Data Processing Agreement (DPA) — Vasco

Last updated: May 9, 2026

This Data Processing Agreement ("DPA") supplements the Vasco Terms of Service and Privacy Policy. It applies when Vasco processes personal data on behalf of its users under the General Data Protection Regulation (GDPR).


1. Definitions


2. Scope and Purpose

Vasco processes personal data on your behalf for:


3. Data Processing Details

Category Data Types Purpose Retention
Customer contacts Name, email, phone, address CRM, invoicing Account lifetime
Financial records Invoices, quotes, payments Business management 7 years (tax law)
Job records Descriptions, schedules, photos Job management 5 years
Time tracking Clock-in/out, hours worked Payroll, costing 5 years
AI learning Interaction patterns, preferences Personalization Account lifetime

4. Processor Obligations

Vasco shall:


5. Authorized Sub-Processors

You provide general authorization for the following sub-processors:

Sub-Processor Purpose Location Safeguards
Supabase Inc. Database hosting, authentication, edge functions EU (AWS Ireland) SCCs, SOC 2
Mollie B.V. Payment processing (EU contractors, EUR) Netherlands PCI DSS, GDPR compliant
Stripe Payments Europe Ltd. Payment processing (UK contractors, GBP) Ireland PCI DSS, GDPR compliant
Resend Inc. Transactional email (invoices, reminders) USA + EU SCCs, SOC 2
Anthropic PBC Photo analysis (Claude Vision) USA SCCs, no data retention
Functional Software Inc. (Sentry) Error reporting (optional) USA SCCs, EU residency available
Expo Inc. Push notification delivery, OTA updates USA SCCs
Amazon Web Services Infrastructure (via Supabase) EU (Ireland) SCCs, ISO 27001

We will notify you of any changes to sub-processors at least 30 days in advance. You may object to a new sub-processor by contacting us within 14 days.


6. Security Measures

Vasco implements:


7. Data Subject Rights

When you receive a data subject request (access, rectification, erasure, portability, restriction, objection), we will:


8. Data Breach Notification

In the event of a personal data breach, we will:


9. International Transfers

For data transfers outside the EU/EEA:


10. Audit Rights

You may:


11. Term and Termination

This DPA remains in effect for the duration of our processing of personal data on your behalf. Upon termination of the service agreement:


12. Contact

Data Protection Contact: privacy@vascobuild.com Legal Contact: legal@vascobuild.com