Skip to main content
VaultFerry
← Home

Data Processing Agreement

This is VaultFerry’s standard Data Processing Agreement. It governs the limited personal data we process on your behalf as your processor — never the contents of your files, which travel directly from your own cloud bucket to your client and are never stored on our servers. It forms part of our Terms of Service.

Version 1.2, effective 1 August 2026. If you require a countersigned or negotiated copy, write to us at privacy@vaultferry.com.

1. Parties and definitions

This Data Processing Agreement (the DPA) records how VaultFerry processes personal data on behalf of the customer in connection with the VaultFerry bring-your-own-storage file-sharing service. It forms part of, and is subject to, the main VaultFerry Terms of Service; where this DPA and the Terms of Service conflict on the subject of data protection, this DPA prevails for that subject.

The two parties to this DPA are:

  • The Customer — the organisation or individual that has entered into the Terms of Service. The Customer acts as the controller (under UK GDPR and the EU GDPR) and as the business (under the CCPA/CPRA). The Customer determines the purposes and means of the processing and controls the cloud storage bucket from which files are served.
  • VaultFerry — the operator of the service. VaultFerry acts as the processor (under UK GDPR and the EU GDPR) and as a service provider or contractor (under the CCPA/CPRA). VaultFerry processes personal data only on the documented instructions of the Customer, as set out in this DPA and the Terms of Service.

VaultFerry is a bring-your-own-storage service: the contents of Customer’s files never traverse or persist on VaultFerry servers, and bytes travel directly from the Customer’s own cloud bucket to the recipient. The only personal data VaultFerry processes as processor on the Customer’s behalf is operational metadata — file names, sizes and object paths; per-access timestamps and success or failure; an approximate region (country) derived from the accessor IP; a salted, non-reversible SHA-256 hash of the accessor IP; the browser User-Agent (downloads); for identity-required upload links, the uploader-provided name and email; the Customer’s encrypted cloud credentials; download-session records for resumable downloads (a hashed session token and re-mint counters); and the branding assets the Customer uploads (logo image, company name, accent colour).

VaultFerry additionally processes account, billing, and security data relating to the Customer as an independent controller — described in the Privacy Policy — and that controller-side processing is outside the scope of this DPA.

The following terms carry the meanings given to them in the UK GDPR, the EU GDPR (Regulation 2016/679) and the Data Protection Act 2018, with their nearest CCPA/CPRA equivalents noted for reference:

  • Controller — the party that determines the purposes and means of processing. The CCPA/CPRA equivalent is the business.
  • Processor — the party that processes personal data on behalf of the controller. The CCPA/CPRA equivalents are the service provider and the contractor.
  • Personal data — any information relating to an identified or identifiable natural person. The CCPA/CPRA equivalent is personal information.
  • Processing — any operation performed on personal data, whether or not by automated means, including collection, storage, use, disclosure and erasure.
  • Data subject — the identified or identifiable natural person to whom personal data relates. The CCPA/CPRA equivalent is the consumer.
  • Sub-processor — a third party engaged by the processor to carry out specific processing activities on behalf of the controller.
  • Personal data breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
  • Supervisory authority — the competent independent public authority responsible for monitoring the application of data protection law. For processing subject to UK law, this is the Information Commissioner’s Office (the ICO).

Terms used in this DPA that are not defined here take the meaning given to them in the UK GDPR, the EU GDPR, the Data Protection Act 2018 or the CCPA/CPRA, as the context requires. The obligations and definitions in this DPA apply in addition to, and do not limit, the rights and obligations of the parties under the Terms of Service.

2. Roles of the parties

For the purposes of this Agreement, and of the UK GDPR, the Data Protection Act 2018, and (where applicable) the EU GDPR, the Customer is the controller and VaultFerry is the processor. The Customer determines the purposes and means of the processing carried out under the service; VaultFerry acts solely as a processor on behalf of the Customer and only in respect of the limited operational metadata described in this Agreement.

VaultFerry is a bring-your-own-storage service. The contents of the Customer’s files never traverse or persist on VaultFerry systems; the bytes travel directly from the Customer’s own cloud bucket to the recipient. VaultFerry is therefore never the controller, nor a processor, of those file contents, because the contents never reach VaultFerry systems. The only personal data VaultFerry processes as processor on the Customer’s behalf is the operational metadata defined in this Agreement: file names, sizes, and object paths; per-access timestamps and success or failure; an approximate region (country) derived from the accessor IP; a salted, non-reversible SHA-256 hash of the accessor IP; the browser User-Agent (downloads); for identity-required upload links, the uploader-provided name and email; the Customer’s encrypted cloud credentials; download-session records for resumable downloads (a hashed session token and re-mint counters); and the branding assets the Customer uploads (logo image, company name, accent colour).

