Data-processing framework
The processing terms to complete with a customer before a project uses sensitive, regulated or customer-controlled personal information. This framework is not a claim of automatic GDPR certification or a substitute for a signed project schedule.
On this page
Roles, scope and instructions
The customer determines purposes and lawful instructions for its workspace data; Vibeful processes that data to provide the agreed service. Each acts independently for its own administration and statutory obligations. A signed schedule must identify parties, processing duration, purposes, data categories, affected people, approved locations, providers and deletion requirements.
Instructions must be documented. We will flag an instruction we reasonably believe unlawful and pause the affected processing while it is resolved. The customer supplies required notices and permissions and must not ask for excessive or unrelated processing.
Confidentiality and safeguards
Access must be limited to authorized personnel with confidentiality duties. Relevant measures include transport encryption, credential encryption, access control, separation of workspaces and operational logging. A project must separately specify any required backup, recovery, audit, residency, vulnerability-management or enhanced security commitments. Do not assume unimplemented certifications or guarantees.
Providers and transfers
The provider schedule must identify Cloudflare, any enabled AI provider such as Anthropic, connected email providers and other processors used for the project, with their functions and relevant locations. Providers require appropriate contractual obligations. Where applicable, changes must be notified with an agreed opportunity to object or resolve the impact.
Cross-border processing requires the applicable assessment, notice, contract or transfer mechanism. No general website clause is itself an EU transfer instrument or Quebec privacy impact assessment. Do not start a project needing those controls before they are established.
Rights, incidents and assistance
Requests received about customer-controlled data should be referred to the customer where appropriate, while preserving Vibeful’s own duties. The parties will cooperate on lawful access, correction, portability, objections and deletion. Response responsibilities and contacts belong in the schedule.
A confirmed incident affecting customer data must be notified to the customer without undue delay after awareness, with available facts, affected data, likely consequences and mitigation updates. Each party must meet its applicable regulator/individual notification and recordkeeping duties; this clause does not replace statutory deadlines.
End of processing and verification
At the end of service, the customer chooses return or deletion where permitted, subject to documented legal retention and practical backup cycles specified in the schedule. Continued retained processing must be restricted to its justified purpose.
Provide reasonable information needed to demonstrate agreed obligations. Audits, if required, should protect other customers’ data, security and provider restrictions and have a defined scope and procedure. Mandatory regulator powers are unaffected. Any special cost or liability allocation must be explicitly agreed.