Legal
Data Processing Agreement
Vizum Apps — Managed AI and hosted retrieval Version 1.0 · Effective date: 29 August 2026 Language: English. A Spanish version is published at /es/dpa. See clause 16.6.
1. The parties, and why this agreement exists
1.1. This Data Processing Agreement (the "DPA") is entered into between:
(a) you, the customer identified in the account through which the Services are used (the "Customer"), acting as controller — responsable del tratamiento under Colombian law; and (b) Enrique Echeverría, a natural person trading as Vizum Apps, with establishments in Colombia and the United States of America ("Vizum"), acting as processor — encargado del tratamiento.
1.2. It forms part of the Terms of Service at /terms (the "Agreement") and applies whenever Vizum processes personal data on the Customer's behalf.
1.3. Vizum is a natural person and not an incorporated entity at the date of this version. Clause 16.2 governs what happens when that changes.
1.4. Acceptance. This DPA is accepted by the same acts that accept the Agreement, and in any event by transmitting Customer Personal Data to the Managed AI service. Where the Customer requires a signed counterpart, write to support@vizumapps.com and one will be provided.
2. What this DPA covers, and what it does not
2.1. This DPA covers only processing in which Vizum acts as processor. That is:
(a) the inference path — prompts, text submitted for embedding, images submitted for optical character recognition, and media submitted for transcription, transmitted through Vizum's service to an AI provider; this occurs in every configuration in which the Customer uses Managed AI; and (b) hosted retrieval storage — vectors, chunk text and original documents stored on Vizum's infrastructure, only where the Customer has set retrieval residency to managed (clause 5).
2.2. This DPA does not cover, because Vizum is not a processor of it:
(a) the Customer's Odoo database. The Platform Software runs on the Customer's own infrastructure. Vizum does not receive, store or have access to the business data it processes, and no processor relationship arises over it; (b) retrieval storage in local or pgvector residency, which remains inside the Customer's own database and PostgreSQL; (c) data processed by a third-party vApp for its own purposes. That relationship is between the Customer and the Developer, and Vizum is not party to it; (d) personal data for which Vizum is itself the controller — the Customer's account, instance registration, billing relationship, desktop telemetry and security logs. That processing is governed by Vizum's privacy notice, not by this DPA. Clause 14 addresses it separately so that the boundary is visible rather than assumed.
2.3. Order of precedence. For matters of personal data processing, this DPA prevails over the Agreement. Where the Customer's own data processing agreement has been negotiated and signed by Vizum, that signed instrument prevails over this one.
3. Definitions
3.1. "GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as retained in United Kingdom law.
3.2. "Colombian Data Protection Law" means Ley 1581 de 2012, Decreto 1074 de 2015 (which compiles Decreto 1377 de 2013), and the binding circulars of the Superintendencia de Industria y Comercio ("SIC").
3.3. "Customer Personal Data" means personal data within Customer Content that Vizum processes under clause 2.1.
3.4. "Sub-processor" means a third party engaged by Vizum to carry out processing activities on Customer Personal Data.
3.5. "SCCs" means the standard contractual clauses in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
3.6. "controller", "processor", "data subject", "processing", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. Responsable, encargado, titular and dato personal have the meanings given in Ley 1581 de 2012.
3.7. Terms defined in the Agreement and not redefined here carry their meaning from the Agreement.
4. Roles, and the allocation of responsibility
4.1. The Customer is the controller. The Customer determines the purposes and means of processing Customer Personal Data, decides what to send, decides which model receives it, and decides where retrieval storage resides.
4.2. Vizum is the processor, and processes only as instructed under clause 6.
4.3. The Customer's own obligations, which Vizum cannot discharge for it. The Customer warrants that:
(a) it has a lawful basis for the processing it instructs — under Article 6 GDPR, and under Colombian law the prior, express and informed authorisation of the titular required by Article 9 of Ley 1581 de 2012, unless an exception applies; (b) it has given data subjects the information required by Articles 13 and 14 GDPR, and the aviso de privacidad required by Article 12 of Decreto 1377 de 2013, including the fact that their data is transmitted to processors located in the United States; (c) the instructions it gives do not cause Vizum to breach applicable law; (d) it has the right to transfer Customer Personal Data to Vizum for processing.