As processor, VaultFerry undertakes that it will:

  • (a) process the operational metadata only on the documented instructions of the Customer, including those set out in this Agreement and in the contract, save where required to do otherwise by Union or Member State law (or, for UK data, domestic UK law) to which VaultFerry is subject;
  • (b) ensure that the persons authorised to process the personal data are bound by an appropriate obligation of confidentiality;
  • (c) implement appropriate technical and organisational measures to secure the personal data, including the measures set out elsewhere in this Agreement;
  • (d) engage sub-processors only on terms consistent with this Agreement, binding each sub-processor to data-protection obligations equivalent to those imposed on VaultFerry before any personal data is disclosed to it;
  • (e) assist the Customer, so far as the nature of the processing allows, in responding to requests from data subjects exercising their rights;
  • (f) assist the Customer with its obligations relating to security, breach notification, data protection impact assessments, and prior consultation;
  • (g) delete the personal data at the end of the service in accordance with the retention terms of this Agreement, and delete existing copies save where required to do otherwise by Union or Member State law (or, for UK data, domestic UK law) to which VaultFerry is subject; and
  • (h) make available to the Customer the information necessary to demonstrate compliance with these obligations, and allow for and contribute to audits and inspections conducted by the Customer or its mandated auditor.

VaultFerry will not sell or share the personal data, and will not retain, use, or disclose it, for any purpose other than performing the service or as otherwise permitted by applicable law. VaultFerry will not combine the personal data it receives with data from any other source or context outside the business relationship, and will promptly notify the Customer if it determines that it can no longer meet its obligations under applicable data-protection law.

Each party complies with the data-protection law applicable to its role. Where the Information Commissioner’s Office is the competent supervisory authority, the parties recognise it as such, and any restricted transfer is made under the UK adequacy regulations or, failing that, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, in each case relying on the transfer gateway in Articles 44 to 49 of the UK GDPR.

3. Scope and details of processing

The subject-matter, duration, nature and purpose of the processing, the categories of personal data, and the categories of data subjects are set out in Annex I. VaultFerry processes personal data only on the documented instructions of the Customer, including the instructions recorded in this Agreement and in Annex I, and solely for the purposes described there.

The duration of the processing is the term of the Customer’s account or of the agreement, whichever ends later (Annex I). The nature and purpose of the processing is operating the portal on behalf of the Customer: minting time-limited access links, recording the access audit, sending notifications, and administering billing. These operations may equally be instructed programmatically, via API keys the Customer creates and automation tools the Customer connects; the processing operations are the same in either case.

The Customer is the data controller and VaultFerry is the processor. VaultFerry does not sell or share personal data, does not retain, use, or disclose it outside the business relationship described in this Agreement, and does not combine it with data obtained from any other source or context.

The only personal data VaultFerry processes as processor on the Customer’s behalf is operational metadata. Because VaultFerry is a bring-your-own-storage service, the contents of the Customer’s files never traverse or persist on VaultFerry systems; bytes travel directly from the Customer’s own cloud bucket to the recipient. File contents are therefore excluded from the scope of this processing. The operational metadata comprises:

  • File metadata — file names, sizes, and object paths, together with customer-entered display labels (connection names, link labels).
  • Access records — per-access timestamps and success or failure outcomes.
  • Approximate region — a country derived from the accessor IP; stored on the audit record only where the Customer’s plan enables it (Pro and Business) and discarded on Free.
  • Hashed IP — a salted, non-reversible SHA-256 hash of the accessor IP; the raw IP is never stored.
  • Browser User-Agent — recorded for download accesses; not persisted for uploads.
  • Uploader identity — for identity-required upload links only, the uploader-provided name and email.
  • Cloud credentials — the Customer’s encrypted cloud storage credentials; download-session records for resumable downloads (a hashed session token and re-mint counters); and the branding assets the Customer uploads (logo image, company name, accent colour).

File names and object paths are customer-controlled free text; the Customer is responsible for not embedding personal or special-category data in them that it does not want processed as metadata.

Further detail on the technical and organisational security measures, the engagement of sub-processors, assistance with data subject rights and the Customer’s security, breach-notification and data-protection-impact-assessment obligations, and the deletion of personal data at the end of the service is set out in the clauses that follow and in Annex I.

4. Processing on documented instructions

VaultFerry processes personal data only on the documented instructions of the Customer, who acts as the data controller while VaultFerry acts as the processor. This obligation extends to any transfer of personal data to a third country or international organisation: VaultFerry makes no such transfer except on the documented instructions of the Customer, unless required to do so by applicable law.

The documented instructions of the Customer comprise this DPA, the Terms, and the configuration and use of the service by the Customer — including the cloud buckets the Customer connects, the share and upload links the Customer creates, the expiry and password settings the Customer applies, the plan the Customer selects, and the requests the Customer issues programmatically via API keys it creates (including through automation tools the Customer connects, acting on the Customer’s behalf). VaultFerry does not process personal data for any purpose outside that scope, does not retain, use, or disclose it beyond the business relationship, does not combine it with data from other sources, and does not sell or share it with any third party.

