VacatoVacato

Data Processing Agreement

Last updated: August 23, 2026 · Version 1.0

How to use this DPA. This page is Vacato's standard Data Processing Agreement for customers who process personal data through Vacato under GDPR (and similar laws). Print or save as PDF from your browser for your records. For a countersigned PDF or custom schedules, email support@vacato.io. This document supplements the Privacy Policy and Terms of Service.

1. Parties and roles

This DPA is between Vacato (the "Processor") and the customer entity that uses Vacato under an Enterprise or other paid plan that includes a written processing agreement (the "Controller"). Where Vacato determines purposes and means of processing its own account data, Vacato acts as an independent controller as described in the Privacy Policy.

2. Subject matter

Vacato provides domain availability monitoring, watchlists, notifications (email, Telegram, Slack, Discord, webhooks, browser push), organization membership, and related APIs. Personal data may include account emails, notification destinations, organization membership, and domains the Controller chooses to track.

3. Duration

Processing lasts for the term of the Controller's Vacato subscription and any post-termination retention needed for legal or security obligations, after which Vacato deletes or returns personal data as described in the Privacy Policy and Settings export/delete flows.

4. Nature and purpose

Processing is limited to providing the Vacato service: authentication, domain checks, alerting, billing metadata via Polar.sh, support, security, and abuse prevention. Vacato does not sell personal data.

5. Types of data and subjects

  • Account holders and invited organization members
  • Contact identifiers for alerts (email, Telegram chat ID, webhook URLs)
  • Service usage and security logs (including IP for rate limiting)

6. Processor obligations

  • Process personal data only on documented instructions from the Controller, including this DPA and product configuration
  • Ensure persons authorized to process data are bound by confidentiality
  • Implement appropriate technical and organizational security measures
  • Assist with data subject requests, DPIAs, and breach notification as reasonably required
  • Delete or return personal data after the end of services, unless law requires retention
  • Make available information necessary to demonstrate compliance, subject to confidentiality

7. Sub-processors

Vacato uses sub-processors to operate the service, including hosting and database (Supabase), payments (Polar.sh), transactional email (Resend), and optional error monitoring (Sentry, when enabled). A current list is available on request at support@vacato.io. Vacato will notify the Controller of material sub-processor changes where required by law.

8. International transfers

Where personal data is transferred outside the EEA/UK, Vacato relies on appropriate safeguards (such as Standard Contractual Clauses) with sub-processors, or other lawful transfer mechanisms described in the Privacy Policy.

9. Security

Vacato maintains access controls, encryption in transit, least-privilege service roles, rate limiting, and audit logging for organization actions. Controllers should also secure their own notification endpoints and API keys.

10. Breach notification

Vacato will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, and provide information reasonably available to assist with the Controller's own notification duties.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service, except where prohibited by applicable data-protection law. If there is a conflict between this DPA and the Terms regarding data protection, this DPA controls for that subject matter.

12. Contact

Privacy and DPA requests: support@vacato.io

Request countersigned copy