Legal
Data Processing Agreement
Last updated September 24, 2026
This DPA forms part of the Terms of Service. The Customer is the controller and Vetiu AB is the processor of personal data in the Customer's workspace. Need a signed copy? Email info@vetiu.com.
1.Scope of processing
- Subjects: Customer's employees, managers and invited users.
- Data: names, work emails, roles, team membership, learning progress, quiz results and uploaded content.
- Purpose: providing the Vetiu platform for the duration of the subscription.
2.Instructions
We process personal data only on the Customer's documented instructions, including these terms and use of the platform settings.
3.Confidentiality and security
Our staff are bound by confidentiality. We apply the technical and organisational measures described on our Security page.
4.Subprocessors
Customer authorises the subprocessors on our Subprocessors page. We notify customers of new subprocessors at least 14 days in advance by email or by updating that page. Customer may object on reasonable data protection grounds by replying to the notice. We will work in good faith to find an alternative; if none can be agreed, Customer may terminate its subscription and receive a prorated refund of prepaid, unused fees. Termination is Customer's sole remedy for a subprocessor change. This authorisation covers all listed AI model providers (OpenAI, Anthropic and Google); we may route AI requests to any of them without further notice. Each is bound by written terms that limit processing to producing the requested output and prohibit using Customer data to train their models.
5.Assistance
We help the Customer respond to data subject requests, and with impact assessments and consultations where reasonably required.
6.Personal data breaches
We notify the Customer without undue delay, and no later than 48 hours after becoming aware of a breach affecting its data.
7.International transfers
Where personal data is transferred outside the EU/EEA, the EU Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: controller to processor) are incorporated into this DPA by reference. The Scope section above serves as Annex I (description of transfer) and our Security page serves as Annex II (technical and organisational measures). A valid transfer mechanism, such as the SCCs or an adequacy decision, is used for every transfer.
8.Deletion and return
At the end of the service, Customer can export its content. We delete remaining personal data within 30 days unless the law requires storage.
9.Audits
We make available the information reasonably needed to demonstrate compliance with this DPA, including our own security documentation and relevant certifications and reports from our infrastructure providers. Providing this information satisfies Customer's audit rights. Any further audit requires 30 days' advance notice, takes place during normal business hours, at Customer's expense, no more than once every 12 months, and subject to confidentiality.