The processing covers only operational metadata, never file content. The bytes of Customer’s files never traverse or persist on VaultFerry systems; they travel directly from the cloud bucket of the Customer to the recipient over a short-lived signed URL (download URLs expire within five minutes; upload URLs within fifteen). The only personal data VaultFerry processes as processor on the Customer’s behalf is metadata about those transfers — file names, sizes, and object paths; per-access timestamps and success or failure outcomes; an approximate region (country) derived transiently from the accessor IP; a salted, non-reversible SHA-256 hash of that IP (never the raw IP); the browser User-Agent (downloads); for identity-required upload links, the uploader-provided name and email; the encrypted cloud credentials of the Customer; download-session records for resumable downloads (a hashed session token and re-mint counters); and the branding assets the Customer uploads (logo image, company name, accent colour).

  • Infringing instructions. VaultFerry informs the Customer if, in the opinion of VaultFerry, an instruction infringes applicable data-protection law.
  • Processing required by law. Where Union or Member State law (or, for UK data, domestic UK law) to which VaultFerry is subject requires VaultFerry to process personal data otherwise than on the documented instructions of the Customer, VaultFerry informs the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

Because file content never reaches VaultFerry systems, the documented instructions of the Customer govern only this narrow set of operational metadata and the encrypted credentials needed to mint signed URLs against the Customer’s own bucket — nothing more.

5. Confidentiality

VaultFerry ensures that any person it authorises to process personal data on behalf of the Customer is bound by an appropriate duty of confidentiality, whether under a contractual obligation or a statutory one. That duty covers all of the operational metadata processed under this Agreement — including file names, sizes and object paths, per-access timestamps and outcomes, the approximate accessor region, the salted SHA-256 accessor IP hash, the browser User-Agent (downloads), any uploader-provided name and email for identity-required upload links, and the Customer’s encrypted cloud credentials — and survives the end of the individual engagement of the relevant person.

Access to personal data is limited to those personnel who genuinely need it to provide, operate or support the service, and is granted on a least-privilege basis. VaultFerry does not sell or share personal data with third parties, does not use or disclose personal data outside the scope of providing the service, and does not combine the personal data it processes for the Customer with data drawn from any other source or context.

  • Binding obligation: authorised persons commit to confidentiality before they are given access to personal data.
  • Need-to-know access: access is restricted to personnel supporting the service and is removed when no longer required.
  • Credential protection: the Customer’s cloud credentials are encrypted with AES-256-GCM, decrypted only in memory, and are never logged.
  • Sub-processors: the sub-processors engaged by VaultFerry and identified in Annex III are bound by confidentiality and data-protection obligations no less protective than those set out here before any personal data is made available to them.

These confidentiality commitments operate alongside the technical and organisational security measures described elsewhere in this Agreement, and apply equally under the UK General Data Protection Regulation and the Data Protection Act 2018.

6. Security of processing

VaultFerry implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32. These measures are described in further detail in Annex II and are kept under review to reflect the state of the art, the limited nature of the processing, and the limited risk that follows from the fact that the contents of Customer’s files are never held on VaultFerry systems.

The measures include, in particular:

  • Encryption of stored credentials. Cloud storage credentials are encrypted at rest using AES-256-GCM, decrypted in memory only at the point of use, and never written to logs.
  • Encryption in transit. All connections are protected using TLS version 1.2 or higher.
  • Password protection. Share-link passwords are hashed using bcrypt with a cost factor of 12 or higher, and are never stored or processed in plaintext.
  • Pseudonymisation of accessor identifiers. Accessor IP addresses are recorded only as a salted, non-reversible SHA-256 hash; the raw IP address is never stored.
  • Signed, short-lived access URLs. Download URLs are cryptographically signed and expire within five minutes of issue; upload URLs are likewise signed and expire within fifteen minutes.

Taking into account the nature of the processing and the information available to it, VaultFerry also assists the Customer in ensuring compliance with the Customer’s obligations under Articles 32 to 36 of the UK GDPR — security of processing, notification of a personal data breach, data protection impact assessments, and prior consultation with the supervisory authority.

Because file contents travel directly from the Customer’s own cloud bucket to the recipient and are never received, stored, or processed by VaultFerry, the residual risk to the rights and freedoms of data subjects is correspondingly limited, and the measures set out above are appropriate to that risk.

7. Sub-processors

The Customer authorises VaultFerry to engage the sub-processors listed below to process personal data on the Customer’s behalf. Each is bound by data-protection terms no less protective than this Agreement, and the contents of the Customer’s connected storage buckets never reach any of them; the branding assets the Customer uploads are stored with the object-storage sub-processor identified in Annex III.

