VAULTN DATA PROCESSING AGREEMENT
V1.01 (Last updated: 2026-06-01)
RECITALS
(A) The Agreement between You and VaultN may require VaultN to process Personal Data on Your behalf.
(B) This Data Processing Agreement sets out the additional terms, requirements and conditions on which VaultN will process Personal Data when providing services under the Agreement. This Agreement contains the mandatory clauses required by Article 28(3) of the General Data Protection Regulation ((EU) 2016/679) (GDPR) for contracts between controllers and processors.
1. Definitions and Interpretation
1.1 Definitions
| Term | Definition |
|---|---|
| Business Purposes | the services to be provided by VaultN to You as described in the Agreement. |
| Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing | have the meanings given in the Data Protection Legislation. |
| Data Protection Legislation | all applicable data protection and privacy legislation in force from time to time in the European Union or any member state of the European Union, including but not limited to Regulation (EU) 2016/679 (GDPR) and its national implementing legislation in the Netherlands (Uitvoeringswet AVG). |
| EEA | the European Economic Area. |
| End User | a natural person who purchases or receives Digital Inventory from You or Your Connection through a retail transaction, whose personal data may be processed by VaultN solely as necessary to fulfill the relevant Order. |
| Records | has the meaning given in Clause 12. |
| Standard Assistance | assistance provided by VaultN in fulfilling its obligations under this DPA at no additional cost to You, unless such assistance requires effort or resources beyond what is reasonably necessary for VaultN to meet its obligations under Article 28 GDPR, in which case VaultN may charge a reasonable fee agreed in advance. |
| Sub-Processor List | the list of approved subprocessors maintained by VaultN at https://vaultn.com/subprocessor-list/, as updated from time to time. |
| Term | this DPA’s term as defined in Clause 10. |
1.2 This DPA is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this DPA.
1.3 The Annexes form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.
1.4 A reference to writing or written excludes fax but not email.
1.5 In the case of conflict or ambiguity between:
- (a) any provision contained in the body of this DPA and any provision contained in the Annexes, the provision in the body of this DPA will prevail;
- (b) the terms of any accompanying invoice or other documents annexed to this DPA and any provision contained in the Annexes, the provision contained in the Annexes will prevail; and
- (c) any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA will prevail.
1.6 Where You and VaultN have entered into a separate executed data processing agreement as part of Specific Terms that covers the obligations set out in this DPA, that agreement supersedes this DPA in its entirety for the duration of those Specific Terms.
1.7 Where You are established in the United Kingdom or subject to the California Consumer Privacy Act, the applicable addendum set out in this DPA applies in addition to and supplements the terms of this DPA. In case of conflict between an addendum and the main body of this DPA, the addendum prevails for the jurisdiction it covers.
2. Personal Data Types and Processing Purposes
2.1 You and VaultN agree and acknowledge that for the purpose of the Data Protection Legislation:
- (a) You are the Controller and VaultN is the Processor.
- (b) You retain control of the Personal Data and remain responsible for Your compliance obligations under the Data Protection Legislation, including but not limited to, providing any required notices and obtaining any required consents, and for the written processing instructions You give to VaultN.
- (c) ANNEX A describes the subject matter, duration, nature and purpose of the processing and the Personal Data categories and Data Subject types in respect of which VaultN may process the Personal Data to fulfill the Business Purposes.
3. VaultN’s Obligations
3.1 VaultN will only process the Personal Data to the extent, and in such a manner, as is necessary for the Business Purposes in accordance with Your written instructions. VaultN will not process the Personal Data for any other purpose or in a way that does not comply with this DPA or the Data Protection Legislation. VaultN will promptly notify You if, in its opinion, Your instructions do not comply with the Data Protection Legislation.
3.2 VaultN will comply promptly with any written instructions from You requiring VaultN to amend, transfer, delete or otherwise process the Personal Data, or to stop, mitigate or remedy any unauthorized processing.
3.3 VaultN will maintain the confidentiality of the Personal Data and will not disclose the Personal Data to third parties unless You or this DPA specifically authorizes the disclosure, or as required by Applicable Law, court or regulator. If Applicable Law, a court or regulator requires VaultN to process or disclose the Personal Data to a third party, VaultN will first inform You of such legal or regulatory requirement and give You an opportunity to object or challenge the requirement, unless Applicable Law prohibits the giving of such notice.
