Skip to content
Legal · Data Processing Agreement

Data Processing Agreement

Last updated · May 1, 2026

VEXOCORE acts as a processor on behalf of customers (controllers) when delivering paid services. This DPA, including the EU SCCs and UK IDTA addendum, governs that relationship and forms part of the Master Services Agreement.

Roles

Customer is the controller; VEXOCORE is the processor. Sub-processors are listed below and may be updated with 30 days’ notice.

Cross-border transfers

We rely on EU SCCs (module 2 or 3 as applicable), the UK IDTA Addendum, and the EU–US Data Privacy Framework for US-based processing.

Security measures

See our Trust Center for the full set of technical and organisational measures.

Sub-processors

NamePurposeRegion(s)
Amazon Web ServicesPrimary cloud infrastructureEU, US, APAC
CloudflareEdge CDN & DDoS protectionGlobal
ResendTransactional email deliveryUS
InngestBackground job orchestrationUS
SentryApplication error monitoringEU
Meilisearch CloudContent search indexEU

Request a counter-signed copy

Email legal@vexocore.io with your entity name and DPO contact, and we’ll return a signed DPA within 24 hours.