  • Vercel Inc.Frontend application hosting and edge network — serves the web application and processes operational metadata; never the contents of your connected storage buckets.
  • Railway Corp.Backend application hosting and managed PostgreSQL metadata database — runs the VaultFerry API and stores the operational metadata and encrypted storage credentials described in the DPA; never the contents of your connected storage buckets.
  • Cloudflare, Inc.Reverse proxy, CDN, and TLS termination for the API domain — processes request content and connection IP addresses in transit; never the contents of your connected storage buckets.
  • Amazon Web Services EMEA SARLObject storage (S3) for the branding assets you upload (logo images) only; never the contents of your connected storage buckets.
  • Hanko GmbHManaged authentication (sign-in, account identity).
  • Resend, Inc.Transactional email — download and upload notifications and subscription confirmations.
  • Stripe, Inc.Subscription billing and payment processing.
  • Better Stack, Inc.Application log aggregation, error alerting, and uptime monitoring — processes pseudonymised operational metadata (request id, pseudonymous account identifiers, and — for API-key usage and lifecycle events — an internal key identifier plus the key's non-secret display prefix, never a key's name or secret); never the contents of your connected storage buckets.

VaultFerry gives the Customer advance notice, by email to the Customer’s account address, of any intended addition or replacement of a sub-processor and a reasonable opportunity to object on data-protection grounds. If VaultFerry cannot accommodate a reasonable objection, the Customer may terminate the affected service.

8. Assisting with data subject rights

Taking into account the nature of the processing, VaultFerry assists the Customer by appropriate technical and organisational measures, insofar as this is possible, to fulfil the Customer’s obligation to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction of processing, data portability, and objection. Because the Customer is the controller and VaultFerry acts only on documented instructions, VaultFerry will not respond to a data subject directly but will route any such request it receives to the Customer. The Customer, as controller, is responsible for providing accessors and uploaders with the transparency information required by Articles 13 and 14; VaultFerry assists by displaying an access-record notice on every public page together with a Customer-configurable privacy-notice link (branding settings).

VaultFerry processes only a limited set of operational metadata on the Customer’s behalf — file names, sizes, and object paths; per-access timestamps and success or failure outcomes; an approximate region (country) derived transiently from the accessor IP; a salted, non-reversible SHA-256 hash of the accessor IP; the browser User-Agent (downloads); for identity-required upload links, the uploader-provided name and email; the Customer’s encrypted cloud credentials; download-session records for resumable downloads (a hashed session token and re-mint counters); and the branding assets the Customer uploads (logo image, company name, accent colour). The contents of the Customer’s files never traverse or persist on VaultFerry servers, so requests concerning file contents are addressed by the Customer within its own cloud storage. For the metadata described above, the following practical levers are available to the Customer:

  • Revoke or delete individual links — the Customer can revoke or delete any individual share link or upload link at any time. A terminated link (revoked, expired, or cap-exhausted) is permanently purged 30 days after termination.
  • Delete the account — deleting the account permanently purges all of the operational metadata processed on the Customer’s behalf and the encrypted cloud credentials. Certain limited items are handled separately, as set out in clause 10: a deletion-audit record — a salted, non-reversible hash of the account email address plus an internal reference and a timestamp, retained for 18 months then purged; an opaque replay-defence marker, not linked to the Customer’s name or email within VaultFerry’s systems, retained as a permanent security control so a deleted account can never be re-animated by a stale session token; and billing and payment records retained for the period required by applicable accounting and tax law.

Where the salted SHA-256 hash of the accessor IP is concerned, it is non-reversible and the raw IP is never written to durable storage or to VaultFerry’s application logs; the infrastructure providers listed in Annex III may process IP addresses in transit and in their own edge or platform logs, which constrains what can be linked back to an individual data subject. VaultFerry will provide the Customer with the information reasonably necessary to identify and act upon the metadata it holds so that the Customer can meet the applicable response deadline.

9. Personal data breach

On becoming aware of a personal data breach affecting personal data VaultFerry processes on the Customer’s behalf, VaultFerry notifies the Customer without undue delay and in any event within 72 hours of becoming aware of it. The notice describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it.

VaultFerry provides reasonable assistance to help the Customer meet its own obligations to notify supervisory authorities and data subjects under Articles 33 and 34 of the UK GDPR (and the EU GDPR equivalents). Because file contents never reach VaultFerry systems, the personal data exposed by any breach on the VaultFerry side is limited to the operational metadata described in Annex I.

10. Return and deletion of data

At the choice of the Customer, VaultFerry deletes or returns all personal data processed on behalf of the Customer after the end of the provision of the services, and deletes existing copies, unless storage is required by applicable law (including Union or Member State law and UK domestic law). Because VaultFerry operates a bring-your-own-storage model, the contents of the Customer’s files never traverse or persist on VaultFerry servers; this clause concerns the operational metadata that VaultFerry processes as processor, together with the Customer’s own API keys — expressly flagged below — for which VaultFerry acts as controller and which VaultFerry stores and purges through the same product mechanics.