4.4. Neither party acts as the other's representative under Article 27 GDPR, and neither is a joint controller with the other in respect of the processing covered by this DPA.
5. Residency: the Customer's choice, and its legal consequence
5.1. Retrieval storage operates in one of three residencies, set by the Customer:
| Residency | Where vectors and original documents live | Vizum's role for stored content |
|---|---|---|
local |
The Customer's own Odoo database and filestore | None |
pgvector |
The Customer's own PostgreSQL | None |
managed |
Vizum's infrastructure, in the United States | Processor |
5.2. Inference is not affected by that choice. In every residency, the content of a request is transmitted through Vizum to an AI provider. Vizum is the Customer's processor for that transmission in all three modes.
5.3. A behaviour with a data-protection consequence, which Vizum states rather than leaves to be discovered. If the Customer changes residency, originals written before the change remain where they were written. Switching from managed to local does not move or delete what Vizum already holds. The Customer must use the deletion mechanisms in clause 11 to remove it. Vizum's deletion obligations under clause 11 extend to that pre-switch residue, and Vizum will not treat a residency change as having discharged them.
6. Processing on documented instructions — GDPR Article 28(3)(a)
6.1. Vizum processes Customer Personal Data only on the Customer's documented instructions, including as to transfers to a third country, unless required to do so by Union, Member State, Colombian or United States law to which Vizum is subject.
6.2. The documented instructions are: this DPA, the Agreement, the configuration the Customer sets in the product (residency, permitted models, default model, retention settings, any provider key it supplies), and the API requests the Customer's Instance transmits. No other instruction is implied.
6.3. Vizum processes Customer Personal Data only to provide, secure and maintain the Managed AI service. Vizum does not process it for its own purposes, does not sell it, and does not use it for advertising or profiling.
6.4. Vizum does not train any model on Customer Personal Data.
6.5. Where required to process by law, Vizum will inform the Customer of that requirement before processing, unless the law prohibits the notification on important grounds of public interest.
6.6. Vizum will inform the Customer if, in its opinion, an instruction infringes the GDPR, Colombian Data Protection Law or another applicable data protection provision. Vizum may suspend the affected processing until the instruction is withdrawn, amended or confirmed.
7. Confidentiality — GDPR Article 28(3)(b)
7.1. Vizum ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7.2. Access is limited to those who need it to provide, secure or maintain the service, and is limited to what they need.
7.3. A fact the Customer is entitled to know. Vizum is currently operated by a natural person with a small number of assisting personnel. There is no separation-of-duties control that a larger organisation would provide, and the operator has administrative access to the production systems. The controls that do exist are described in Annex II.
7.4. These obligations survive termination.
8. Security — GDPR Article 28(3)(c) and Article 32
8.1. Vizum implements the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to data subjects.
8.2. Annex II states measures that are in place and verified. It does not state aspirations. Measures that are absent are named in Annex II §5, so that the Customer can assess the risk rather than infer an assurance.
8.3. The Customer is responsible for its own side: securing its Odoo instance, managing its users' access rights, protecting its instance token and account credentials, and deciding what it is appropriate to send to a third-party processor.
8.4. Vizum may update the measures in Annex II. An update must not reduce the overall level of security.
9. Sub-processors — GDPR Article 28(3)(d) and Article 28(2)
9.1. The Customer gives a general authorisation for Vizum to engage Sub-processors, subject to this clause 9.
9.2. The Sub-processors engaged at the date of this version are listed individually in Annex III, with function and location.
9.3. Vizum imposes on each Sub-processor, by contract, data protection obligations that are in substance those of this DPA, and remains fully liable to the Customer for a Sub-processor's performance.
