together with supplementary measures where needed. Transfers of UK and Swiss personal data use the UK Addendum and the Swiss amendments to the SCCs.

8.3 If a transfer mechanism is invalidated, Vesence will put an alternative in place without undue delay.

9. Return and deletion

When the Agreement ends, Vesence returns and deletes Customer Personal Data in accordance with the request window, export deadline, active-system deletion rules and separate backup deletion period in clause 14.6 of the Terms. A timely requested export is completed before the relevant data is deleted from active systems. Vesence does not delete data that EU or Member State law requires it to keep. All Customer Personal Data retained pending export or deletion, in backups or under a legal retention requirement remains protected by this DPA.

10. Liability, term and law

10.1 Each party's liability under this DPA is subject to the Terms, including clause 13.3. Liability towards data subjects follows Article 82 GDPR. Neither party indemnifies the other for administrative fines imposed on it.

10.2 This DPA lasts as long as Vesence processes Customer Personal Data. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails. Section 16 of the Terms governs the applicable law and disputes.

Annex 1 — Details of processing

ItemDetails
Subject matter and natureProviding the Service: storing, displaying, editing and sharing Customer Content; running AI models and Agents on it; running Users' cloud computers; syncing with Connected Services as Users instruct
PurposeProviding, securing and supporting the Service for the Customer under the Agreement
DurationThe term of the Agreement plus the deletion periods in clause 14.6 of the Terms
Data subjectsThe Customer's Users. Anyone who appears in Customer Content, such as the Customer's clients, counterparties, correspondents, meeting attendees and employees
Categories of personal dataWhatever appears in Customer Content: names, contact details, emails and calendar entries, document contents, identifiers and any other data Users submit or connect. User account identifiers and activity logs
Special categoriesNot intended, but they may appear in Customer Content that the Customer chooses to submit. The Customer decides whether that is lawful
Retention in the ServiceKept until deleted by a User or the Customer, or under clause 14.6 of the Terms. The deletion rules in that clause apply to all copies, including file versions, Agent checkpoints and cloud computer disk snapshots. Subject to those deletion rules, the retention periods during use of the Service are as follows. Automatic file version history: all versions for 1 day, hourly for 1 week, daily for 3 months. Agent checkpoints: 1 month. Saved versions: until deleted. Cloud computer disk: only the latest snapshot is kept. It expires 30 days after the computer last started from it, after which the computer starts fresh
LocationsSee the subprocessor list: EU or US primary region for files and chats; other processing as listed there

Annex 2 — Technical and organizational measures

Vesence shall implement and maintain the following technical and organizational measures for the Service.

AreaMeasures
Identity and accessSign-in only through Microsoft Entra ID or Google. Vesence stores no passwords. Workspaces are tied to the Customer's Entra tenant or Google Workspace domain. Workspace administrator and shared-drive roles: owner, editor, viewer
Customer isolationEach User's data sits in separate per-User and per-drive storage objects. Each User's cloud computer is a separate container that holds no credentials. It reaches only that User's own data, through internal endpoints bound to that User outside the container
Connected Service tokensStored server-side, encrypted with AES-256-GCM, in the User's own storage object. Never sent to the browser or the cloud computer
Agent safeguardsAgents cannot send email. A change an Agent proposes to a Connected Service, such as a file write, calendar reply, message or folder change, waits for the User to approve that exact request. Vesence's servers re-check the approved request before carrying it out. Browser control in the desktop app needs per-chat permission, plus separate permission for uploads
EncryptionTLS for data in transit. Cloudflare encrypts all stored data at rest
AI providersOpenAI requests are sent with storage switched off, and EU Workspaces use OpenAI's EU data residency endpoint. OpenAI keeps a prompt cache for up to 24 hours (see the subprocessor list). No subprocessor may train on Customer Content
Region separationFiles and chats are stored in R2 buckets locked to Cloudflare's EU jurisdiction (location EEUR) or US jurisdiction (ENAM). The EU user directory is in an EU-jurisdiction database; the US directory has a location hint only. Cloud computers have no location limit
ResilienceDatabases and per-User storage objects have Cloudflare's 30-day point-in-time recovery (D1 Time Travel; Durable Object point-in-time recovery). File contents have no separate backup beyond Cloudflare's replicated storage; version history (Annex 1) covers accidental changes
Staff accessVesence maintains policies restricting personnel access to Customer Content to what is necessary to provide support expressly authorized by the Customer, to investigate security incidents or abuse, or to comply with law, as set out in clause 9.7 of the Terms.
Development and vulnerability managementVesence shall maintain documented procedures for secure development and vulnerability management. These include static analysis, secret scanning, automated dependency updates and regular independent penetration tests.
Incident responseVesence shall maintain documented incident response procedures covering the detection, investigation and remediation of security incidents, and notification of personal data breaches in accordance with section 4 of this DPA.