Deletion and return operate through the following product mechanics:

  • Account deletion. When the Customer deletes the account, VaultFerry permanently purges every row of the Customer’s operational metadata and the encrypted cloud credentials. Three items are handled separately: a deletion-audit record — a salted, non-reversible hash of the account email address plus an internal reference and a timestamp, retained for 18 months, then purged; a replay-defence marker — an opaque identifier issued by VaultFerry’s identity provider, not linked to the Customer’s name or email within VaultFerry’s systems, which VaultFerry retains as a permanent security control (a defence-in-depth measure against session replay) to ensure a deleted account can never be re-animated by a stale session token; and billing and payment records — payment-processor (Stripe) event records and the payment processor’s customer record, which may include the account email address, cardholder name, billing address, and the last four digits of a payment card — retained for the period required by applicable accounting and tax law (VaultFerry applies a seven-year window to stored event records, after which they are deleted automatically). On account deletion VaultFerry redacts the directly identifying fields from its stored event records; the retained records keep the payment-processor customer reference (an opaque account identifier), and a corresponding customer record remains on the processor’s side, in each case for tax and chargeback history.
  • Terminated share and upload links. Links that have reached a terminal state — revoked, expired, or cap-exhausted (download cap for share links, file-count cap for upload links) — are purged 30 days after termination.
  • API keys. API keys are the Customer’s own account credentials, for which VaultFerry acts as controller (this account data is described in the Privacy Policy); they are noted here because VaultFerry stores and purges them. The key value itself is stored only as a display prefix and a one-way hash — never the key value — alongside the Customer-chosen key name. Revoking a key disables it immediately; the revoked record is purged 30 days after revocation. Scheduling account deletion revokes all of the Customer’s keys at once, and the key records, including the name, are purged with the account.
  • Access-audit records. Access-audit rows are retained according to the plan of the Customer: 7 days on Free, 30 days on Pro, and 365 days on Business. Records older than the applicable window are removed automatically.

For these three residual items VaultFerry acts as an independent controller from the moment of deletion: the deletion-audit record and the replay-defence marker are processed under VaultFerry’s own legitimate interests in fraud-prevention, accountability, and security (Article 6(1)(f)), and billing records under VaultFerry’s legal obligations (Article 6(1)(c)), in each case as disclosed in the Privacy Policy. The processor deletion duty in this clause is otherwise unqualified.

Where the Customer elects return rather than deletion, VaultFerry provides the personal data in a structured, machine-readable form: activity records are available as a CSV export from the dashboard on plans that include it, and a complete export of the remaining categories is provided on request to the privacy contact, without charge, within 30 days and before the corresponding rows are purged. The raw accessor IP is never written to durable storage or to VaultFerry’s application logs in the first place; the infrastructure providers listed in Annex III may process IP addresses in transit and in their own edge or platform logs; the audit record retains only a salted, non-reversible SHA-256 hash and an approximate region, so deletion of an audit row removes the only personal data held for that access event.

Where applicable law (including Union or Member State law, UK domestic law, or United States federal or state law) requires VaultFerry to retain particular personal data beyond the periods above, VaultFerry retains only the data so required, for the period so required, and continues to protect it under the technical and organisational measures described in this Agreement until it may lawfully be deleted. Residual copies of deleted rows may persist in encrypted database backups for up to 7 days before expiring; backups are used only for disaster recovery, and deletions are re-applied to any database restored from them before it serves traffic.

11. Audits and demonstrating compliance

VaultFerry makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations of a processor under Article 28 of the UK GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or by an independent auditor it mandates, in accordance with this clause.

VaultFerry may discharge these obligations primarily by providing relevant documentation and by responding to reasonable security questionnaires. The documentation VaultFerry can make available describes, among other things, the technical and organisational measures summarised in this Agreement, including AES-256-GCM encryption of the Customer’s cloud credentials (decrypted in memory only and never logged), TLS 1.2 or higher in transit, bcrypt at a cost factor of 12 or greater for share-link passwords, salted SHA-256 hashing of accessor IP addresses, and signed download URLs that expire within five minutes and signed upload URLs that expire within fifteen minutes.

Where documentation and questionnaire responses do not reasonably satisfy the Customer’s audit rights, the Customer or its mandated auditor may carry out an inspection, subject to the following conditions:

  • Notice. The Customer gives VaultFerry reasonable advance written notice of any requested audit or inspection.
  • Frequency. Audits and inspections are limited to once per twelve-month period, save where an inspection is required by a competent supervisory authority, such as the Information Commissioner’s Office, or where the Customer reasonably believes a personal data breach affecting its data has occurred.
  • Confidentiality. The Customer and any mandated auditor are bound by obligations of confidentiality at least as protective as those in this Agreement, and any auditor must not be a competitor of VaultFerry.
  • Scope and conduct. Audits and inspections are limited to information and systems relevant to the processing of the Customer’s personal data, are conducted during normal business hours, and are carried out so as to cause minimal disruption to VaultFerry operations and not to compromise the confidentiality, security, or integrity of data belonging to other customers.