9.4. A limitation on clause 9.3 that Vizum states plainly. For the AI providers listed in Annex III §2, Vizum has not negotiated bespoke data processing agreements. The obligations that bind those providers are their own standard published terms and data processing addenda for the account through which a request runs. Vizum has not obtained an instrument that mirrors this DPA clause for clause, and does not represent otherwise. The Customer should read this together with clause 12.6 of the Terms of Service before sending regulated or sensitive content. Vizum is pursuing those agreements and will update Annex III.
9.5. The Customer's configuration determines which Sub-processor receives its content. The Customer selects the model per application. Vizum does not warrant that Customer Personal Data goes to one AI provider rather than another; it goes to the provider that serves the model the Customer selected.
9.6. Where the Customer supplies its own provider key, the request runs against the Customer's own account with that provider, under the Customer's own contract with them. That provider is then the Customer's own processor or controller, not Vizum's Sub-processor, and clause 9.3 does not apply to it.
9.7. Notice of change. Vizum will give the Customer at least thirty (30) days' notice before adding or replacing a Sub-processor that will process Customer Personal Data, by email to the account address and by updating Annex III.
9.8. Objection. The Customer may object on reasonable data protection grounds within thirty (30) days of the notice. The parties will discuss in good faith. If no resolution is reached, the Customer may terminate the Managed AI service without penalty and receive a refund of unspent prepaid balance and of any prepaid fee for the unused period. Terminating is the Customer's remedy; Vizum is not obliged to keep an alternative provider in service.
9.9. Urgent replacement. Where a Sub-processor must be replaced urgently for security or continuity, Vizum may do so with immediate effect and will notify the Customer without undue delay, and clause 9.8 then applies retrospectively.
10. Assisting the Customer — GDPR Article 28(3)(e) and (f)
10.1 Data subject rights
10.1.1. Taking into account the nature of the processing, Vizum assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise rights under Chapter III GDPR, and the rights of the titular under Article 8 of Ley 1581 de 2012.
10.1.2. The Customer can exercise most of these rights itself, immediately, without asking Vizum, and this is the primary mechanism:
| Right | Mechanism available to the Customer |
|---|---|
| Access and portability | Export of all managed vectors, chunk text, metadata and original documents, through the export endpoint exposed to the Instance |
| Erasure | Delete a document, delete by identifier, or purge an entire namespace, through the deletion endpoints exposed to the Instance |
| Rectification | Delete and re-index the corrected document |
| Restriction | Change residency, or remove the content from managed storage |
10.1.3. Where the Customer cannot satisfy a request through those mechanisms, Vizum will assist on request. Vizum will respond to a documented assistance request within ten (10) business days.
10.1.4. If a data subject contacts Vizum directly, Vizum will not respond to the substance of the request. Vizum will redirect the data subject to the Customer and inform the Customer without undue delay, unless legally required to act otherwise.
10.1.5. Assistance under clause 10.1.3 is provided at no charge unless requests are manifestly unfounded, excessive or repetitive, in which case Vizum may charge a reasonable fee, notified in advance.
10.2 Personal data breaches
10.2.1. Vizum notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event within forty-eight (48) hours of becoming aware of it. That period is set so that the Customer can meet its own 72-hour obligation under Article 33 GDPR.
10.2.2. The notification will describe, so far as known at the time: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a point of contact. Where the information is not available at once, it will be provided in phases without further undue delay.
10.2.3. Vizum will not delay notification in order to complete its investigation.
10.2.4. Vizum will take reasonable steps to contain and remediate, and will preserve evidence.
10.2.5. Vizum does not notify supervisory authorities or data subjects on the Customer's behalf. Those are the controller's decisions and the controller's obligations.
10.3 Impact assessments and prior consultation
10.3.1. Vizum provides reasonable assistance with data protection impact assessments under Article 35 GDPR and prior consultation under Article 36, taking into account the nature of the processing and the information available to Vizum.
10.3.2. This DPA, its Annexes, and the public documentation are intended to supply the information a Customer needs to complete an assessment. Where more is needed, ask at support@vizumapps.com.
11. Return and deletion — GDPR Article 28(3)(g)
11.1. On termination of the Managed AI service, or at the Customer's request at any time, Vizum deletes Customer Personal Data held in managed retrieval storage, unless Union, Member State, Colombian or United States law requires it to be stored.
