vega

Data Processing Addendum

The terms on which Vega processes personal data on a customer's behalf, the transfer clauses it relies on, and the security measures that are and are not in place.

version 1.0effective 2026-09-20

1The parties, and when this applies

This Data Processing Addendum ("DPA") forms part of the agreement between UNIWISE LLC, a Wyoming limited liability company, 360 Central Park West 7E, New York, NY, United States ("Vega", the processor), and the customer that has entered into Vega's terms of service as an organisation ("Customer", the controller).

No signature is required. This DPA becomes binding when Customer enters into that agreement, which is the same click-through construction Linear, Vercel and Anthropic use. Requiring a countersigned copy would mean Vega has no DPA in force with anyone, which is where it stood until this version.

Where this DPA and the agreement conflict on the processing of personal data, this DPA governs.

2Definitions

Applicable Data Protection Law
The GDPR, the UK GDPR together with the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), each to the extent it applies. Terms not defined here have the meaning given in the GDPR.
Customer Personal Data
Personal data that Vega processes on Customer's behalf under the agreement. Described in Annex I.
SCCs
The Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
UK Addendum
The International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, in force since 21 March 2022.
Subprocessor
A third party Vega engages to process Customer Personal Data on Customer's behalf. The current list is the subprocessor list, which is Annex III.

3Roles

For Customer Personal Data processed on Customer's instructions under the agreement, Customer is the controller and Vega is the processor.

For account administration, billing, security, abuse prevention and operating the service, Vega is a controller in its own right, and the privacy policy applies to that processing rather than this DPA.

The agreement, this DPA and Customer's use of the service are Customer's complete documented instructions. Vega will tell Customer if an instruction appears to infringe Applicable Data Protection Law, and may suspend that processing until it is resolved.

The subject matter, duration, nature, purpose and categories of data and data subjects are in Annex I.

4Training

Vega does not use Customer Personal Data, or any customer content, to train any model. This is not a setting and there is nothing for an administrator to opt into. Since 16 September 2026 the switch that would open Vega's training store is a constant in the source set to off, read before any connection detail, so no training write is possible on any plan; a test that ships with the code sets the connection details and proves the store still does not open. No plan in Vega's catalogue is marked as training on content.

Turning training on in future would be a reviewed change to the source, accompanied by a new major version of the privacy policy and a fresh consent request, and Customer would receive the notice in section 6 first.

5Security

Vega implements the technical and organisational measures in Annex II. Annex II states what is implemented and, separately and on the same page, what is not. Vega will not represent a measure as in place before it is.

Vega's personnel with access to Customer Personal Data are bound by confidentiality obligations.

6Subprocessors

Customer authorises the subprocessors on the subprocessor list, which is Annex III to this DPA.

Vega will publish a new subprocessor on that list at least 30 days before it begins processing Customer Personal Data, and will email account holders when it does. Customer may object within those 30 days on reasonable data-protection grounds; the parties will discuss it in good faith, and if it cannot be resolved Customer may terminate the affected part of the service.

Thirty days is a deliberate choice. It is longer than several comparable companies offer, because a customer reads the number and a short window is not a real opportunity to object.

7Data subject requests

Vega will not respond to a data subject request about Customer Personal Data itself, except to direct the person to Customer, unless legally required to respond.

Vega will assist Customer in responding, taking into account the nature of the processing. A person's own record can be exported from the product by that person, and Vega can produce the same export for Customer.

8Personal data breach

Vega will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information available at the time, and will provide reasonable assistance with Customer's own notification duties under Articles 33 and 34 GDPR.

9Assistance with assessments

Vega will provide Customer with information reasonably necessary for Customer's own data protection impact assessments and prior consultations, to the extent Customer cannot obtain it from Vega's published documents. The security page, the subprocessor list and Annex II of this DPA are written to answer most of it without a call.