3.4 VaultN will reasonably assist You as Standard Assistance with meeting Your compliance obligations under the Data Protection Legislation, taking into account the nature of VaultN’s processing and the information available to VaultN, including in relation to Data Subject rights, data protection impact assessments under Article 35 GDPR and reporting to and consulting with the relevant regulator under the Data Protection Legislation under Article 36 GDPR.
4. VaultN’s Employees
4.1 VaultN will ensure that all of its employees, contractors, agents and any other persons authorized to access or process the Personal Data:
- (a) are informed of the confidential nature of the Personal Data and are bound by written confidentiality obligations and use restrictions in respect of the Personal Data;
- (b) have undertaken training on the Data Protection Legislation and how it relates to their handling of the Personal Data and how it applies to their particular duties; and
- (c) are aware both of VaultN’s duties and their personal duties and obligations under the Data Protection Legislation and this DPA.
5. Security
5.1 VaultN will at all times implement appropriate technical and organizational measures against accidental, unauthorized or unlawful processing, access, copying, modification, reproduction, display or distribution of the Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Personal Data including, but not limited to, the security measures set out in ANNEX B.
5.2 VaultN will implement such measures to ensure a level of security appropriate to the risk involved, including as appropriate:
- (a) the pseudonymisation and encryption of personal data;
- (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and
- (d) a process for regularly testing, assessing and evaluating the effectiveness of the security measures.
6. Personal Data Breach
6.1 VaultN will without undue delay and in any event within 72 hours of becoming aware notify You in writing if it becomes aware of:
- (a) the loss, unintended destruction or damage, corruption, or unusability of part or all of the Personal Data. VaultN will restore such Personal Data at its own expense as soon as possible.
- (b) any accidental, unauthorized or unlawful processing of the Personal Data; or
- (c) any Personal Data Breach.
6.2 Where VaultN becomes aware of (a), (b) and/or (c) above, it will, without undue delay, also provide You with the following written information:
- (a) description of the nature of (a), (b) and/or (c), including the categories of in-scope Personal Data and approximate number of both Data Subjects and the Personal Data records concerned;
- (b) the likely consequences; and
- (c) a description of the measures taken or proposed to be taken to address (a), (b) and/or (c), including measures to mitigate its possible adverse effects; and
- (d) the name and contact details of the designated contact from whom further information can be obtained.
6.3 Immediately following any accidental, unauthorized or unlawful Personal Data processing or Personal Data Breach, the parties will coordinate with each other to investigate the matter. Further, VaultN will reasonably cooperate with You in Your handling of the matter, including but not limited to:
- (a) assisting with any investigation;
- (b) providing You with physical access to any facilities and operations affected;
- (c) facilitating interviews with VaultN’s employees, former employees and others involved in the matter including, but not limited to, its officers and directors;
- (d) making available all relevant records, logs, files, data reporting and other materials required to comply with all Data Protection Legislation or as otherwise reasonably required by You; and
- (e) taking reasonable and prompt steps to mitigate the effects and to minimise any damage resulting from the Personal Data Breach or accidental, unauthorized or unlawful Personal Data processing.
6.4 VaultN will not inform any third party of any accidental, unauthorized or unlawful processing of all or part of the Personal Data and/or a Personal Data Breach without first obtaining Your written consent, except when required to do so by Applicable Law. For the avoidance of doubt, this Clause applies to VaultN’s processing in its capacity as processor under this DPA and does not limit VaultN’s compliance with any mandatory regulatory reporting obligation applicable to VaultN directly under Applicable Law in a separate capacity.
6.5 VaultN agrees that You have the sole right to determine:
- (a) whether to provide notice of the accidental, unauthorized or unlawful processing and/or the Personal Data Breach to any Data Subjects, the in-scope regulator, law enforcement agencies or others, as required by law or regulation or in Your discretion, including the contents and delivery method of the notice; and
- (b) whether to offer any type of remedy to affected Data Subjects, including the nature and extent of such remedy.
7. Transfers of Personal Data
7.1 VaultN (and any subprocessor) will not transfer or otherwise process the Personal Data outside the EEA without obtaining Your prior written consent, except where such transfer is made to subprocessors listed in the Sub-Processor List, in which case Your acceptance of this DPA constitutes prior written consent for those transfers, which shall be made on the basis of Standard Contractual Clauses as adopted by the European Commission (EU Commission Decision 2021/914) or such other transfer mechanism as is valid under Chapter V GDPR, a copy of which VaultN will provide to You upon request.
8. Subprocessors
8.1 Other than those subprocessors listed in the Sub-Processor List, VaultN will not authorize any other third party or subprocessor to process the Personal Data.