11.2. The Customer chooses return or deletion. The export mechanism in clause 10.1.2 is available throughout, and remains available during the grace period in clause 11.3.
11.3. Grace period. Where a Managed AI subscription is cancelled, managed vectors and documents are retained for thirty (30) days and then purged. The period is a configurable parameter with a default of 30 days; the applicable period is stated in the product. After the purge, Vizum cannot recover the data.
11.4. Deletion on demand takes effect immediately and does not wait for the grace period.
11.5. What is deleted by the purge: managed vectors, their chunk text and metadata, and the original documents held in managed residency, including any pre-switch residue described in clause 5.3.
11.6. What is not deleted by the purge, and the Customer must know it: (a) the prepaid AI balance, which is not storage and is retained; (b) usage and billing ledger records — model, token counts, amounts, timestamps and a pseudonymous user reference. They contain no prompt and no response content. They are retained for accounting, tax and audit purposes; (c) transcripts produced by the transcription service, which at the date of this version have no automatic retention limit. Vizum will delete them on request, and clause 11.4 applies to them. Ask at support@vizumapps.com.
11.7. Certification. Vizum will confirm deletion in writing on request.
11.8. Documents submitted for text extraction are held only for the duration of the extraction and are deleted immediately afterwards, with a backstop sweep that removes any residue within two hours.
12. International transfers
12.1 Where the processing happens
12.1.1. All processing under this DPA takes place in the United States of America. Vizum's infrastructure is hosted in New York (compute and managed database) and in a United States object storage region (files). The AI providers in Annex III are established in the United States.
12.1.2. There is no European Union, United Kingdom or Colombian hosting option at the date of this version. A Customer that requires data to remain in a specific jurisdiction should use local or pgvector residency for stored content, and should note clause 5.2: inference still leaves that jurisdiction.
12.2 European Union and European Economic Area
12.2.1. Where Customer Personal Data is subject to the GDPR, the transfer to Vizum is made under the SCCs (Decision (EU) 2021/914), which are incorporated into this DPA by reference and form part of it.
12.2.2. Module Two (controller to processor) applies to the transfer from the Customer to Vizum.
12.2.3. Module Three (processor to processor) applies to onward transfers from Vizum to a Sub-processor that is itself a processor, subject to clause 9.4.
12.2.4. The following selections apply to the incorporated SCCs: (a) Clause 7 (docking clause): applies. (b) Clause 9 (sub-processors): OPTION 2, general written authorisation, with the notice period in clause 9.7 of this DPA. (c) Clause 11 (redress): the optional independent dispute resolution body is not selected. (d) Clause 17 (governing law): the law of Ireland. (e) Clause 18(b) (forum): the courts of Ireland. (f) Annex I, II and III of the SCCs are populated by Annex I, Annex II and Annex III of this DPA respectively.
12.2.5. In the event of a conflict between the SCCs and any other provision of this DPA or the Agreement, the SCCs prevail in respect of transfers subject to the GDPR.
12.2.6. Transfer impact. The parties acknowledge that United States law, including FISA Section 702 and Executive Order 12333, may permit access by public authorities. Vizum's position, and its supplementary measures, are stated in Annex II §4. Vizum has not received a government access request for Customer Personal Data to the date of this version.
12.3 United Kingdom
12.3.1. Where the UK GDPR applies, the SCCs apply as supplemented by the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, and references to supervisory authorities and governing law are read accordingly.
12.4 Colombia
12.4.1. This is a transmisión internacional de datos personales, not a transferencia, and the distinction is the basis on which it is lawful.
12.4.2. Under Articles 24 and 25 of Decreto 1377 de 2013 (compiled in Decreto 1074 de 2015), a transmisión to a processor located abroad does not require the titular's prior authorisation for the transfer itself where a contract of transmission is in place between the responsable and the encargado that: (a) states the scope of the processing; (b) states the activities the encargado will carry out on the responsable's behalf; (c) states the obligations the encargado undertakes towards the responsable and the titular.
