Data Processing Agreement (DPA)

Last updated: 22 July 2026

This Data Processing Agreement (DPA) forms part of the contractual relationship between Client Company (Controller) and APPVECTO S.R.L. (provider of Vecto HR and data processor under the GDPR), for use of the Vecto HR SaaS platform.

1. Contracting parties

The data controller is the Client Company — the organization that creates the account and uses the Vecto HR application for human resources management, hereinafter referred to as the Controller.

The processor is APPVECTO S.R.L., CUI 54906519, registered office: Strada Agricultorilor nr. 18, Subsol Tehnic, Spațiu Tehnic 2, 707085 Lunca Cetățuii, Iași, România, which processes personal data exclusively on behalf of and in accordance with the Controller's instructions, within the meaning of Regulation (EU) 2016/679 (GDPR). Contact: contact@appvecto.com, support: support@appvecto.com.

2. Subject and duration

Processing takes place through the Vecto HR platform, for human resources management: employee records, payroll, time tracking, personnel documents, reports, occupational health and safety (OHS), and related features.

Processing lasts for the active subscription period and, where applicable, for the archiving period required by law or the Controller's documented instructions.

3. Types of data and data subjects

  • identification data (first name, last name, national ID/CNP, ID card series and number);
  • contact data (address, phone, email);
  • banking data (IBAN, bank) for salary transfers;
  • professional data (job title, department, salary, seniority, time records);
  • medical data only to the extent necessary for OHS (medical clearances, fitness certificates), upon the Controller's instruction;
  • data subjects: employees, contractors, authorized users of the Controller.

4. Documented instructions

The Processor processes data only on the basis of the Controller's documented instructions, including through organization configuration in the application, the Terms and Conditions, this DPA, and reasonable written requests.

If the Processor considers that an instruction infringes the GDPR or other data protection provisions, it will inform the Controller without undue delay.

5. Confidentiality

The Processor ensures that persons authorized to process data are bound by confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Technical and organizational measures

  • AES-256-GCM encryption for selected sensitive data (e.g. CNP, IBAN) where used in the implementation;
  • role-based access control (RBAC) and multi-tenant isolation between organizations;
  • authenticated sessions (httpOnly cookies) and CSRF protection;
  • audit log for relevant security and compliance actions;
  • periodic backups according to the platform's technical configuration.

7. Sub-processors

The Controller generally authorizes use of the sub-processors listed below, with equivalent data protection contractual obligations. The Processor will inform the Controller of material changes to the list through documentation updates or reasonable notice, as applicable.

  • Stripe — payment processing and subscription management;
  • Vercel — application hosting;
  • Neon — PostgreSQL database;
  • Cloudflare R2 — file storage (documents, backups);
  • Resend — platform default transactional email delivery.
  • An email provider configured by the Controller (SMTP) may be used for notifications; it is chosen and administered by the Controller.

8. International transfers

Some sub-processors may process data outside the European Economic Area, depending on the infrastructure used. Where required, transfers rely on appropriate safeguards under GDPR Chapter V (for example Standard Contractual Clauses or other permitted mechanisms), as set out in applicable contracts, DPAs, and provider documentation. The Processor does not represent that a specific mechanism applies to every provider without documentary confirmation.

9. Assistance with data subject rights

The Processor provides reasonable assistance to the Controller in fulfilling obligations regarding data subject requests (access, rectification, erasure, etc.), to the extent technically feasible and within the platform's features.

Requests sent directly to the Processor will be redirected to the Controller, unless law or agreement permits a direct response.

10. Security incidents and breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting data processed on behalf of the Controller, with available information to enable the Controller to meet its legal obligations.

11. Deletion, return, and export

Upon termination of the contract or at the Controller's documented request, the Processor deletes or returns data according to instructions, except categories under confirmed legal retention, LEGAL_REVIEW_REQUIRED, or ACTIVE legal hold.

Eligible temporary and access data may be deleted immediately; accounting records use the confirmed 1 July + 5 years formula only when classified as such. Organization closure may remain RETAINED_LEGAL or PARTIAL_FAILED until R2, Stripe, email and backup stages are verified.

Backups are not selectively wiped mid-cycle; expiry follows the approved backup policy, and restore re-applies GDPR tombstones before the application becomes usable.

Article 19 notices to recipients are recorded on the existing GdprRequest stage results (no duplicate registry). Inbox copies at third-party recipients may be outside technical control — documented as such.

If the Controller does not respond to an EMPLOYEE_ERASURE request, the Processor escalates and keeps WAITING_CONTROLLER / RETAINED_LEGAL — it does not auto-erase HR data.

The Controller may export data through features available in the platform before termination.

12. Audit and cooperation

The Controller may request information necessary to demonstrate GDPR compliance. On-site audits or extended system access are conducted on reasonable terms, with prior notice, taking into account security of other clients and infrastructure.

13. Liability

The parties' liability regarding data protection is governed by the Terms and Conditions and applicable law. Nothing in this DPA limits data subject rights or mandatory obligations under the GDPR.

14. Electronic acceptance

This agreement is accepted electronically by the Controller upon registration in the application, by checking the mandatory DPA acceptance box. The date and user identifier are recorded in the organization's dpaAcceptedAt and dpaAcceptedBy fields.

15. Related documents

For additional details about privacy, terms, and data-subject rights, see Privacy Policy, Terms and conditions and GDPR rights.

Document updated on 22 July 2026. For questions about processing at platform level: contact@appvecto.com. For employee data, contact your organization's HR administrator.

Privacy Policy · Terms and conditions · GDPR rights · DPA Agreement ·

Data Processing Agreement (DPA) | Vecto HR | Vecto HR