Because the contents of the Customer’s files never traverse or persist on VaultFerry servers and travel directly from the Customer’s cloud bucket to the recipient, an audit covers only the operational metadata that VaultFerry processes as described in this Agreement, together with the related security measures, sub-processor arrangements, retention behaviour, and breach-handling procedures.

VaultFerry informs the Customer without undue delay if, in its opinion, an instruction relating to an audit or inspection infringes the UK GDPR, the Data Protection Act 2018, or other applicable data protection law, and contributes to such audits and inspections on the basis set out above.

12. International transfers

Where the processing involves transferring personal data outside the EEA or the UK, VaultFerry relies on an adequacy decision or, in the absence of one, on appropriate safeguards. For EEA-origin transfers this means the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914). For UK-origin transfers this means the UK International Data Transfer Agreement (in force 21 March 2022) or the UK Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018.

These mechanisms operate under the transfer gateway in Articles 44 to 49 of the EU GDPR and the parallel provisions of the UK GDPR. Where an adequacy decision or UK adequacy regulations made under Article 45 of the UK GDPR cover the destination, VaultFerry may rely on that decision in place of the contractual safeguards. Where a transfer is UK-origin only, no conflicting EU Standard Contractual Clauses obligation overrides the applicable UK instrument.

The location of hosting and of the sub-processors engaged by VaultFerry is set out in Annex III. The personal data potentially in scope of a transfer is limited to the operational metadata described in this Agreement; the contents of the Customer’s files never traverse or persist on VaultFerry servers, since bytes travel directly from the Customer’s cloud bucket to the recipient.

The Customer authorises such transfers to the extent they are necessary to provide the service. VaultFerry does not sell or share personal data, does not combine the personal data received with data from other sources, and binds each sub-processor to the same transfer restrictions before any personal data is shared. VaultFerry will notify the Customer promptly if it can no longer give effect to an applicable transfer mechanism.

Where a restricted transfer from the EEA requires appropriate safeguards, the parties incorporate the EU Standard Contractual Clauses (2021/914), Module Two (controller to processor), into this Agreement by reference, completed as follows: Annexes I and II of the SCCs are populated by Annexes I and II of this Agreement and the parties’ details under the Terms; Annex III of the SCCs by Annex III of this Agreement; the optional docking clause is not used; under Clause 9(a), Option 2 (general written authorisation) applies with the notice mechanics of clause 7 of this Agreement; and the competent supervisory authority is determined under Clause 13 of the SCCs. For UK-origin restricted transfers, the UK Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 is likewise incorporated, with Tables 1 to 4 completed by reference to the same Annexes and party details. The Customer’s acceptance of the Terms executes these instruments in electronic form.

13. United Kingdom addendum

This section applies to the extent that personal data processed by VaultFerry under this Agreement is subject to the law of the United Kingdom. Where it applies, it supplements and, where necessary, modifies the other sections of this Agreement for UK-origin personal data.

  • Applicable law. References in this Agreement to the GDPR are read as references to the UK GDPR and the Data Protection Act 2018, as retained, amended, or replaced in UK law. References to the EEA are read as references to the United Kingdom, or are taken to include the United Kingdom where a transfer covers both.
  • Supervisory authority. The Information Commissioner (the Information Commissioner’s Office, or ICO) is the competent supervisory authority for UK personal data, in place of the EU lead supervisory authority.
  • Restricted transfers. Any transfer of UK personal data to a country outside the United Kingdom that is not the subject of UK adequacy regulations made under Article 45 of the UK GDPR is made under the UK International Data Transfer Agreement (the IDTA, in force 21 March 2022) or under the UK Addendum to the EU Standard Contractual Clauses issued by the ICO under section 119A of the Data Protection Act 2018, in each case as the restricted-transfer gateway under Articles 44 to 49 of the UK GDPR in place of the EU Standard Contractual Clauses.
  • Mandatory Clauses. Where the parties rely on the UK Addendum, the ICO Table 1 to Table 4 format applies and the Mandatory Clauses are incorporated without modification; only the Optional Clauses may be agreed between the parties.
  • Governing law and jurisdiction. For UK-origin transfers under this section, the governing law is the law of England and Wales and the courts of England and Wales have jurisdiction over disputes, in place of any EU member-state law or EU court.

Where a transfer is UK-origin only, the UK instrument identified above governs and no conflicting obligation under the EU Standard Contractual Clauses overrides it. The obligations VaultFerry undertakes elsewhere in this Agreement as processor — processing only on the documented instructions of the Customer, binding authorised personnel to confidentiality, maintaining the technical and organisational measures described in this Agreement, engaging the named sub-processors under equivalent terms, assisting the Customer with data subject requests and with breach, assessment, and consultation obligations, notifying the Customer within 72 hours of becoming aware of an incident, purging data on the retention schedule and on account deletion, and providing the information needed to demonstrate compliance — apply equally to UK personal data under the UK GDPR and the Data Protection Act 2018.

