Last updated: 16 July 2026
This DPA supplements the Service Terms where Vitrine processes personal data on behalf of a Customer subject to UK/EU GDPR. For Customer content, the Customer is the controller and Vitrine the processor.
Vitrine processes only on the Customer's documented instructions: limited business-contact data of the Customer's users, and product images (not intended to contain personal data). Vitrine does not require the Customer's end-consumer data.
Confidentiality of authorised staff; appropriate security measures; assistance with data-subject requests, breach notification and DPIAs; notice without undue delay after a personal-data breach.
The Customer authorises sub-processors that support the Service (hosting, email) under terms no less protective than this DPA; Vitrine remains liable for them and gives notice of changes. International transfers rely on an appropriate safeguard (e.g. the EU SCCs + UK Addendum). On termination, data is deleted or returned at the Customer's choice, save where retention is required by law.
← Back to vitrine-ai.com