WhyVault

Data processing agreement (DPA)

Version of 25 September 2026

This English version is a translation for your convenience. Only the German version is legally binding. Read the German version

1. Parties and conclusion

This agreement applies between the business using WhyVault (“customer”, controller) and

Ohrlaf GmbHReichholz 187634 ObergünzburgGermany

(“processor”, “we”). It specifies both parties' data protection obligations arising from the use of WhyVault under the Terms of Service (main contract).

This agreement becomes part of the main contract as soon as the customer uses WhyVault as a business (§ 10 of the Terms); no signature is required, the electronic format suffices (Art. 28(9) GDPR). On request we send the customer a signed copy – write to hello@whyvault.io.

2. Subject matter, duration, nature and purpose

The subject matter is storing and providing the content the customer puts into WhyVault (notes, files, folders, versions, history), including handing it to AI assistants the customer connects, and support.

Nature of processing: collection, storage, organisation, adaptation, retrieval, consultation, transmission to assistants connected by the customer, export, erasure.

Purpose: providing WhyVault under the main contract.

The duration corresponds to the term of the main contract. Obligations that extend beyond its end (deletion, confidentiality) continue to apply.

3. Types of data and data subjects

The customer alone decides which personal data the content contains. Typically these are:

  • contact and master data (names, roles, email addresses, phone numbers, addresses);
  • content of communication, meetings, projects and decisions;
  • data in attached files (e.g. images, documents);
  • usage data of the customer's accounts (sign-in, history of changes, connected assistants).

Data subjects are in particular the customer's employees, customers, prospects, business partners and other contacts, and the users of its account.

The customer should only store special categories of personal data (Art. 9 GDPR) and data on criminal convictions (Art. 10 GDPR) if it has a legal basis for this and considers the measures in Annex 1 sufficient.

4. Instructions

We process the data only on documented instructions from the customer, including with regard to transfers to third countries, unless required to do so by EU or German law; in that case we inform the customer before processing, unless that law prohibits it (Art. 28(3)(a) GDPR).

The instructions follow from the main contract, this agreement and the customer's use of WhyVault (such as creating, changing, exporting or deleting content and connecting assistants). The customer gives further instructions in text form to hello@whyvault.io.

If we believe an instruction infringes data protection law, we inform the customer without undue delay and may suspend its execution until the customer confirms or changes it.

5. Confidentiality and personnel

Only persons who have committed themselves to confidentiality or are under a statutory obligation of confidentiality have access to the data (Art. 28(3)(b) GDPR). Currently this is only the managing director.

We only look at content if the customer asks us to (support), if we are legally required to, or if it's necessary to fend off a malfunction or specific abuse.

6. Security of processing

We take the technical and organisational measures under Art. 32 GDPR described in Annex 1. We may develop them further as long as the level of protection does not decrease; we document material changes.

7. Sub-processors

The customer grants us general authorisation to engage sub-processors (Art. 28(2) GDPR). The sub-processors engaged at conclusion are listed in Annex 2 and are deemed approved.

We inform the customer by email at least four weeks in advance of any intended changes (addition or replacement). The customer may object within this period for good cause under data protection law. If we cannot resolve the objection, the customer may terminate the main contract as of the change.

We contractually bind sub-processors to a level of protection equivalent to this agreement (Art. 28(4) GDPR) and remain responsible to the customer for them.

Ancillary services such as telecommunications or payment processing, and AI assistants the customer connects itself, are not sub-processing: they receive content on the customer's instructions and process it under the customer's contract with their provider.

8. Transfers to third countries

We store the content in Frankfurt (EU). Transfers to third countries, such as access by sub-processors for maintenance and support, only take place under the conditions of Art. 44 et seq. GDPR – based on an adequacy decision (EU-US Data Privacy Framework) or the EU Standard Contractual Clauses. Annex 2 names the respective basis.

9. Assisting the customer

We assist the customer with appropriate measures in responding to data subject requests (Art. 12–22 GDPR). The customer can do much of this itself: search, change, export and delete content. If a data subject contacts us directly, we forward the request to the customer.

We also assist the customer with the security of processing, notifications of personal data breaches, data protection impact assessments and prior consultations with the supervisory authority (Art. 32–36 GDPR), in each case within the information available to us.

10. Personal data breaches

If we become aware of a breach affecting the customer's data, we inform the customer without undue delay, if possible within 24 hours and at the latest within 48 hours of becoming aware, by email to the address of its account.

The notification contains, as far as known, the information under Art. 33(3) GDPR: nature of the breach, categories and approximate number of data subjects and records, likely consequences and measures taken or proposed. We provide missing information without undue delay. We immediately take the measures necessary for containment.