8.2 Where the subprocessor fails to fulfill its obligations under the written agreement with VaultN which contains terms substantially the same as those set out in this DPA, VaultN remains fully liable to You for the subprocessor’s performance of its agreement obligations.
8.3 You and VaultN agree that VaultN will be deemed by them to control legally any Personal Data controlled practically by or in the possession of its subprocessors.
9. Complaints, Data Subject Requests and Third-Party Rights
9.1 VaultN will take such technical and organizational measures as may be appropriate, and promptly provide such information to You as You may reasonably require, to enable You to comply with:
- (a) the rights of Data Subjects under the Data Protection Legislation, including, but not limited to, subject access rights, the rights to rectify, port and erase personal data, object to the processing and automated processing of personal data, and restrict the processing of personal data; and
- (b) information or assessment notices served on You by the relevant regulator under the Data Protection Legislation.
9.2 VaultN will notify You immediately in writing if it receives any complaint, notice or communication that relates directly or indirectly to the processing of the Personal Data or to either party’s compliance with the Data Protection Legislation.
9.3 VaultN will notify You without undue delay and in any event within 15 calendar days if it receives a request from a Data Subject for access to their Personal Data or to exercise any of their other rights under the Data Protection Legislation.
9.4 VaultN will give You as Standard Assistance its full co-operation and assistance in responding to any complaint, notice, communication or Data Subject request.
9.5 VaultN will not disclose the Personal Data to any Data Subject or to a third party other than in accordance with Your written instructions, or as required by Applicable Law.
10. Term and Termination
10.1 This DPA will remain in full force and effect so long as:
- (a) the Agreement remains in effect; or
- (b) VaultN retains any of the Personal Data related to the Agreement in its possession or control (the “Term”).
10.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect the Personal Data will remain in full force and effect.
10.3 If a change in any Data Protection Legislation prevents either party from fulfilling all or part of its obligations under the Agreement, the parties may agree to suspend the processing of the Personal Data until that processing complies with the new requirements. If the parties are unable to bring the Personal Data processing into compliance with the Data Protection Legislation within the period applicable to material changes under Section 11.1(B) of the Agreement, which the parties agree constitutes a material change for the purposes of that section, and under no circumstances less than 30 days, either party may terminate the Agreement in accordance with the notice provisions of the Agreement.
11. Data Return and Destruction
11.1 At Your request, VaultN will give You, or a third party nominated in writing by You, a copy of or access to all or part of the Personal Data in its possession or control in the format and on the media reasonably specified by You.
11.2 On termination of the Agreement for any reason or expiry of its term, VaultN will securely delete or destroy or, if directed in writing by You, return and not retain, all or any of the Personal Data related to this DPA in its possession or control, except for one copy that it may retain for internal auditing purposes only, for no longer than 3 years following the date of deletion or return, unless a longer retention period is required under Applicable Law.
11.3 If any law, regulation, or government or regulatory body requires VaultN to retain any documents, materials or Personal Data that VaultN would otherwise be required to return or destroy, it will notify You in writing of that retention requirement, giving details of the documents, materials or Personal Data that it must retain, the legal basis for such retention, and establishing a specific timeline for deletion or destruction once the retention requirement ends.
12. Records
12.1 VaultN will keep detailed, accurate and up-to-date written records regarding any processing of the Personal Data, including but not limited to, the access, control and security of the Personal Data, subprocessors as listed in the Sub-Processor List, the processing purposes, categories of processing, and a general description of the technical and organizational security measures referred to in Clause 5.1 (the “Records”).
12.2 VaultN will ensure that the Records are sufficient to enable You to verify VaultN’s compliance with its obligations under this DPA and the Data Protection Legislation and VaultN will provide You with copies of the Records upon request.
13. Audit
13.1 VaultN will, upon Your reasonable written request and no more than once per calendar year (unless a Personal Data Breach has occurred), make available to You the following in order of preference:
- (a) a current ISO 27001 certification and associated Statement of Applicability, which VaultN may provide in satisfaction of its audit obligations under this Clause;
- (b) where You reasonably consider that (a) does not demonstrate sufficient compliance, relevant records and documentation as necessary to verify VaultN’s compliance with this DPA, with no on-site access required; and
- (c) where a Personal Data Breach has occurred or a supervisory authority requires it, or where You have reasonable grounds to believe that the information provided under (a) or (b) does not adequately demonstrate compliance with Article 28 GDPR, provided that You have first exhausted the remedies under (a) and (b) and provided VaultN with written reasons for Your belief, an on-site audit, the scope, timing and cost of which shall be agreed in advance between You and VaultN, and for which VaultN may require the appointment of a mutually agreed independent third-party auditor under a non-disclosure agreement.
13.2 In all cases, You will provide VaultN with reasonable prior written notice of no less than 30 calendar days.
14. Warranties
14.1 VaultN warrants and represents that:
- (a) its employees, agents and any other person or persons accessing the Personal Data on its behalf are reliable and trustworthy and have received the required training on the Data Protection Legislation;
- (b) it and anyone operating on its behalf will process the Personal Data in compliance with the Data Protection Legislation and other laws, enactments, regulations, orders, standards and other similar instruments;
- (c) it has no reason to believe that the Data Protection Legislation prevents it from providing any of the Agreement’s contracted services; and
- (d) considering the current technology environment and implementation costs, it will take appropriate technical and organizational measures to prevent the accidental, unauthorized or unlawful processing of Personal Data and the loss or damage to the Personal Data, and ensure a level of security appropriate to:
- (i) the harm that might result from such accidental, unauthorized or unlawful processing and loss or damage;
- (ii) the nature of the Personal Data protected; and
- (iii) comply with all applicable Data Protection Legislation and its information and security policies, including the security measures required in Clause 5.1.
14.2 You warrant and represent that VaultN’s expected use of the Personal Data for the Business Purposes and as specifically instructed by You will comply with the Data Protection Legislation.
15. Indemnification
15.1 VaultN agrees to indemnify, keep indemnified and defend at its own expense You against all costs, claims, damages or expenses incurred by You or for which You may become liable due to any failure by VaultN or its employees, subcontractors or agents to comply with any of its obligations under this DPA and/or the Data Protection Legislation.
15.2 The limitation of liability set forth in the Agreement will apply to this DPA’s indemnity or reimbursement obligations, provided that the carve-out in Section 10.3 of the Agreement for data protection obligations applies and this DPA’s indemnity obligations shall not be subject to the general liability cap to the extent that such obligations cannot be limited under Applicable Law.
16. Notices
16.1 Any notice given under or in connection with this DPA shall be given in accordance with Section 11.2 of the Agreement. Notices from You to VaultN shall be sent to [email protected] or such other address as VaultN notifies You in writing from time to time.
17. Governing Law
17.1 This DPA is governed by the laws of the Netherlands. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands, consistent with Section 12.1 of the Agreement.
UK GDPR ADDENDUM TO THE VAULTN DATA PROCESSING AGREEMENT
This Addendum forms part of the DPA and applies where You are established in the United Kingdom or where You process personal data subject to the UK GDPR in connection with the Services. To the extent of any conflict between this Addendum and the main body of the DPA, this Addendum prevails for UK GDPR processing only.
1. Definitions
UK GDPR means the retained EU law version of the General Data Protection Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
2. Modifications to the DPA
To the extent that VaultN processes personal data subject to the UK GDPR on Your behalf, the DPA applies with the following modifications:
- (a) References to Data Protection Legislation include the UK GDPR and the Data Protection Act 2018.
- (b) References to Standard Contractual Clauses mean the International Data Transfer Agreement (IDTA) issued by the UK Information Commissioner’s Office, or the UK Addendum to the EU SCCs as applicable and approved by the UK Secretary of State.
- (c) References to supervisory authority include the UK Information Commissioner’s Office.
- (d) The governing law of this Addendum, to the extent it covers UK GDPR processing only, is the law of England and Wales. For the avoidance of doubt, all other provisions of the DPA and the Agreement remain governed by Dutch law.
3. Liability
VaultN’s liability for breaches of this Addendum is subject to the same limitations as set out in Clause 15 of the DPA and Section 10.3 of the Agreement. Nothing in this Addendum creates liability beyond those limits.
4. Your Warranty
You warrant that You have the legal basis required under the UK GDPR for sharing personal data with VaultN under this Addendum.
CCPA ADDENDUM TO THE VAULTN DATA PROCESSING AGREEMENT
This Addendum forms part of the DPA and applies where You are a business subject to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act 2020 (together, CCPA) and You share personal information with VaultN in connection with the Services. To the extent of any conflict between this Addendum and the main body of the DPA, this Addendum prevails for CCPA processing only.
1. Role of VaultN
The parties acknowledge that to the extent VaultN processes personal information as defined under CCPA on Your behalf, VaultN acts as a Service Provider as defined under CCPA Section 1798.140(ag).
2. VaultN’s Obligations
VaultN confirms that it:
- (a) will not sell or share personal information received from You;
- (b) will not retain, use, or disclose personal information for any purpose other than performing the Services specified in the Agreement;
- (c) will not retain, use, or disclose personal information outside the direct business relationship between VaultN and You; and
- (d) will notify You if VaultN determines it can no longer meet its obligations under CCPA.
3. Your Warranty
You represent and warrant that You have provided all notices and obtained all consents required under CCPA for sharing personal information with VaultN as a Service Provider.
4. Scope of Processing
VaultN’s obligations under this Addendum are strictly limited to the personal information processed in the course of providing the Services. VaultN does not process consumer personal information as defined under CCPA except as strictly necessary for Order fulfillment. VaultN does not process sensitive personal information as defined under CCPA Section 1798.140(ae).
5. Liability
VaultN’s liability for any breach of this Addendum is subject to the limitations set out in Clause 15 of the DPA and Section 10.3 of the Agreement. Nothing in this Addendum creates liability beyond those limits.
6. Governing Law
This Addendum does not modify VaultN’s governing law position. The Agreement and DPA remain governed by Dutch law. This Addendum supplements the DPA solely to address CCPA compliance obligations and does not constitute a submission to California jurisdiction.
ANNEX A — Personal Data Processing Details
Subject matter of processing
VaultN processes Personal Data as necessary to provide the Services under the Agreement, including the operation and maintenance of the VaultN Platform and all Services and Add-Ons provided thereunder.
Duration of processing
As set out in Clause 10 of this DPA.
Nature of processing
Collection, storage, retrieval, transmission, and deletion of Personal Data as necessary to provide the Services under the Agreement.
Business Purposes
As defined in the Agreement and the applicable Terms of Service and Terms of Add-Ons.
Personal Data Categories
The following categories of Personal Data may be processed by VaultN in the course of providing the Services:
- Account and User data: names, email addresses, and job titles of Users and Other Users as defined in the Agreement.
- IP addresses: collected at the point of API authentication and order creation for security, fraud prevention, and regional access control purposes.
- Unique end-user identifiers: pseudonymised identifiers passed by You or Your Connections to identify End Users in the context of order fulfillment, provided in hashed form.
- Unique order identifiers: internal and third-party order reference identifiers (including clientOrderReference and orderGuid) generated or passed in the course of order creation, reservation, completion, and fulfillment.
- Platform authentication credentials: where direct entitlement processing is enabled, authentication tokens or credentials passed by You or Your Connections to facilitate fulfillment of digital assets directly to an End User’s platform account.
You warrant that You have obtained all necessary consents and have the required legal basis under Applicable Law for sharing the Personal Data referred to in categories 2 to 5 above with VaultN, as required under the Agreement.
Data Subject Types
Users and Other Users as defined in the Agreement, and End Users to the extent their Personal Data is processed in categories 2 to 5 above.
ANNEX B — Security Measures
VaultN’s technical and organizational security measures are governed by VaultN’s Information Security Policy, as published and amended from time to time by VaultN and available upon request at [email protected] (the “ISP”). The ISP is the sole source of truth for VaultN’s security measures and takes precedence over the overview below in the event of conflict.
The following is a high-level overview of VaultN’s current security measures as reflected in the ISP:
- Access control: Access to Personal Data is restricted to authorized personnel on a need-to-know basis. Role-based access controls are implemented and reviewed periodically. Multi-factor authentication is required for access to production systems.
- Encryption: Personal Data is encrypted in transit using TLS 1.2 or higher. Personal Data at rest is encrypted using industry-standard encryption protocols.
- Incident response: VaultN maintains a documented information security incident response procedure. Security incidents are logged, investigated, and escalated in accordance with the ISP and the breach notification obligations in Clause 6 of this DPA.
- Business continuity and availability: VaultN maintains backup and recovery procedures to ensure the availability and resilience of processing systems. Recovery procedures are tested periodically in accordance with the ISP.
- Vendor and subprocessor security: Third-party subprocessors are assessed for security compliance prior to engagement and are contractually required to maintain security standards consistent with the ISP. The current list of approved subprocessors is maintained at the Sub-Processor List.
- Staff training and awareness: All personnel with access to Personal Data receive training on data protection and information security obligations on an ongoing basis.
- Physical security: Access to VaultN’s physical infrastructure is restricted and controlled. VaultN’s cloud infrastructure is hosted on Microsoft Azure, which maintains its own physical security certifications and controls.
VaultN reviews and updates the ISP at least annually. Where an update to the ISP materially reduces the level of security provided to You, VaultN will notify You in accordance with Clause 16 of this DPA.