Data Processing Agreement
Third Vector acts as processor under this agreement whenever it handles personal data for a business client: in Applied AI Services, when a Facilitated Node or review cycle brings personal data to it, and in hosted Canopy features once they ship. It is written to meet Article 28 GDPR and takes effect when an Order Form or SOW that incorporates it is signed, so it needs no signature of its own.
Version 1.1 · 2 October 2026
Parties: Third Vector Advisory B.V., registered in the Netherlands, KvK 99226774, Heemraadssingel 123A, 3022 CC Rotterdam, the Netherlands (“Third Vector”, “we”, “us”), and the Client that buys from us under the Third Vector Terms (“you”). Contact: legal@thirdvector.io.
How it applies to your engagement: the Order Form or SOW says whether personal data is processed at all and, if it is, fills in Annex 1 (what data, whose, why) and names any sub-processor beyond the published list in Annex 3.
1. About this DPA
1.1 What it covers
This data processing agreement (DPA) applies whenever we process personal data on your behalf while delivering what you bought under the Third Vector Terms (the “Terms”). That covers three cases:
- Applied AI Services, where the SOW lists materials that contain personal data (section 12.2 of the Terms);
- Facilitated Nodes and review cycles, where you share outputs that contain personal data, or we see it in your environment during a session (section 12.1); and
- hosted Canopy features that store or process Client Content on our systems (section 12.3).
1.2 When it applies
This DPA takes effect when an Order Form or SOW that says it applies is signed, or when both parties agree in writing that it applies to an existing engagement; email is enough. Signing that Order Form or SOW signs this DPA. It then applies for as long as we process Client Personal Data.
1.3 What it does not cover
Personal data we process as controller under our Privacy Policy: the contact, booking and intake details of Academy participants (section 7.8 of the Terms), and the business contact details of your people that we use to run our relationship with you.
1.4 How it fits with the Terms
This DPA forms part of the agreement described in section 1.3 of the Terms. On the processing of personal data it prevails over the Terms and the SOW, and only an Order Form that names the section of this DPA it changes can vary it. Where this DPA is silent, the Terms apply. Where the SCCs apply (section 6), they prevail over this DPA.
2. Definitions
- Client Personal Data: personal data we process on your behalf under the agreement, whether it sits in Client Content you share with us, in systems you give us access to, or in anything we create from those.
- Data Protection Law: the GDPR, the Dutch GDPR Implementation Act (Uitvoeringswet AVG), and any other law on the protection of personal data that applies to the processing, including the UK GDPR and the Swiss Federal Act on Data Protection where they apply.
- EEA: the European Economic Area.
- GDPR: Regulation (EU) 2016/679, the General Data Protection Regulation.
- SCCs: the standard contractual clauses for transfers to third countries approved by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.
- Sub-processor: a third party we engage to process Client Personal Data on your behalf. It does not include our employees, or individual contractors who work within our team, on our systems and under our instructions (section 16.1 of the Terms).
Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meaning given in Article 4 GDPR. Other capitalised terms, such as Client, Client Content, Order Form, SOW, Facilitated Node, Canopy Node and AI Provider, have the meaning given in the Terms.
3. Roles and instructions
3.1 Who is who
You are the controller of Client Personal Data and we are your processor. Where you process that data as a processor for your own client, we are your sub-processor, and you confirm that your client has authorised you to engage us on these terms.
3.2 Your instructions
We process Client Personal Data only on your documented instructions, including on transfers outside the EEA (section 6). At signature, your instructions are the Order Form, the SOW, the Terms and this DPA, including Annex 1. You may give further instructions in writing; email is enough. An instruction that changes the scope, deliverables or timeline is a change under section 6.3 of the Terms. Where EU or Member State law requires us to process Client Personal Data other than on your instructions, we tell you before we do, unless that law forbids it.
3.3 Instructions we believe are unlawful
We tell you immediately if we believe an instruction infringes Data Protection Law. We may pause the processing it concerns until you confirm, change or withdraw it.
3.4 What you are responsible for
You make sure that you have a lawful basis for the processing and for sharing Client Personal Data with us, that data subjects have been told what the law requires, and that your instructions comply with Data Protection Law. You share only the personal data the SOW needs, and remove or pseudonymise the rest where you can. You do not share special categories of personal data (Article 9 GDPR) or data on criminal convictions and offences (Article 10 GDPR) unless the Order Form or SOW names them and the extra measures that apply.
3.5 Your own AI Provider
Where Canopy Nodes run in your own environment on the AI Provider you choose (sections 12.1 and 13.1 of the Terms), that AI Provider processes data for you under your contract with it. It is not our sub-processor, and this DPA does not cover it.
4. What we commit to
4.1 Purpose
We use Client Personal Data only to deliver what you bought. We never use it to train AI models, to develop other products, or for the learnings in section 10.6 of the Terms.
4.2 Our people
Only the people delivering your engagement, including contractors, and our directors have access to Client Personal Data. Where your Order Form asks for it, we limit access further to the people it names. Each of them is bound by confidentiality obligations at least as protective as section 11 of the Terms (section 16.1 of the Terms).