12.4.3. This DPA is that contract of transmission, and clauses 2, 4, 6, 7, 8, 9, 10, 11 and 13 supply the required content.
12.4.4. The restriction in Article 26 of Ley 1581 de 2012 on transfers to countries without an adequate level of protection therefore does not bar this processing. The Customer should note that the SIC has not declared the United States to have an adequate level of protection, so if the Customer's arrangement is characterised as a transferencia rather than a transmisión — for example because the recipient processes for its own purposes — a separate basis is required, ordinarily the express and unequivocal authorisation of the titular.
12.4.5. The Customer remains the responsable and retains the duties that attach to that role, including the aviso de privacidad, the collection of authorisation, attention to consultas y reclamos, and any duty to register a database with the Registro Nacional de Bases de Datos.
12.4.6. Vizum's own registration position is stated rather than assumed: whether the responsable is obliged to register with the RNBD depends on the responsable's own characteristics and asset thresholds. Vizum has not determined its own registration obligation and has not registered. The Customer should not treat this DPA as evidence that either party has registered.
13. Audits and information — GDPR Article 28(3)(h)
13.1. Vizum makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.
13.2. First-line response. Vizum will answer a written information request, including a security questionnaire, within thirty (30) days.
13.3. On-site or in-depth audit. The Customer may conduct one audit per twelve-month period, and additionally where a personal data breach has occurred or a supervisory authority requires it. The Customer will: (a) give thirty (30) days' written notice; (b) agree scope and timing so as not to disrupt the service; (c) ensure the auditor is bound by confidentiality and is not a competitor of Vizum; (d) bear its own costs, and Vizum's reasonable costs where the audit exceeds one working day.
13.4. Vizum will not give access to another customer's data, to shared infrastructure in a way that risks another customer's data, or to information that would compromise the security of the service.
13.5. No third-party certification exists. Vizum holds no ISO 27001 certification, no SOC 2 report and no equivalent independent attestation, and does not offer one in place of an audit. Clause 13.3 is therefore the Customer's real audit right, not a fallback.
13.6. Sub-processor audits. Vizum will pass on audit information it holds about a Sub-processor. It cannot grant audit rights over a Sub-processor's infrastructure that it does not itself hold, and clause 9.4 applies.
14. Where Vizum is controller, not processor
14.1. So that the boundary is explicit rather than inferred, Vizum is the controller of the following, and this DPA does not govern it:
(a) account data — name, email address, hashed password, and the IP address recorded at registration and login; (b) security logs — failed authentication attempts by IP address and email address, retained for the period stated in clause 14.3; (c) instance registration — the Customer's database identifier and URL; (d) billing data — Stripe customer and payment identifiers, invoices, transactions. Card numbers never reach Vizum's servers; they pass from the payer's browser to Stripe; (e) desktop telemetry — an event label, a date and a count, aggregated on the Customer's server, with no user identity and no content, retained for 730 days; (f) usage and billing metering — model, token counts, amounts and a pseudonymous user reference.
14.2. The user reference in metering and in retrieval scoping is a one-way hash derived from the database identifier and the user's internal identifier. Vizum cannot reverse it and does not hold the identities behind it.
14.3. Failed licence-claim attempts, which record an IP address, are retained for 7 days.
14.4. Vizum's lawful basis for this processing is the performance of the contract, and its legitimate interest in operating and securing the service. The privacy notice describes it.
15. Liability
15.1. Liability under this DPA is subject to the limitations in the Agreement, except where the applicable law does not permit it.
15.2. The limitations in the Agreement do not apply to, and do not limit: (a) liability under Article 82 GDPR to a data subject; (b) an administrative fine imposed under Article 83 GDPR or under Ley 1581 de 2012; (c) liability under the SCCs to a data subject, which the SCCs govern on their own terms.
15.3. Where the SCCs and clause 15.1 conflict, the SCCs prevail.
15.4. Each party is liable for damage it causes by processing that infringes applicable data protection law, in accordance with Article 82 GDPR.
16. General
16.1. Term. This DPA takes effect on acceptance and continues for as long as Vizum processes Customer Personal Data, and its surviving obligations continue thereafter.
16.2. Assignment on incorporation. Vizum may assign this DPA to an entity incorporated to carry on the business, on notice to the Customer. The assignee assumes it in full, and the Customer's rights are not reduced. Until then the natural person named in clause 1.1(b) is the encargado and bears the obligations personally.
16.3. Changes. Vizum may update this DPA where required by law or by a change in the service. A change that reduces the Customer's rights or Vizum's obligations takes effect no less than thirty (30) days after notice, and the Customer may terminate the Managed AI service within that period under clause 9.8.
16.4. Severability. If a provision is invalid, it is severed to the minimum extent and the remainder continues.
16.5. Governing law. This DPA is governed by the law stated in the Agreement, except that clause 12.2 is governed by the law of Ireland as provided by the SCCs, and except that nothing displaces the mandatory application of the GDPR or of Colombian Data Protection Law.
16.6. Languages. This DPA is published in English and Spanish. For a Customer established in Colombia or in another Spanish-speaking jurisdiction, the Spanish version prevails. For everyone else, the English version prevails.
16.7. Contact. All notices, requests and questions under this DPA: support@vizumapps.com.
16.8. No data protection officer has been appointed. Vizum has assessed that Article 37 GDPR does not require one on the present scale of processing. The contact point in clause 16.7 is the address for all matters under this DPA. Vizum has not appointed an Article 27 representative in the European Union or the United Kingdom; clause 4 of Annex II §5 records this as an open item.
ANNEX I — Description of the processing
A. List of parties
Data exporter (controller): the Customer identified in the account through which the Services are used. Contact details are those held in the account. Role: controller / responsable del tratamiento.
Data importer (processor): Enrique Echeverría, trading as Vizum Apps Establishments: Colombia and the United States of America Contact: support@vizumapps.com Role: processor / encargado del tratamiento
B. Description of the transfer
Categories of data subjects Determined by the Customer, since the Customer chooses what to index and what to submit. Typically:
- the Customer's employees, contractors and internal users;
- the Customer's customers, clients and prospects;
- the Customer's suppliers and business contacts;
- any individual named in a document the Customer indexes or submits.
Categories of personal data Determined by the Customer. In the ordinary case:
- identification and contact data appearing in documents (names, email addresses, telephone numbers, postal addresses);
- employment, commercial and contractual information appearing in documents;
- the free-text content of prompts submitted by the Customer's users, which may contain any personal data the user types;
- the full content of documents the Customer indexes, and the text extracted from them;
- vector embeddings derived from that content;
- transcripts of audio and video the Customer submits;
- a pseudonymous user reference (a one-way hash) used to scope retrieval and to attribute usage.
Sensitive data The service is not intended for, and has not been assessed for, special categories of personal data. Under clause 12.6 of the Agreement the Customer must not submit health, biometric, genetic, racial or ethnic, political, religious, trade-union, sex-life or sexual-orientation data, data relating to children, payment card numbers, or government identifiers, without a prior written agreement extending this DPA. Where such an agreement is made, the additional restrictions and safeguards will be recorded in it.
Frequency of the transfer Continuous, on each request the Customer's Instance makes.
Nature of the processing Transmission, execution of AI inference through a third-party provider, generation of vector embeddings, text extraction from documents, optical character recognition, transcription of audio and video, image generation, storage of vectors and original documents in managed residency, retrieval by vector and full-text search, hosting, backup, deletion.
Purpose of the processing To provide the Managed AI and hosted retrieval service to the Customer, on the Customer's instruction, and to secure and maintain it.
Retention
- Managed vectors and documents: for the life of the subscription, then 30 days, then purged (clause 11.3), or on demand (clause 11.4).
- Extraction inputs: for the duration of extraction only, with a two-hour backstop sweep (clause 11.8).
- Transcripts: no automatic limit; deleted on request (clause 11.6(c)).
- Usage and billing metering: retained for accounting and audit; no content (clause 11.6(b)).
Sub-processor transfers Subject matter, nature and duration as set out in Annex III.
C. Competent supervisory authority
For transfers subject to the GDPR, the supervisory authority of the Member State in which the Customer, as data exporter, is established, or in which it has designated its Article 27 representative, determined in accordance with clause 13 of the SCCs.
For processing subject to Colombian Data Protection Law, the Superintendencia de Industria y Comercio (Delegatura para la Protección de Datos Personales).
ANNEX II — Technical and organisational measures
These are the measures in force and verified. Section 5 names what is absent. Read both.
1. Transport and network
1.1. TLS on all public endpoints, with certificates issued by Let's Encrypt and served by Caddy. 1.2. HTTP Strict-Transport-Security, two-year max-age, with includeSubDomains. 1.3. X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy response headers. 1.4. Outbound requests to AI providers are pinned to a validated public IP address after DNS resolution, which defends against DNS rebinding and server-side request forgery.
2. Authentication, authorisation and abuse control
2.1. Passwords are stored as PBKDF2-SHA512 hashes. No password is stored or recoverable in clear text. 2.2. Authentication rate limiting: five failed attempts per five minutes, per IP address and per email address, followed by a fifteen-minute block. Checkout is limited to ten attempts per five minutes per IP address. 2.3. Instance authentication uses a per-instance token compared in constant time. The token is accepted only in a request header or body, never in a query string, so that it does not appear in server logs or in referrer headers. 2.4. Login is restricted to portal accounts on the public account API, so an internal or administrative account cannot be authenticated through it. 2.5. Timing equalisation on the authentication path, so that a non-existent account cannot be distinguished from a wrong password. 2.6. Uniform refusal messages on entitlement and licence routes, so they cannot be used to enumerate other tenants.
3. Tenant isolation and application security
3.1. Every stored vector and document row is bound to an instance identifier, and every read and write is scoped to it. Retrieval is additionally scoped by an opaque per-user reference. 3.2. The per-user reference is a one-way hash of the database identifier and the internal user identifier. Vizum cannot invert it. 3.3. Third-party applications execute in a sandboxed frame with an opaque origin, without access to the host session or cookies. The frame is served with a sandbox content-security-policy directive as a second layer. 3.4. Every call an application makes crosses a permission gate that is default-deny: an operation not explicitly allowed for the application's declared permissions is refused. The gate is enforced in two independent places, and the server re-checks server-side rather than trusting the client. 3.5. Application data access runs as the calling user, never with elevated privilege, so the Customer's own Odoo access rights and record rules continue to apply. 3.6. Storage caps are available per document, per application namespace, per user and per instance.
4. Hosting, storage and continuity
4.1. Compute and the managed PostgreSQL database are hosted by DigitalOcean in the United States (New York). Files are held in DigitalOcean Spaces object storage in a United States region. 4.2. Encryption in transit on all connections to the database, object storage and providers. 4.3. Encryption at rest is provided by DigitalOcean for the managed database and for object storage, under DigitalOcean's platform terms. 4.4. Backups of the production database are taken by DigitalOcean's managed backup service. 4.5. Original documents are stored on the filestore, not in database table columns, which limits their exposure in a database dump. 4.6. Documents submitted for text extraction are deleted immediately after extraction, with a backstop sweep at two hours. 4.7. Text extraction and optical character recognition of document structure run on Vizum's own servers. Content is transmitted to an AI provider only where the Customer's request requires model inference — chat, embedding, reranking, LLM-based vision, transcription, and image generation. 4.8. Vector and full-text search execute entirely within Vizum's PostgreSQL. A retrieval query is not sent to any AI provider.
5. What is absent — stated so the Customer can assess the risk
5.1. There is no Content-Security-Policy on the web application. The frame-level sandbox directive in §3.3 governs application frames only, and it carries no default-src, script-src or connect-src. A site-wide policy is an open remediation item. 5.2. There is no third-party security certification — no ISO 27001, no SOC 2, no independent penetration test report available to Customers. 5.3. There are no bespoke data processing agreements with the AI providers beyond their standard published terms (clause 9.4). 5.4. No Article 27 representative has been appointed in the European Union or the United Kingdom. 5.5. No data protection officer has been appointed (clause 16.8). 5.6. Separation of duties is limited by the scale of the operation (clause 7.3). 5.7. There is no formal, exercised incident response runbook. Clause 10.2 states a binding 48-hour notification commitment; the internal procedure supporting it is being documented. 5.8. Multi-factor authentication is not enforced on Store accounts. Where an account has a second factor configured, the non-interactive account API refuses it rather than bypassing it. 5.9. Email addresses are not verified at registration. 5.10. Account API tokens do not expire automatically. They are revocable.
