> Source: https://votivusconsulting.com/dpa

# Votivus Consulting: Data Processing Agreement

**Effective date:** 24 June 2026
**Last updated:** 17 July 2026

This Data Processing Agreement ("**DPA**") is binding and forms part of the agreement between the parties whenever Votivus processes personal data on a client's behalf.

---

## 1. Parties and scope

- **Votivus Consulting Limited** ("**Votivus**", "**Processor**"); and
- the client identified in the applicable proposal, order, or statement of work ("**Client**", "**Controller**").

This DPA applies whenever Votivus processes personal data on the Client's behalf in connection with an engagement (for example, analysing analytics, advertising, CRM, email, or website data containing personal data about the Client's customers, prospects, staff, or contacts). Each party complies with applicable data-protection law, including the EU GDPR and the Cyprus Data Protection Law (Law 125(I)/2018) ("**Data Protection Law**"). Terms such as controller, processor, personal data, processing, data subject, special categories, personal data breach, supervisory authority, and Standard Contractual Clauses ("**SCCs**") have their GDPR meanings. "**Material**", where used in this DPA, has the meaning given in the Terms of Service.

---

## 2. Processing details (Article 28(3))

| Item | Description |
|---|---|
| Subject matter | AI-assisted growth, marketing, website, analytics, advertising, email, and operational analysis and related consulting |
| Duration | The engagement term, plus any retention required by law |
| Nature and purpose | Receiving, reviewing, analysing, transforming, storing, and reporting on Client-provided business data to deliver audits, recommendations, and deliverables |
| Data subjects | The Client's customers, prospects, website visitors, subscribers, staff, contractors, and business contacts |
| Personal data | Names, business contact details, identifiers, website/campaign activity, CRM records, analytics and advertising data, email-engagement data, account metadata, and other personal data within Client-provided materials |
| Special categories | None, unless expressly agreed in writing with documented safeguards and an Article 9 condition identified by the Client |

Engagement-specific details, if any, are in Annex 1. The Client must not provide special-category, criminal-offence, or children's data, or other highly sensitive data, unless expressly agreed in writing with safeguards documented.

---

## 3. Roles and Client obligations

The Client is the controller and Votivus the processor. The Client warrants that it has a lawful basis for the processing and for sharing the data with Votivus, has given any required notices and obtained any required consents, and that its instructions will not put Votivus in breach of Data Protection Law. **The Client will indemnify Votivus against claims, losses, and costs arising from the Client's breach of these warranties or from instructions that infringe Data Protection Law, subject to section 12.**

---

## 4. Processor obligations

Votivus will: (1) process only on the Client's documented instructions (this DPA, the Terms, the Engagement Terms, and further written instructions), informing the Client first if required by law to go further (unless the law prohibits it), and informing the Client without undue delay if it believes an instruction infringes Data Protection Law; (2) ensure persons authorised to process are bound by confidentiality; (3) implement the Article 32 security measures in Annex 2; (4) engage sub-processors only under section 6; (5) assist the Client under sections 7–8; (6) notify breaches under section 9; (7) return or delete data under section 10; and (8) make available information to demonstrate compliance and allow audits under section 11.

---

## 5. Security

Taking account of the state of the art, costs, and the nature, scope, context, and purposes of processing and the risk to data subjects, Votivus maintains the measures in Annex 2 (access control, authentication, encryption in transit and at rest where supported, segregation, logging, supplier diligence, incident response, and secure deletion), and may update them provided protection is not reduced.

---

## 6. Sub-processors

The Client gives **general written authorisation** for Votivus to engage sub-processors, listed in the **[Subprocessor List](/subprocessors)**. Votivus will: impose data-protection obligations on each sub-processor no less protective than this DPA (Art. 28(4)); **remain fully liable to the Client for each sub-processor's performance**; and give the Client at least **10 days' notice** of any intended addition or replacement, where practicable. The Client may object on reasonable data-protection grounds within 10 days; if unresolved in good faith, the Client may terminate the affected services and Votivus will refund pre-paid, unused fees for them on a pro-rata basis.

**Our own AI-processing infrastructure is not a sub-processor.** Where Votivus processes Client personal data on its own self-hosted AI infrastructure (Annex 2 and Annex 3), no separate organisation is involved and no sub-processor relationship arises; that processing remains subject to this DPA in full, including the security measures in Annex 2 and the international-transfer terms in section 13.

