← visionmade.ai

Data Processing Agreement

Last updated: May 2026 · Version 2.0 · VISIONMADE AI LTD

This Data Processing Agreement ("DPA") forms part of the agreement between VISIONMADE AI LTD, trading as visionmade.ai, company number 17173691, registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom ("visionmade.ai", the "Processor"), and the Creator that has signed up for or otherwise uses the Vera AI widget service (the "Controller").

This DPA is intended to satisfy the requirements of Article 28 of the EU GDPR and Article 28 of the UK GDPR, where applicable.

1. Definitions

  • "Agreement" means the visionmade.ai Terms and Conditions or other applicable service agreement governing the provision of the Service.
  • "Controller" means the Creator that determines the purposes and means of the processing of Visitor Personal Data collected through its Vera deployment.
  • "Data Protection Laws" means the EU GDPR, the UK GDPR, the UK Data Protection Act 2018, applicable e-privacy laws and any national laws implementing or replacing them.
  • "Data Subject" means the natural person to whom Personal Data relates — primarily Visitors interacting with Vera on a Creator landing page.
  • "EU GDPR" means Regulation (EU) 2016/679.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" includes collection, storage, transmission, analysis, consultation, use, disclosure, restriction, erasure and destruction of Personal Data.
  • "Processor" means visionmade.ai when processing Personal Data on behalf of the Controller under this DPA.
  • "Restricted Transfer" means a transfer of Personal Data to a country requiring additional safeguards under applicable Data Protection Laws.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "UK GDPR" has the meaning given in section 3(10) of the UK Data Protection Act 2018.
  • "Visitor" means an individual who visits a Creator landing page and interacts with the Vera AI widget.

2. Scope and status of the parties

2.1. This DPA applies only to Personal Data processed by visionmade.ai as Processor on behalf of the Controller. Personal data processed by visionmade.ai as controller — including Creator account, billing and support data — is governed by the visionmade.ai Privacy Policy.

2.2. For Visitor Personal Data processed through Vera on the Controller's landing page, the Controller acts as controller and visionmade.ai acts as processor.

2.3. The Controller determines the purposes, lawful basis, transparency information and overall legal compliance of its use of Vera. visionmade.ai processes Visitor Personal Data only in accordance with this DPA, the Agreement and the Controller's documented instructions.

3. Details of the processing

Processing is carried out for the purpose of providing the Vera AI widget service, enabling real-time conversational responses, maintaining conversation logs, generating audience intelligence and analytics for the Controller, and supporting security and service integrity.

The Controller acknowledges that Visitors may voluntarily include Personal Data, and occasionally special category data, in free-text conversations. Vera is not designed to request special category data. The Controller must assess whether its specific use case makes such data foreseeable and, where required, implement a valid Article 9 condition before deploying Vera.

4. Controller obligations

The Controller shall:

  • ensure that its instructions to visionmade.ai are lawful and consistent with Data Protection Laws;
  • determine and document the lawful basis for processing Visitor Personal Data through Vera;
  • provide clear privacy information to Visitors before or at the time their data is collected, including information on AI interaction and conversation logging;
  • ensure landing pages include appropriate cookie or similar technology notices and consent mechanisms;
  • not instruct Vera to collect Personal Data that is excessive, unlawful or incompatible with disclosed purposes;
  • respond to Data Subject rights requests where the Controller is responsible for doing so.

5. Processor obligations and documented instructions

5.1. visionmade.ai shall process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.

5.2. If visionmade.ai considers that an instruction infringes applicable Data Protection Laws, it shall inform the Controller without undue delay.

5.3. visionmade.ai shall not use Personal Data processed on behalf of the Controller for its own independent purposes, except where data has been anonymised or where required by law.

5.4. visionmade.ai shall ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.

6. Confidentiality

visionmade.ai shall keep Personal Data confidential and ensure that its personnel, contractors and authorised representatives are bound by appropriate confidentiality obligations.

7. Security measures

visionmade.ai shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Current measures are summarised in Schedule 2 of the full DPA document. visionmade.ai may update measures from time to time, provided the overall level of security is not materially reduced.

8. Personal data breaches

visionmade.ai shall notify the Controller without undue delay, and where reasonably practicable within 48 hours, after becoming aware of a Personal Data breach affecting Personal Data processed on behalf of the Controller. The notification shall include available information on the nature, likely consequences and measures taken to address the breach.

9. Assistance and Data Subject rights

visionmade.ai shall provide reasonable assistance to the Controller to enable the Controller to respond to Data Subject rights requests under applicable Data Protection Laws. Because Visitor conversations are normally linked to a session identifier rather than a name or email address, the Controller may need to obtain sufficient information from the Visitor to locate the relevant conversation.

10. Sub-processors

The Controller grants visionmade.ai general authorisation to engage Sub-processors. Authorised Sub-processors are listed in Schedule 3 of the full DPA document. visionmade.ai shall provide reasonable prior notice of any intended addition or replacement of a Sub-processor. visionmade.ai shall remain responsible to the Controller for the performance of its Sub-processors' data protection obligations.

11. International transfers

Conversation logs and application data are hosted in the European Union through EU-based infrastructure, including Hetzner and Supabase where configured in EU data centre regions.

Some Sub-processors or service providers may be established outside the EEA or the United Kingdom. In particular, OpenAI may process conversation messages through its API, and Cloudflare may process traffic through its global network. Where Personal Data is transferred outside the EEA or the UK, visionmade.ai shall ensure that appropriate safeguards are in place, including Standard Contractual Clauses or the UK International Data Transfer Addendum.

Personal data submitted to OpenAI through the API is not intended to be used by OpenAI to train or improve its models, unless visionmade.ai expressly enables such data sharing under the applicable OpenAI account settings.

12. Audit and compliance

visionmade.ai shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits where required by Data Protection Laws, subject to reasonable notice, confidentiality obligations and measures to avoid disruption to the Service.

13. Deletion and return of data

Upon termination or expiry of the Service, visionmade.ai shall delete or return Personal Data processed on behalf of the Controller in accordance with the Agreement and the Controller's documented instructions. Unless the Controller requests earlier deletion, conversation logs are retained by default for up to 12 months from collection or termination, after which they will be deleted or anonymised.

14. Aggregated and anonymised data

visionmade.ai may generate and use aggregated or anonymised data derived from the Service for product improvement, security, reporting and business intelligence, provided that such data cannot reasonably be used to identify an individual or the Controller's specific deployment.

15. Liability

Each party's liability under this DPA shall be subject to the limitations set out in the Agreement, except to the extent such limitations are prohibited by applicable Data Protection Laws.

16. Term and termination

This DPA shall remain in force for as long as visionmade.ai processes Personal Data on behalf of the Controller. Termination of the Agreement shall not affect obligations that by their nature are intended to survive, including confidentiality, deletion, audit records and liability provisions.

17. Changes to this DPA

visionmade.ai may update this DPA from time to time to reflect changes in law, providers or the nature of the Service. Where changes are material, visionmade.ai shall provide reasonable notice to active Controllers. Continued use of the Service after the effective date constitutes acceptance of the updated DPA.

18. Applicable data protection framework and governing law

This DPA is based on and shall be interpreted in accordance with Article 28 of the EU GDPR. Where the UK GDPR applies, references to the GDPR shall be read as references to the UK GDPR to the extent required by applicable law. The governing law of the Agreement shall apply to contractual matters not governed by mandatory Data Protection Laws.

Contact

For data protection matters: [email protected]
VISIONMADE AI LTD, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom