Data Processing Agreement
Pilot draft v1 · August 2026 · Art. 28 GDPR. Executed per-customer on signature; contact michael@ivi.vc.
1. Subject matter and duration
This agreement governs ivi's processing of personal data contained in customer documents (capital account statements, fund reports, capital call notices) and associated account data, for the purpose of providing the audit-grade extraction and portfolio intelligence service (the "Service"), for the duration of the customer's subscription and until deletion under § 7.
2. Nature and purpose of processing
Receiving, optically reading, extracting figures from, storing, and presenting the customer's fund documents; operating the customer's account (authentication, transactional email, processing events). The customer is the controller for this data; ivi processes it as a processor on the customer's documented instructions (the Service's configured behavior).
3. Categories of data subjects and data
Data subjects: the customer's authorised users. Personal data: names, e-mail addresses, authentication records, and personal financial data contained in uploaded fund documents (e.g. capital account balances). Sensitive categories are not knowingly collected; fund documents may contain personal financial data processed only for the Service.
4. Subprocessors
The provider (processor) uses the following subprocessors, current as of August 2026 (mirrors the Privacy Policy):
- Supabase (Supabase, Inc.) — database, authentication, file storage (London, UK)
- NetCup GmbH — application hosting (Germany)
- Mistral AI — OCR API (document text recognition)
- Railway — hosting of our self-managed OCR (Docling) container
- OpenAI — text extraction models, accessed via the Vercel AI Gateway (Vercel, Inc.)
- Inngest — background job processing
- emailit — transactional e-mail delivery
- Stripe — payment processing (when a paid subscription is active)
The customer grants general authorisation for these subprocessors; material changes will be notified by e-mail with a right to object. Data-processing terms with each subprocessor mirror the protections of this agreement.
5. Obligations and rights of the customer
ivi assists the customer in responding to data-subject rights requests (access, rectification, export, erasure) by making the affected data available or deleting it on the customer's documented instruction, within one business day during the pilot.
6. Technical and organisational measures (TOMs)
- Encryption in transit (TLS) for all data movement.
- Per-customer isolation at the database and API layer (team scoping enforced server-side).
- Access limited to personnel who need it; authentication records retained.
- Customer documents and extracted figures are never used to train AI models and never shown to other customers.
- Audit-grade per-figure provenance for extracted financial data.
7. Deletion and return
On termination, the customer's documents and extracted figures are deleted within 30 days of a deletion request (or exported beforehand on request), except where retention is legally required.
8. Audits and information
ivi provides the information necessary to demonstrate compliance and, during the pilot, conducts audits via the per-figure provenance records; on-site audits may be agreed for paid engagements.
9. Personal-data breaches
ivi notifies the customer without undue delay upon becoming aware of a personal-data breach affecting the customer's data, including the information required by Art. 33(3) GDPR.
10. Governing law
The law of the operator's seat of business (see Imprint).