10Deletion and return

At the end of the agreement Vega will, at Customer's choice, delete or return Customer Personal Data, subject to the retention periods in the privacy policy and to any retention Applicable Data Protection Law requires.

11Audit

On reasonable written request, and no more than once in any twelve-month period, Vega will provide the information reasonably necessary to demonstrate compliance with this DPA. That may be a summary of security practices, a completed security questionnaire, or a relevant certification once Vega holds one, in place of an on-site audit.

Where Applicable Data Protection Law gives Customer or a supervisory authority a right of on-site inspection that this clause does not satisfy, that right is not displaced by it.

12International transfers

Vega's database and application run in Tokyo, Japan. Every model step runs in Oregon, United States, on Amazon Web Services' Bedrock service, and files a person chooses to keep are stored there too. Transactional email is sent from the United States. Content therefore leaves Japan in the ordinary course of operating the service. There is no customer-selectable region.

Where Vega processes personal data originating in the EEA outside it, the parties incorporate the SCCs, Module Two (controller to processor), completed by Annex I of this DPA for Annexes I and II of the SCCs, with the Republic of Ireland as the governing law and forum where the SCCs require a choice. For transfers subject to UK data protection law the parties incorporate the UK Addendum. For transfers subject to Swiss law the SCCs apply as adapted by Swiss law, with references to the GDPR read as references to the FADP.

Japan holds an adequacy decision from the European Commission, which covers the storage leg. It does not cover the onward legs to the United States, which is what the clauses above are for.

Should Vega certify under the EU-U.S. Data Privacy Framework or an equivalent adequacy mechanism, that mechanism may be relied on in place of the SCCs for the transfers it covers, with the SCCs remaining in effect as a fallback.

13Liability, term and governing law

Each party's liability under this DPA is subject to the limitations of liability in the agreement.

This DPA remains in effect for as long as Vega processes Customer Personal Data on Customer's behalf. It is governed by the law that governs the agreement, except where Applicable Data Protection Law requires otherwise for the SCCs or the UK Addendum.

14Changes to this DPA

This DPA carries a version number and an effective date, both shown at the top, and every published version is kept so that "what was in force on this date" has an exact answer. A change that reduces the protection this DPA gives will be published at least 30 days before it takes effect, and account holders will be emailed.

This is version 1.0. It is the first DPA Vega has offered. Before it, the legal index said plainly that no DPA was available.

15Contact

Questions about this DPA, a request for a countersigned copy, a security questionnaire, or a data subject request: help@tryvega.tech.

UNIWISE LLC, 360 Central Park West 7E, New York, NY, United States.

16Annex I — the processing

ItemDescription
Subject matterProvision of Vega, a work-memory and usage-intelligence service, to Customer.
DurationThe term of the agreement, plus the retention periods in the privacy policy.
Nature and purposeCapturing moments of work from AI tools Customer's people already use; classifying them; deriving contexts, behavioural signals and archetypes; and presenting them to the person, and in aggregate to Customer's managers.
Categories of data subjectCustomer's employees, contractors and other authorised users of the service. Incidentally, third parties named inside captured content.
Categories of personal dataAccount identifiers (name, email address, workspace). Work content: prompts, model replies, titles, summaries, project labels, session references and, where a person has turned it on for a category, verbatim transcripts. Usage and telemetry: timestamps, durations, tool and connector identifiers, token estimates. Derived data: behavioural signal scores and an inferred archetype.
Special category dataNot sought and not knowingly processed. A personal-life filter runs before storage on every intake path and fails closed on error, which reduces the risk without eliminating it.
FrequencyContinuous, for as long as a connector is installed.
Competent supervisory authorityDetermined by Customer's own establishment; Vega has no EU establishment and no Article 27 representative appointed.

17Annex II — technical and organisational measures

Written to the Article 32 GDPR headings. Everything in the first table is true of the code today. Everything in the second table is published because a measures annex that omits its gaps is a misrepresentation, and because a buyer is entitled to price the difference.

In place.

