Legal

Data Processing Agreement

Last updated: August 29, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Valibrio OÜ ("Valibrio") and the customer using Valibrio where Valibrio processes personal data on the customer's behalf.

This DPA is intended to address the requirements applicable to processor relationships under the EU General Data Protection Regulation ("GDPR").

1. Parties and roles

The customer is the controller of personal data that it submits to, collects through, or otherwise instructs Valibrio to process on its behalf. Valibrio OÜ, registry code 17517776, registered in Estonia, acts as the processor for that personal data.

Each party is responsible for complying with the data-protection obligations that apply to it in its respective role.

2. Scope and duration of processing

Valibrio processes personal data as necessary to provide the Valibrio service, including hosting validations, collecting and storing participant responses, presenting results, generating exports, providing requested AI-assisted features, maintaining service security and integrity, and performing related operations requested through the service.

Processing continues for the duration of the customer's use of the relevant Valibrio services and for any additional period in which data is retained in accordance with the agreement, applicable law, or documented retention and deletion procedures.

3. Nature and purpose of processing

Processing may include collection, recording, organization, storage, retrieval, consultation, analysis, transmission to authorized subprocessors, generation of creator-facing results, deletion, and other operations necessary to provide the service.

Valibrio processes customer personal data only to provide and protect the service in accordance with the customer's documented instructions, unless processing is required by applicable law.

4. Categories of data and data subjects

Personal data processed on behalf of a customer may include participant names and email addresses where provided, selections, ratings, written feedback, validation responses, attribution information, uploaded or submitted content, and technical or pseudonymous identifiers used in connection with the service.

Data subjects may include validation participants, respondents, customer personnel, or other individuals whose personal data the customer chooses to process through Valibrio.

Customers are responsible for determining whether the personal data they process through Valibrio is appropriate for the service and for avoiding unnecessary collection of special-category or other sensitive personal data.

5. Customer instructions and responsibilities

The customer instructs Valibrio to process personal data as necessary to provide the services the customer enables and uses. Additional documented instructions may be agreed where reasonably necessary and consistent with the services.

The customer is responsible for ensuring that its instructions and its collection and use of personal data comply with applicable data-protection law, including establishing an appropriate legal basis and providing required notices to data subjects.

If Valibrio reasonably believes an instruction infringes applicable data-protection law, Valibrio may inform the customer and suspend the affected processing where appropriate while the issue is resolved.

6. Confidentiality

Valibrio will ensure that persons authorized to process customer personal data are subject to appropriate confidentiality obligations and access the data only as necessary to perform their responsibilities.

7. Security

Valibrio maintains technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction, taking into account the nature of the processing and the risks presented by the processing.

Valibrio's service uses authentication, authorization and ownership controls, database row-level security, restricted privileged operations, private storage controls where applicable, and security-focused testing intended to maintain separation and protection of customer data.

Additional information about Valibrio's security approach is available on the Security page.

8. Subprocessors

The customer authorizes Valibrio to engage subprocessors where necessary to provide the service. Valibrio will require subprocessors that process customer personal data to provide appropriate data-protection commitments consistent with applicable law.

Valibrio maintains a current list of subprocessors on its Subprocessors page.

Valibrio remains responsible for the performance of its data-protection obligations where required by applicable data-protection law when engaging subprocessors.

9. International transfers

Where processing involves a transfer of personal data outside the European Economic Area and applicable law requires transfer safeguards, Valibrio will use an appropriate lawful transfer mechanism and require relevant subprocessors to do the same.

10. Data-subject requests

Taking into account the nature of the processing, Valibrio will provide reasonable assistance to the customer, where required by applicable law and reasonably possible, in responding to requests from data subjects exercising their data-protection rights.

If Valibrio receives a request relating to personal data for which the customer is the controller, Valibrio may direct the requester to the customer unless applicable law requires otherwise.

11. Security incidents

Valibrio will notify the customer without undue delay after becoming aware of a personal-data breach affecting personal data processed by Valibrio on the customer's behalf where notification is required by applicable data-protection law.

Valibrio will provide information reasonably available to it that the customer reasonably requires to meet applicable breach notification obligations.

12. Compliance assistance

Taking into account the nature of the processing and information available to Valibrio, Valibrio will provide reasonable assistance with applicable obligations concerning processing security, personal-data breaches, data-protection impact assessments, and prior consultation where required by applicable data-protection law.

13. Deletion and return

Customers can delete validations and associated data through the service, and account deletion removes associated application data in accordance with Valibrio's deletion procedures. Uploaded assets associated with deletion may be removed through an asynchronous storage-cleanup process.

Following termination of the relevant services, Valibrio will delete or return customer personal data as required by applicable data-protection law and the customer's documented instructions, unless applicable law requires continued retention. Limited operational, security, billing, or legal records may be retained where lawfully necessary.

14. Demonstrating compliance

Valibrio will make available information reasonably necessary to demonstrate compliance with its processor obligations under applicable data-protection law.

Where required by applicable law, Valibrio will allow reasonable audits or inspections relating to processing under this DPA, subject to appropriate confidentiality, security, scope, and scheduling requirements designed to avoid unreasonable disruption to the service or other customers.

15. Relationship with other terms

This DPA supplements the Valibrio Terms of Service and applies only to processing for which Valibrio acts as a processor on behalf of the customer. Valibrio's processing as an independent controller is described in the Privacy Policy.

If this DPA conflicts with the Terms of Service regarding the processing of personal data on the customer's behalf, this DPA controls to the extent of that conflict.

16. Contact

Questions about this DPA or Valibrio's processing of personal data can be sent to privacy@valibrio.com.