14. United States state privacy laws

This section applies where personal information processed under this Agreement is subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, the CCPA/CPRA) or to comparable United States state privacy laws. With respect to such personal information, the Customer is the business and VaultFerry acts as a service provider (or contractor) processing the personal information on behalf of the Customer.

VaultFerry makes the following commitments in respect of the personal information disclosed to it by, or collected by it for, the Customer:

  • No sale or sharing. VaultFerry does not sell the personal information and does not share it for cross-context behavioural advertising or for any other purpose, in each case as those terms are defined under the CCPA/CPRA.
  • Limited business purpose. VaultFerry processes the personal information solely to provide the VaultFerry service to the Customer under this Agreement, which is the specified business purpose, and for no other purpose. The personal information VaultFerry processes as a service provider on the Customer’s behalf is limited to operational metadata (file names, sizes and object paths; per-access timestamps and success or failure; an approximate region derived from the accessor IP, stored on the audit record only where the Customer’s plan enables it (Pro and Business) and discarded on Free; a salted, non-reversible SHA-256 hash of the accessor IP; the browser User-Agent (downloads); for identity-required upload links, the uploader-provided name and email; the Customer’s encrypted cloud credentials; download-session records for resumable downloads (a hashed session token and re-mint counters); and the branding assets the Customer uploads (logo image, company name, accent colour)). The contents of the Customer’s files never traverse or persist on VaultFerry servers.
  • No use outside the relationship. VaultFerry does not retain, use or disclose the personal information for any purpose other than the business purpose described above, nor outside the direct business relationship between the parties, except where retention, use or disclosure is permitted by applicable law.
  • No combining. VaultFerry does not combine the personal information it receives under this Agreement with personal information that it receives from, or on behalf of, any other person, or that it collects from its own interaction with any individual, except as permitted by the CCPA/CPRA.
  • Sub-processors bound. VaultFerry engages only the sub-processors identified in Annex III to this Agreement and binds each of them by written contract to the same restrictions that apply to VaultFerry under this section before any personal information is made available to them.
  • CCPA compliance. VaultFerry will comply with all obligations applicable to a service provider (or contractor) under the CCPA/CPRA, will provide the same level of privacy protection as is required of businesses, and will cooperate with the Customer in responding to verifiable consumer requests.
  • Certification. VaultFerry certifies that it understands the restrictions set out in this section and will comply with them.

VaultFerry will notify the Customer without undue delay if it determines that it can no longer meet its obligations under the CCPA/CPRA or comparable United States state privacy laws. The Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use of the personal information. VaultFerry grants the Customer the right to take such steps as are reasonably necessary to ensure that VaultFerry uses the personal information in a manner consistent with the Customer’s obligations under those laws.

15. Liability and order of precedence

In the event of a conflict or inconsistency between this Data Processing Agreement and the Terms, this Data Processing Agreement prevails with respect to data-protection matters. For all other matters, the Terms prevail.

The liability of each party under this Data Processing Agreement is subject to the limitations and exclusions of liability set out in the Terms. Nothing in this Data Processing Agreement increases or extends the liability of either party beyond what the Terms provide. This Data Processing Agreement is governed by the law specified in the Terms — the laws of England and Wales — save that clause 13 governs UK-origin restricted transfers.

  • Order of precedence. For data-protection matters, this Data Processing Agreement takes priority over the Terms; for all other matters, the Terms take priority.
  • Liability. Each party’s liability under this Data Processing Agreement remains subject to the limitations and exclusions of liability agreed in the Terms.
  • Annexes. The Annexes to this Data Processing Agreement form an integral part of it and are to be read together with it.

Save as expressly amended or supplemented by this Data Processing Agreement, the Terms remain in full force and effect.

16. Changes, term, and contact

This Data Processing Agreement takes effect on the date the Customer accepts the Terms and remains in force for as long as VaultFerry processes personal data on the Customer’s behalf. When that processing ends — on account deletion or termination of the service relationship — VaultFerry deletes the relevant personal data in line with the retention rules set out above.

VaultFerry may update this standard-form DPA from time to time. The version and effective date shown at the top of this page reflect the current text. VaultFerry notifies Customers of material changes to this DPA by email to the Customer’s account address.

If you have questions about this DPA, or if you require a countersigned or separately negotiated copy, you can reach VaultFerry at the privacy contact linked in the introduction to this page.

Annex I — Details of processing

The following details describe the processing carried out by VaultFerry as processor on behalf of the Customer as controller. The contents of the Customer’s files never traverse or persist on VaultFerry servers; bytes travel directly from the Customer’s cloud bucket to the recipient, so VaultFerry processes only the operational metadata listed below.