---

## 7. Assistance with data-subject rights

Taking account of the nature of the processing, Votivus will assist the Client by appropriate measures, insofar as possible, to respond to data-subject requests under Chapter III GDPR. If a data subject contacts Votivus directly about data processed for the Client, Votivus will not respond substantively (unless legally required) and will forward the request to the Client without undue delay.

---

## 8. Assistance with compliance

Taking account of the nature of processing and information available to it, Votivus will reasonably assist the Client with security (Art. 32), breach notification (Arts. 33–34), data-protection impact assessments (Art. 35), and prior consultation (Art. 36). Votivus may charge a reasonable fee, notified first, for assistance materially beyond its standard tooling.

---

## 9. Personal-data breaches

Votivus will notify the Client **without undue delay and no later than 24 hours** after becoming aware of a personal-data breach affecting personal data processed for the Client, with the information available (nature of the breach, categories and approximate numbers affected, likely consequences, measures taken or proposed, and a contact point), and will cooperate and take reasonable steps to mitigate. Notifying the supervisory authority and data subjects remains the Client's responsibility as controller unless agreed otherwise; Votivus will provide what the Client reasonably needs to meet its own deadlines.

---

## 10. Return and deletion

On termination or expiry, at the Client's choice, Votivus will delete or return the personal data processed for the Client and delete existing copies, unless law requires storage, completing this within **30 days** after the later of the engagement ending, the Client's written request, or payment of outstanding fees for the engagement. Votivus may retain personal data only where required by law or to establish, exercise, or defend legal claims; retained data stays protected under this DPA. Votivus will confirm deletion in writing on request. This section governs client personal data and prevails over any longer retention stated for Votivus's own business records elsewhere.

---

## 11. Audits

Votivus will make available information reasonably necessary to demonstrate Article 28 compliance and allow and contribute to audits by the Client or its mandated auditor, no more than once per 12 months (absent a breach or regulator requirement), on at least 14 days' notice, limited to relevant data-processing matters, and conducted to protect Votivus's systems, other clients' data, and security. Votivus may satisfy a request via policies, summaries, certifications, or third-party reports where these reasonably address it. Each party bears its own audit costs unless the audit reveals a material Votivus breach, in which case Votivus bears the reasonable audit cost.

---

## 12. Liability

Liability under this DPA is subject to the exclusions and **caps in the Terms of Service**, except to the extent liability cannot lawfully be limited. **The parties acknowledge and agree that those caps (a general cap, being the greater of the fees paid for the relevant engagement in the prior 12 months or EUR 5,000; a data-protection and confidentiality cap, being the greater of two times those fees or EUR 50,000; and an overall aggregate cap of EUR 100,000) apply to and are incorporated into this DPA by reference, whether or not the Client separately accepted the Terms online.** Liability for breach of data-protection or confidentiality obligations is subject to the **data-protection and confidentiality cap** (not the lower general cap). **Nothing in this DPA limits a data subject's direct rights under Article 82 GDPR, the parties' respective statutory liabilities to data subjects or the supervisory authority, or any liability that cannot lawfully be limited.**

---

## 13. International transfers

**Where this arises.** Votivus's own AI-processing infrastructure (Annex 2, Annex 3) operates outside the EEA. In addition, some sub-processors on the Subprocessor List may process data outside the EEA. Both cases are transfers under GDPR Chapter V, and Votivus applies the following:

- **Our own infrastructure.** Personal data that is not publicly available and is processed on Votivus's own self-hosted AI infrastructure never leaves Votivus's control and is not shared with any separate organisation, but is nonetheless physically located outside the EEA. Votivus safeguards this processing through the technical and organisational measures in Annex 2 (in particular access control, authentication, and encryption) and through internal policies restricting access to Votivus's own personnel. **We recommend, and intend to obtain, formal legal advice on whether an additional Chapter V transfer mechanism (such as Standard Contractual Clauses executed with respect to Votivus's own processing locations) should further document this arrangement, and will update this section once that advice is finalised.**
- **Sub-processors.** Where a sub-processor performs processing or transfers outside the EEA, Votivus requires that sub-processor to maintain a valid Chapter V mechanism: adequacy (including the EU–US Data Privacy Framework where the recipient is certified), the SCCs with any required supplementary measures, or another lawful mechanism. Where the SCCs apply, the parties complete the relevant module and annexes and the SCCs prevail on transfer matters. The responsible party informs the Commissioner before any special-category transfer under Article 46/47 where Cyprus law requires.