4.3 Security
We apply the technical and organisational measures in Annex 2, which give a level of security appropriate to the risk, as Article 32 GDPR requires. We may update them as technology and risks change, provided the overall level of protection does not go down.
4.4 Your systems
Where you give us access to your own systems, we also follow the security policies you give us in writing (section 12.2 of the Terms).
4.5 Records
We keep a record of the processing we carry out on your behalf, as Article 30(2) GDPR requires.
5. Sub-processors
5.1 Authorisation
You give us general authorisation to engage the sub-processors on our published list (Annex 3, at thirdvector.io/subprocessors) and any sub-processor named in your Order Form or SOW.
5.2 Notice of changes
Before we add or replace a sub-processor, we tell you by email at least 14 days before it first processes Client Personal Data, and we update the published list.
5.3 Your right to object
You may object on reasonable data protection grounds within those 14 days. We then look in good faith for a solution, such as not using that sub-processor for your data. If we cannot find one, either party may end the affected SOW or hosted feature by written notice, and section 9.2 of the Terms applies as if you had ended it for cause.
5.4 The same obligations
We engage each sub-processor under a written contract that imposes data protection obligations that are, in substance, the same as those in this DPA, including sufficient guarantees on security. AI providers process Client Personal Data only on terms that exclude training on it (section 12.2 of the Terms).
5.5 We stay responsible
We remain responsible to you for our sub-processors’ performance of their obligations, within section 11.
6. Transfers outside the EEA
6.1 When we transfer
We transfer Client Personal Data to a country outside the EEA, or let a sub-processor access it from there, only on your instructions and with a transfer mechanism under Chapter V GDPR in place. Annex 3 shows where each sub-processor processes data and the mechanism it relies on, and signing this DPA instructs us to make the transfers Annex 3 describes.
6.2 Which mechanism
Each transfer relies on one of:
- an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for a recipient certified under it;
- the SCCs, Module 3 (processor to processor), in place between us and the sub-processor or between the sub-processor and its own sub-processor; or
- another mechanism Chapter V GDPR allows.
For data subject to UK or Swiss law, the SCCs apply with the UK International Data Transfer Addendum or the Swiss adjustments, as the case requires.
6.3 If a mechanism falls away
If a mechanism we rely on is invalidated or suspended, we move the transfer to another valid mechanism without undue delay, or stop it.
6.4 Clients outside the EEA
Where you are established outside the EEA and we send Client Personal Data to you, Module 4 of the SCCs (processor to controller) applies where Data Protection Law requires it, and is incorporated into this DPA by reference.
7. Personal data breaches
7.1 We tell you within 48 hours
We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client Personal Data.
7.2 What we tell you
As far as we know it at the time: what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, what we have done or propose to do, and who to contact. Where we do not yet have all of it, we send what we have and follow up as we learn more.
7.3 What we do
We take reasonable steps to contain the breach and limit its effects, and we help you meet your own obligations to notify the supervisory authority and data subjects under Articles 33 and 34 GDPR. We do not notify the authority or data subjects on your behalf unless you ask us to or the law requires it. Notifying you of a breach is not an admission of fault or liability.
7.4 Where notices go
We send breach notices to the contact named in the Order Form, or otherwise to the person who signed it. You report a suspected breach to us at legal@thirdvector.io.
8. Helping you meet your obligations
8.1 Requests from data subjects
If a data subject contacts us directly about Client Personal Data, we pass the request to you within 5 business days and do not answer it ourselves, other than to say we have passed it on. We help you respond to requests to exercise rights under Chapter III GDPR, through appropriate technical and organisational measures and taking into account the nature of the processing.
8.2 Assessments and consultation
We give you reasonable help with your obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to us.
8.3 Cost
Help under this section is included up to four hours in any twelve months. Beyond that, we charge at the rates in the Order Form or SOW, or otherwise at our standard rates, and agree an estimate with you first. Help needed because we breached this DPA is always free.
9. Audits and information
9.1 Information
On request, we give you the information you reasonably need to show that we meet Article 28 GDPR and this DPA. That includes our current measures under Annex 2, the sub-processor list, and, once in any twelve months, our answers to a reasonable security questionnaire.
9.2 Audits
Where that information is not enough, or a supervisory authority asks for it, you may audit our compliance with this DPA, yourself or through an independent auditor who is bound by confidentiality and is not our competitor. An audit takes place once in any twelve months, unless a personal data breach or a supervisory authority gives reason for another, on at least 30 days’ written notice, during business hours, and without unreasonable disruption to our work.
9.3 Sub-processors
For our sub-processors, we meet this section by passing on the audit reports and certifications they make available to us, such as SOC 2 or ISO/IEC 27001 reports, where their terms allow.
9.4 Cost
You bear the cost of an audit, including our reasonable time at the rates in the Order Form. We bear our own costs where an audit finds that we materially breached this DPA.
10. Return and deletion
10.1 At the end
When the SOW or hosted feature ends, or earlier on request, we return or delete Client Personal Data, as you choose, within 90 days. If you have not chosen within 14 days of the end, we delete it.