  • Subject matter: the provision of the VaultFerry portal to the Customer.
  • Duration: for the term of the Customer’s account or of the agreement, whichever ends later.
  • Nature and purpose: minting time-limited download and upload links, recording the access audit, sending notification email, and billing the Customer for the service — whether instructed through the dashboard or instructed programmatically, via API keys the Customer creates and automation tools the Customer connects.
  • Categories of data subjects: the Customer’s clients and recipients who access download links; uploaders who use file-request links.
  • Categories of personal data: file names, sizes, and object paths, together with customer-entered display labels (connection names, link labels); per-access timestamps and success or failure; the approximate region (country) derived from the accessor IP, stored on the audit record only where the Customer’s plan enables it (Pro and Business) and discarded on Free; a salted, non-reversible SHA-256 hash of the accessor IP, never the raw IP; the browser User-Agent (recorded for download accesses; not persisted for uploads); for identity-required upload links, the uploader-provided name and email; the Customer’s encrypted cloud credentials; download-session records for resumable downloads (a hashed session token and re-mint counters), removed by scheduled cleanup after the session window; and the branding assets the Customer uploads (logo image, company name, accent colour).

The raw accessor IP is processed transiently only to derive the approximate region and is never written to durable storage or to VaultFerry’s application logs; the infrastructure providers listed in Annex III may process IP addresses in transit and in their own edge or platform logs. Cloud credentials are encrypted with AES-256-GCM, decrypted in memory only, and never logged.

Annex II — Technical and organisational measures

VaultFerry implements the following technical and organisational measures to protect personal data, in accordance with Article 32. Because VaultFerry operates a bring-your-own-storage model, the contents of the Customer’s files never traverse or persist on VaultFerry systems, which materially reduces the surface to which these measures apply.

  • Encryption of stored credentials. The Customer’s cloud credentials are encrypted at rest using AES-256-GCM, decrypted in memory only at the point of use, and never written to logs.
  • Encryption in transit. All connections to VaultFerry are protected with TLS version 1.2 or higher.
  • Password hashing. Share-link passwords are hashed with bcrypt at a cost factor of 12 or higher; the raw password is never stored.
  • API-key credentials. Customer-created API keys are verified against a one-way SHA-256 hash; the key itself is displayed once at creation and never stored. Keys are revocable with immediate effect, revoked records are purged after 30 days, and API traffic is rate-limited per key and per account.
  • IP pseudonymisation. Accessor IP addresses are pseudonymised through salted, non-reversible SHA-256 hashing; the raw IP address is never stored.
  • Signed, short-lived URLs. Download URLs are cryptographically signed and short-lived, expiring within five minutes of issue; upload URLs are likewise signed and expire within fifteen minutes.
  • Access control. Access to systems and data is restricted to authorised personnel on a need-to-know basis.
  • Direct-transfer architecture. Under the bring-your-own-storage architecture, file contents travel directly between the Customer’s bucket and the recipient and never reach VaultFerry systems.
  • Audit logging. Access events are logged to support auditing and accountability.
  • Encrypted backups. Database backups are encrypted, retained for up to 7 days, and used only for disaster recovery.

These measures are reviewed and applied to the operational metadata that VaultFerry processes as part of providing the service.

Annex III — Sub-processors

VaultFerry engages the following sub-processors to process operational metadata in providing the service. The contents of the Customer’s connected storage buckets never reach any of them (branding assets are stored with the object-storage entry below), and each is bound by data-protection terms no less protective than this Agreement.

  • Vercel Inc.Frontend application hosting and edge network — serves the web application and processes operational metadata; never the contents of your connected storage buckets. Processing location: United States (global edge network)
  • Railway Corp.Backend application hosting and managed PostgreSQL metadata database — runs the VaultFerry API and stores the operational metadata and encrypted storage credentials described in the DPA; never the contents of your connected storage buckets. Processing location: United States entity; deployment region: Amsterdam, Netherlands (EU)
  • Cloudflare, Inc.Reverse proxy, CDN, and TLS termination for the API domain — processes request content and connection IP addresses in transit; never the contents of your connected storage buckets. Processing location: United States entity; global edge network
  • Amazon Web Services EMEA SARLObject storage (S3) for the branding assets you upload (logo images) only; never the contents of your connected storage buckets. Processing location: London, UK — eu-west-2
  • Hanko GmbHManaged authentication (sign-in, account identity). Processing location: Frankfurt, Germany (EU)
  • Resend, Inc.Transactional email — download and upload notifications and subscription confirmations. Processing location: United States
  • Stripe, Inc.Subscription billing and payment processing. Processing location: United States (payments processed globally)
  • Better Stack, Inc.Application log aggregation, error alerting, and uptime monitoring — processes pseudonymised operational metadata (request id, pseudonymous account identifiers, and — for API-key usage and lifecycle events — an internal key identifier plus the key's non-secret display prefix, never a key's name or secret); never the contents of your connected storage buckets. Processing location: United States entity (Delaware); log-data region: Germany (EU)