Trust

Draft — to be reviewed by counsel before launch. Applies to business customers as processor terms under GDPR art. 28.

1. Roles

The customer is the controller of the personal data in the files it transfers and the recipient addresses it enters; Vessio is the processor. For account data Vessio is the controller (see the privacy policy).

2. Instructions

Vessio processes customer data only to deliver the service as configured by the customer: storing objects until expiry, delivering them to the recipients the customer named, scanning Standard-mode files by the published policy, and sending the notifications the customer triggers.

3. Confidentiality and security

Staff with access are bound to confidentiality. Measures: encryption in transit (TLS) and at rest; end-to-end encryption available on every paid plan, in which case Vessio holds ciphertext only; passkey sign-in; audit logging of administrative actions; least-privilege access; backups with tested restore; a documented incident process.

4. Sub-processors

Listed on the sub-processor page, all within the EU/EEA. Changes are announced 30 days ahead; the customer may object and terminate.

5. Assistance and deletion

Vessio assists with data-subject requests and breach notifications (without undue delay, and within 48 hours of becoming aware). At the end of the service, data is deleted per the retention schedule; the customer can delete transfers at any time.

6. Audits

Vessio provides the trust page, the public threat model and the results of independent security reviews. Further audits by agreement.