Skip to content

Legal

Data Processing Agreement

Last updated 25 August 2026

This page publishes Vorx Ltd's ("Vorx", "Processor") standard framework Data Processing Agreement ("DPA"), made available for customers' pre-contract due diligence. It supplements our Terms of Service and Privacy Policy and reflects how Vorx processes personal data on a customer's ("Controller") behalf when the customer uses the Platform to build and operate an application, and where the personal data involved is subject to the GDPR or a similar data-protection law.

This page is a framework reference, not a signed contract. If your organization needs an executed, counter-signed DPA — for example naming your entity as Controller and incorporating your own required terms — contact legal@vorx.com.

1. Subject matter and duration

This DPA applies for as long as Vorx processes personal data on the Controller's behalf under the Terms of Service, and covers personal data the Controller or its own end users submit to, or that is generated by, the Platform — including data entered into the Controller's Vorx account and data collected by an application the Controller builds on Vorx, where that application uses Vorx-provided backend infrastructure.

2. Nature and purpose of processing

Vorx processes personal data to provide the Platform: generating, hosting, and operating applications the Controller builds; storing files and backend data the Controller's application collects; sending transactional communications; and providing customer support. Processing is limited to what these purposes require.

3. Categories of data subjects and personal data

Data subjects may include the Controller's own team members (Vorx account users) and, where the Controller's application collects it, that application's own end users or visitors.

Categories of personal data depend entirely on what the Controller builds and configures, and can include: account identifiers (name, email), authentication data, content submitted through forms or app features, uploaded files, and technical/usage data (IP address, device information). Vorx does not control what personal data a Controller's application is designed to collect — that determination, and the legal basis for it, is the Controller's responsibility as Controller.

4. Processor obligations

Vorx will:

  • process personal data only on the Controller's documented instructions, including regarding international transfers, unless required to do otherwise by law (in which case Vorx will inform the Controller before processing, unless prohibited from doing so);
  • ensure persons authorized to process the personal data are subject to confidentiality obligations;
  • implement appropriate technical and organizational security measures (see §6);
  • assist the Controller, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations around security, breach notification, and data protection impact assessments, to the extent reasonably required;
  • at the Controller's choice, delete or return personal data at the end of the provision of services, except where retention is required by law; and
  • make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality.

5. Subprocessors

The Controller authorizes Vorx to engage the subprocessors listed on our Subprocessors page, which we keep current as our infrastructure changes. Vorx imposes data-protection obligations on each subprocessor materially equivalent to those in this DPA and remains liable for their performance. Contact legal@vorx.com to arrange advance notice of new subprocessors for your account, and to raise an objection.

6. Security measures

Vorx maintains technical and organizational measures designed to protect personal data, consistent with those described in our Privacy Policy — including encryption in transit, access controls scoped to what each service needs, and monitoring. The specific measures in place at any time are described in more detail in our Security overview and available to enterprise customers under NDA on request.

7. Personal data breach notification

Vorx will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably available to us to help the Controller meet its own notification obligations.

8. International transfers

Where personal data is transferred outside the EEA/UK to a subprocessor, Vorx relies on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism, as applicable to that subprocessor and jurisdiction.

9. Liability and precedence

Liability under this DPA is subject to the limitations set out in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA governs.

10. Governing law

This DPA is governed by the laws of Ireland, consistent with the Terms of Service.

11. Requesting an executed DPA

To request a countersigned version of this DPA for your organization, or to ask questions about any section, contact legal@vorx.com.