6. Governance
6.1. A documented security review was conducted and its findings tracked to closure, with the open items reflected in §5. 6.2. Automated security and code-quality gates run against changes before release. 6.3. Vulnerability reports are received at support@vizumapps.com under the disclosure terms in clause 14.2 of the Agreement.
ANNEX III — Sub-processors
All processing performed on Vizum's own infrastructure takes place in the United States of America. The infrastructure and payment Sub-processors in §1 are established there. The AI providers in §2 are not all United States companies — the notes to each row say where each one is established, and two of them are not — so content routed to a provider the Customer selects may be processed outside the United States as well. This is stated here rather than in a note because it changes the transfer analysis, and because the Customer, not Vizum, chooses the provider.
1. Infrastructure and payments
| # | Sub-processor | Function | Location | Data reaching it |
|---|---|---|---|---|
| 1 | DigitalOcean, LLC | Cloud hosting, managed PostgreSQL, Spaces object storage | United States (New York; object storage in a US region) | All Customer Personal Data processed under this DPA, at rest and in transit |
| 2 | Stripe, Inc. | Payment processing, subscriptions, billing portal, refunds | United States | Not a Sub-processor of Customer Personal Data under this DPA. Stripe processes account and billing data for which Vizum is the controller (clause 14.1(d)). It is listed here for completeness because the Customer asked to see every recipient. Card numbers pass from the payer's browser to Stripe and never reach Vizum's servers. |
2. AI providers
Which of these receives a given item of Customer Personal Data is determined by the Customer's own model configuration (clause 9.5). A provider whose models the Customer has not enabled receives nothing.
| # | Sub-processor | Function | Location | Endpoint |
|---|---|---|---|---|
| 3 | OpenAI, L.L.C. | Chat inference, embeddings, audio transcription | United States | api.openai.com |
| 4 | Anthropic, PBC | Chat inference, LLM-based vision | United States | api.anthropic.com |
| 5 | Google LLC — Gemini | Chat inference, embeddings, LLM-based vision | United States | generativelanguage.googleapis.com |
| 6 | Google LLC — Cloud Vision | Optical character recognition | United States | vision.googleapis.com |
| 7 | xAI Corp. | Chat inference, embeddings, audio transcription | United States | api.x.ai |
| 8 | MiniMax | Chat inference | United States endpoint | api.minimax.io |
| 9 | Ollama (cloud) | Chat inference, embeddings | United States | ollama.com |
| 10 | Mistral | Chat inference, where configured | Configurable endpoint | Configured per deployment |
Notes on this table, which the Customer should read rather than skim:
(a) Anthropic does not provide an embeddings API, so embeddings never go to Anthropic. (b) Ollama may also be self-hosted, in which case the endpoint is the one the deployment configures and the data does not reach Ollama's cloud service. (c) Mistral is a French company, and its endpoint is configurable rather than fixed: the effective destination depends on the deployment's configuration. It is the second Sub-processor referred to in the note above this Annex that is not established in the United States. (d) MiniMax is a company of the People's Republic of China serving a United States endpoint. A Customer with a restriction on transfers to China, or on providers subject to Chinese law, should not enable MiniMax models, and should set its permitted-model list accordingly. Vizum flags this because the endpoint's location does not settle the question. (e) Where the Customer supplies its own provider key, that provider is the Customer's own processor and not Vizum's Sub-processor (clause 9.6). (f) Clause 9.4 applies to every provider in this section 2.
3. Changes
Additions and replacements are notified under clause 9.7, with the objection right in clause 9.8.