---

## 14. Term, precedence, and survival

This DPA takes effect when processing for the Client begins and continues until all such personal data is deleted or returned. On a conflict about data processing, precedence is: (1) the SCCs (transfers); (2) this DPA; (3) the Engagement Terms; (4) the Terms of Service; (5) the Privacy Policy. Confidentiality, liability, and transfer obligations survive termination.

---

## Annex 1: Processing description

Unless an engagement-specific annex says otherwise, section 2 applies. Controller: the Client (as named in the Engagement Terms). Processor: Votivus Consulting Limited. Processor contact: **info@votivusconsulting.com**.

## Annex 2: Technical and organisational measures (Article 32 GDPR)

Votivus implements and maintains the following measures, proportionate to the risk, and reviews them periodically. This Annex describes our actual current practices; where a measure applies differently to our Cloudflare-hosted website/portal versus our self-hosted AI infrastructure, that distinction is noted.

| Area | Measures |
|---|---|
| **Access control** | Access to production systems, the client portal, and our self-hosted AI infrastructure is limited to our two founders; we currently have no additional staff or contractors with access to client data. Access is reviewed on an ongoing basis given the small size of our team, and is revoked promptly if this ever changes. |
| **Authentication** | Multi-factor authentication is enabled on our hosting/security provider (Cloudflare) and on our email accounts. Secure, unique credentials are used; there are no shared logins. |
| **Encryption** | Our website, client portal, and related infrastructure are served through Cloudflare, which provides encryption in transit (TLS). Our self-hosted AI infrastructure device has full-disk encryption enabled. Where a third-party provider (Cloudflare, Stripe, Google Analytics, Attio) offers encryption at rest, we rely on that provider's standard implementation. |
| **Network & device security** | Our website and portal run behind Cloudflare's network and security layer (including bot/abuse protection). Our self-hosted AI device is a dedicated machine used only for this purpose, kept updated, and physically accessible only to our founders. |
| **Segregation** | Client engagement data is logically separated by client within the platforms we use (our application/data platform and our self-hosted AI infrastructure), consistent with how those systems are structured. |
| **Logging & monitoring** | We rely on the security-relevant logging provided by Cloudflare and our other providers (authentication events, access logs) and review them when investigating an issue. |
| **Vulnerability & patch management** | We keep our self-hosted AI device's operating system and software up to date, and rely on our hosting and platform providers (Cloudflare, Stripe, Google Analytics, Attio, Anthropic, Perplexity, and our application/data platform) to maintain their own infrastructure. |
| **Backups & resilience** | We maintain backups of the data and configuration on our self-hosted AI infrastructure, established as a standing practice from 17 July 2026. Data held within Cloudflare and our application/data platform relies on those providers' own backup and resilience practices. |
| **Supplier (sub-processor) diligence** | We select providers (Cloudflare, Stripe, Google Analytics, Attio, our application/data platform, Anthropic, and Perplexity) based on their published security and privacy practices, and put Article 28 contracts or equivalent terms in place where they process personal data on our behalf. |
| **Pseudonymisation & minimisation** | We limit what we collect and process to what the engagement requires, and use pseudonymisation or aggregation where feasible. |
| **Personnel** | Our founders, as the only personnel with access to client data, are personally bound by the confidentiality obligations in the Terms of Service and this DPA. |
| **Incident response** | We maintain a documented process to detect, investigate, escalate, mitigate, and notify personal-data breaches, including the controller-notification timing in section 9. We do not currently carry a retained third-party incident-response or cyber-insurance arrangement; our response relies on our own, direct handling of any incident. |
| **Secure deletion & return** | Secure deletion or return of client personal data at the end of an engagement under section 10, including from backups within the normal backup cycle. |

A more detailed, engagement-specific security schedule may supplement (but not reduce) these measures.

## Annex 3: Authorised sub-processors

As listed in the **[Subprocessor List](/subprocessors)**, identifying for each: provider, service/category, purpose, location/hosting region, and transfer mechanism. Our own self-hosted AI infrastructure is described in Annex 2 above and is not a sub-processor (section 6). Changes to the sub-processor list are governed by section 6.

---

*Votivus Consulting Limited: Data Processing Agreement.*