10.2 Copies
Deletion covers copies on our systems and with our sub-processors. Copies in backups, or in a sub-processor’s own deletion cycle, are kept out of use and deleted in that cycle. Where EU or Member State law requires us to keep Client Personal Data, we keep only what it requires, protect it under this DPA, and delete it when the requirement ends.
10.3 Confirmation
On request, we confirm the deletion in writing.
11. Liability
11.1 The cap applies
Our liability under this DPA falls within section 15 of the Terms, including the cap in section 15.1. This DPA does not say otherwise.
11.2 What the cap leaves alone
The cap works between the two of us. It does not limit the rights of data subjects under Article 82 GDPR, or liability that the law does not allow to be limited (section 15.4 of the Terms). Each party bears any administrative fine a supervisory authority imposes on it.
11.3 Shared responsibility
Where one party has paid full compensation to a data subject for damage the other party caused in part, it may recover the other party’s share under Article 82(5) GDPR. Our share stays within the cap.
12. Duration, changes and law
12.1 Duration
This DPA applies for as long as we process Client Personal Data for you, and ends once section 10 is complete. Sections 7, 10 and 11 continue for as long as they are needed.
12.2 Changes
The version of this DPA in force when your Order Form or SOW is signed applies to it. We may update it on 30 days’ written notice where Data Protection Law, a supervisory authority or a court requires it, or where the change does not reduce the protection of Client Personal Data. Any other change needs your written agreement.
12.3 Law and disputes
This DPA is governed by Dutch law, and disputes go exclusively to the competent court in Rotterdam (section 17 of the Terms). Where the SCCs apply, they are governed by Dutch law and the Dutch courts are their forum.
Annex 1: Description of processing
The table sets the default for each kind of engagement. The Order Form or SOW narrows it, or adds to it, for yours.
| Applied AI Services | Facilitated Nodes and review cycles | Hosted Canopy features | |
|---|---|---|---|
| Subject matter and purpose | Delivering the SOW: capturing your playbooks, methods or processes as Skills, and building and testing Custom Skills and Custom Nodes | Delivering the Facilitated Node and reviewing the outputs you choose to share | Storing and running Custom Skills and related Client Content for you |
| Data subjects | Your employees and contractors; people interviewed or recorded for the SOW; your customers or other people named in the materials you share | Your employees and contractors taking part in sessions; people named in outputs you share | Your users of the feature; people named in content you store |
| Personal data | Names, roles and work contact details; statements, opinions and decisions in interviews, recordings and transcripts; voice and image in recordings; personal data in documents and system exports the SOW lists | Names and roles; personal data visible on screen during a session or contained in shared outputs | Account details of your users; personal data in stored content |
| Nature of processing | Receiving, storing, transcribing, structuring and analysing, including with AI models; consultation; return and deletion | Viewing during sessions; receiving, reviewing and deleting shared outputs | Storage, execution and deletion, as the feature’s supplementary terms describe |
| Duration | The SOW term, plus up to 90 days for return or deletion (section 10) | The Facilitated Node, plus up to 90 days | While you use the feature, plus up to 90 days |
Special categories of personal data and data on criminal convictions are excluded, unless the Order Form or SOW names them with the extra measures that apply (section 3.4).
Per engagement, the Order Form or SOW records:
- The engagement and SOW reference.
- The data subjects and personal data involved, from the table above or in addition to it.
- Any special categories, with the extra measures.
- Any of your systems we access, and the security policies that apply there (section 4.4).
- Any sub-processor used beyond Annex 3.
- Your contact for breach notices (section 7.4).
Annex 2: Technical and organisational measures
These are the measures we apply to Client Personal Data under section 4.3.
Access and accounts
- Client Personal Data is handled only in Third Vector’s company accounts on the services in Annex 3, never in personal accounts.
- Multi-factor authentication is on for every account that can reach Client Personal Data.
- Access is limited to the people delivering the engagement, including contractors, and Third Vector’s directors. Where the Order Form asks for it, we limit access further to the people it names.
Storage and handling
- Client materials are kept in a folder per client in our Google Workspace shared drives, and in a project space per client in Notion.
- Client Personal Data is not stored on removable media or outside the systems in Annex 3.
- Data is encrypted in transit and at rest by the providers in Annex 3.
AI processing
- Client Personal Data is processed only through the AI providers in Annex 3, on commercial terms that exclude training on it.
- Where the SOW allows, we remove or pseudonymise personal data before AI processing.
Devices
- Work laptops use full-disk encryption, automatic screen lock and current operating system updates.
People
- Everyone with access is bound by confidentiality obligations at least as protective as section 11 of the Terms.
- Sessions are recorded only with the consent of everyone present (section 7.8 of the Terms).
Deletion
- Return or deletion of Client Personal Data within 90 days after the engagement ends (section 10).
Annex 3: Sub-processors
Our current sub-processors, with where each processes data and the transfer safeguard it relies on, are listed at thirdvector.io/subprocessors. That page is this Annex 3, and we update it under section 5.2.