Data Processing Agreement

This applies whenever Vesper handles personal data on your behalf. It forms part of the Terms of Service and takes effect the moment you send us your first request — there is nothing to sign unless you want a countersigned copy, which we will provide on request.

Version 1.0 In force from 6 September 2026 Role Vesper is the processor

1Roles

You are the controller. You decide what your users are asked, why, and what happens to the answer. We are your processor: we act on your instructions and for no purpose of our own.

This agreement is governed by UK GDPR and the Data Protection Act 2018, and by EU GDPR where it applies to you.

2What we process

Categories of data subject

End users of your application who interact with Vesper.

Categories of personal data

Whatever appears in the messages your application sends us. In normal use that is a spoken or typed request — a question, an instruction — which may incidentally contain a name or a personal detail the user chose to say.

Special category data

None, and you must not send it. Health, sexuality, religion, politics, biometrics and criminal offence data are outside the scope of this agreement. If your application would foreseeably send those, tell us before you integrate.

Duration

For the length of a single request. Messages are held in memory long enough to answer and are not written to a database. What persists is a count of requests and their cost.

3Your instructions

Our documented instruction is simple: answer the message and return the answer. That is the whole processing operation.

We will not process the data for any other purpose. In particular we do not use it to train, fine-tune or evaluate models, we do not profile your users, and we do not contact them.

If we believe an instruction from you would breach data protection law, we will tell you rather than carry it out.

4Confidentiality

Anyone with access to your data is bound by a duty of confidentiality that survives the end of their engagement. Access is limited to people who need it to run or support the service.

5Security measures

  • Encryption in transit — TLS on every route in and out. There is no unencrypted path.
  • Encryption at rest — provided by Google Cloud for everything we store.
  • No message retention — the strongest measure available: data that is never written cannot be breached.
  • Credential hygiene — API keys are stored only as a SHA-256 fingerprint. We cannot recover a key, and neither can anyone who reaches the database.
  • Least privilege — database rules refuse each customer any record but their own, and refuse the fields that decide money even on their own record.
  • Immediate revocation — a revoked key fails on the next request, not at the next renewal.
  • Spend ceilings — enforced before a request is served, so a runaway integration is bounded rather than discovered on an invoice.

6Sub-processors

You give general authorisation for the following, and no others:

  • Google Cloud / Firebase (Ireland & EU) — hosting, authentication, database.
  • Google Gemini API — generates the reply.
  • Google Cloud Text-to-Speech — synthesises the voice.
  • Cloudflare (global edge) — serves the API endpoint. Requests pass through; nothing is stored there.

We will give you 30 days’ notice before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may terminate without penalty and we will refund the unused part of your term.

7International transfers

Your account data and usage counters are stored in the EU (eur3). Generation and speech synthesis may be processed in other Google regions, covered by the UK International Data Transfer Addendum and the EU Standard Contractual Clauses that Google incorporates into its terms.

8Helping with requests

If a user exercises their rights — access, erasure, portability — you can almost always answer without us, because we hold nothing about them: no identifier, no message history, only an anonymous count of requests.

Where you do need us, we will help within 10 working days at no charge.

9Breaches

We will tell you without undue delay and within 48 hours of becoming aware of a personal data breach affecting your data, with what we know, what we are doing, and what you may need to tell your users or the ICO.

We will not wait until we understand it fully before telling you. A late complete report is worse than an early incomplete one.

10Audit

On reasonable notice, once a year, we will answer a security questionnaire and provide the information you need to demonstrate compliance. For an on-site audit or a penetration test, ask — we will agree scope and timing rather than refuse.

11Deletion

When your contract ends we delete your account and usage data within 30 days, except records we must keep for tax or legal reasons. There is nothing to delete on the message side, because nothing was kept.

Cached audio persists, being content-addressed text nobody can retrieve without already possessing it. If you want yours purged, ask and we will do it.

12Liability

The liability provisions of the Terms of Service apply to this agreement. Nothing here limits either party’s liability to a data subject under data protection law.