MeasureWhat is actually there
Encryption in transitTLS throughout.
Encryption at restProvider-level at the database, plus application-layer AES-256-GCM on verbatim prompts and replies before the row reaches the database, a fresh initialisation vector per field, the authentication tag stored, and a refusal to store rather than store in the clear when the key is absent.
Data minimisation at ingestionA server-side topical filter drops personal-life content on every intake path and fails closed on classifier error or timeout.
Default-closed verbatim retentionVerbatim retention is off for every category by default and is authorised at one chokepoint that denies on any unknown.
Credential redactionPattern-based redaction of API keys, access tokens, cloud keys, bearer tokens, JWTs and private keys before storage.
Access controlSeat-scoped authorisation on every surface; owner-only material is excluded from manager, team, public and recruiting payloads rather than hidden in them.
Pseudonymisation for cross-account useProper nouns, organisations, sectors, amounts and counterparty roles are stripped before anything is used across accounts.
Aggregation floorNo cross-person figure below three contributors, from one constant used by every surface.
No static cloud credential for inferenceModel calls authenticate with one-hour credentials minted from the hosting platform's signed identity token on a role that grants two actions on named model ARNs.
Staff accountabilityAn append-only, content-free staff action log with a per-action field whitelist and hashed email addresses.
Customer-visible auditCompany visibility changes are logged, protected by database trigger against edit and delete, and readable by any member.
Secret hygieneConnector tokens are stored as SHA-256 hashes with a non-secret prefix. Vega holds no third-party credentials.
PortabilityA person can export their own record from the product, and Vega can produce the same export for Customer.
Containment on deletionDeleting an account releases its company seats rather than destroying them, so one person cannot delete a company's work.
Baseline HTTP hardeningnosniff, frame denial, a referrer policy, and camera, microphone and geolocation denied.
No trackingNo analytics, advertising, session-recording or error-reporting third party in the application.

Not in place. Do not read these as measures.

MissingConsequence
Per-account encryption keys, and key rotationOne key encrypts every account's verbatim text and Vega holds it. One leaked key is every account. There is no rotation procedure and no per-tenant separation.
Key custody and escrowThe key exists in one place, in one hosting provider's environment, write-only. There is no second copy and no documented recovery, so the same design that protects the transcripts can also strand them.
Negotiated zero-retention terms with model hostsContent sits with Amazon Web Services under its standard terms. Its published no-storage default is quoted and dated on the subprocessor list; it is a published default, not a term Vega holds.
A retention or purge job for contentContent is kept until deleted. The short clocks that exist cover ancillary records only.
Row-level logging of staff readsStaff can read customer content. The log records the page opening, not the rows.
Database-level immutability on the staff logThe staff log has no database constraint and logging is best-effort. The customer-facing company log has both.
Row-level security on some tablesIncluding the table that holds previews of content the personal-life filter judged personal.
Certification, external audit, penetration testNone, and no date by which there will be.
Incident responseNo runbook, no on-call rotation, no detection beyond provider logs. This is why section 8 says "without undue delay" rather than a number.
Proven restoreBackups exist. A restore has never been drilled, so "we have backups" is not yet "we can come back".
Residency choiceTokyo for storage, Oregon for every model call. No customer can choose otherwise.
Organisation-level privacy controlsEvery privacy control belongs to the individual. A customer administrator cannot govern their own members' settings.

18Annex III — subprocessors

Annex III is the subprocessor list, which is maintained as a published page rather than reproduced here, so that a customer reads the current list and not a copy of it that has gone stale. It names every company, what each receives, and where it is.

At the effective date of this version those companies are Supabase (database, authentication and file storage, in Tokyo), Amazon Web Services (the infrastructure beneath Supabase in Tokyo, and model inference plus file storage in Oregon), Vega's application hosting provider, Anthropic (the author of the models, which receives content only on a fallback route that is off by default), Resend (transactional email) and Stripe (payment, on Stripe's own hosted page).