11. Deletion and return

The customer can export its content at any time as a zip of Markdown files and attachments – this is the return within the meaning of Art. 28(3)(g) GDPR.

After the main contract ends, we delete all customer data within 30 days at the latest, unless a legal obligation requires retention. If the customer deletes its account itself, this happens immediately. Where backups exist, the data is removed from them when they are overwritten, within 7 days at the latest. On request we confirm the deletion in text form.

12. Evidence and audits

On request we provide the customer with all information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits (Art. 28(3)(h) GDPR).

As evidence, this agreement with Annex 1, written information and the certifications and reports of our sub-processors usually suffice. The customer agrees further audits, including on-site, with us with reasonable notice (at least four weeks); they take place during business hours, without disrupting operations, and by auditors bound to confidentiality. The customer bears the costs unless the audit reveals a material breach on our part.

13. Liability and final provisions

Liability is governed by Art. 82 GDPR; otherwise the rules of the main contract apply.

In case of conflict between this agreement and the main contract, this agreement prevails on data protection matters. German law applies. If a provision is invalid, the rest of the agreement remains valid.

Annex 1 – Technical and organisational measures

Confidentiality (Art. 32(1)(b) GDPR)

  • Physical access: we don't run our own servers. The data centres of our sub-processors (AWS Frankfurt for Supabase; Vercel) are audited against recognised standards such as ISO/IEC 27001 and SOC 2.
  • System access: users sign in via email link, one-time code or password (at least 12 characters, checked against known data breaches); captcha against automated sign-in attempts; security notifications by email when password or address change. Administrative access only for the managing director.
  • Data access: separation of accounts in the database via row level security – every request only sees the data of its own account; keys with server privileges only on the server, never in the browser. Access tokens for assistants only as hashes, individually revocable, optionally read-only.
  • Separation: each customer has its own vault; data of different customers is logically separated. Automated tests only use their own test accounts, which are deleted afterwards.
  • Encryption: in transit via TLS (HSTS enforced), at rest with AES-256.
  • Pseudonymisation: access tokens and passwords are only stored as hashes.

Integrity (Art. 32(1)(b) GDPR)

  • Input control: every change is stored as a version with time, author (user or named connection) and description in the history and can be restored.
  • Writes only go through vetted database functions; direct writes to notes, versions and history are technically blocked.
  • Transfer control: transfers only encrypted; content only goes to assistants the customer connects itself. Assistants cannot delete notes; writes are limited to 30 per minute and connection.
  • Strict content security policy and further security headers against code injection.

Availability and resilience (Art. 32(1)(b) and (c) GDPR)

  • Operation with established cloud providers on redundant infrastructure.
  • Versioning of all changes, trash for deleted notes and export by the customer at any time.
  • Limits on uploads, writes and emails against overload and abuse.

Regular testing and evaluation (Art. 32(1)(d) GDPR)

  • Automated tests check, with every change, among other things the separation of accounts, database privileges and plan limits.
  • Security reviews of code and configuration, most recently in September 2026, including checking all dependencies for known vulnerabilities.
  • Processor control: sub-processors only with an agreement under Art. 28 GDPR (Annex 2).

Annex 2 – Sub-processors

At conclusion we engage these sub-processors:

  • Supabase

    DPA
    Service
    Database, file storage and sign-in (hosting your notes and account)
    Provider and location
    Supabase Pte. Ltd., 65 Chulia Street #38-02/03, Singapore 049513; data is stored in Frankfurt (AWS eu-central-1). Transfers based on the EU Standard Contractual Clauses.
    Role
    Processor
  • Vercel

    DPA
    Service
    Hosting of website and app, server functions, visitor statistics
    Provider and location
    Vercel Inc., 440 N Barranca Ave, Suite 4133, Covina, CA 91723, USA; server functions in Frankfurt (fra1), delivery via a global network (CDN). Certified under the EU-US Data Privacy Framework, plus EU Standard Contractual Clauses.
    Role
    Processor
  • Plunk

    DPA
    Service
    Sending sign-in links, account emails and – with consent – news
    Provider and location
    Storage in the EU (Hetzner, Germany); delivery via Amazon SES, which may pass servers outside the EU in transit only (EU Standard Contractual Clauses).
    Role
    Processor
  • Google Workspace

    DPA
    Service
    Our mailbox hello@whyvault.io – support and feedback
    Provider and location
    Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland; parent Google LLC (USA) is certified under the EU-US Data Privacy Framework.
    Role
    Processor

Stripe/Link (selling the Pro subscription, independent controller), Cloudflare Turnstile (captcha on the sign-in forms, no customer content) and Have I Been Pwned (no personal data) do not act as sub-processors for customer content. Details are in the privacy policy.