Vilmak
Data Processing Agreement
Effective date: 9 September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the tenant company ("Controller") and Vilmak Ltd (company number 17425133, registered office: Bowen Suite, The Globe Centre, 1 St. James Square, Accrington, BB5 0RE) ("Processor"), for the provision of the Vilmak outreach platform (the "Service"), and applies whenever Vilmak processes personal data on the Controller's behalf. It is incorporated by reference into our Terms of Service.
1. Subject matter and duration
This DPA applies for the duration of the Controller's use of the Service under the Terms of Service, and for so long afterwards as Vilmak retains any personal data processed on the Controller's behalf.
2. Nature and purpose of processing
Vilmak processes personal data solely to provide the Service: operating the platform, storing the Controller's business contacts, sending email campaigns using the Controller's own connected sending accounts, checking those accounts for replies, enforcing unsubscribe/suppression requests, generating account and delivery records, and maintaining backups, all as instructed by and configured by the Controller through its use of the Service.
3. Types of personal data
Name and email address of Authorised Users; hashed passwords; role assignments; and, within Contact Data (as defined in the Terms of Service) supplied by the Controller — name, email address, phone number, job title, company name, and website of the Controller's business contacts, together with campaign delivery, reply, and unsubscribe/suppression status relating to each contact. Also, the Controller's own email-sending account credentials (SMTP and, where configured, IMAP username and password), which Vilmak stores encrypted and processes solely to send the Controller's campaigns and check for replies on the Controller's instruction.
4. Categories of data subjects
The Controller's own Authorised Users (its team members with platform access), and the individuals whose details are included in the Controller's Contact Data — that is, the business contacts the Controller markets to. The Controller is the data controller for these individuals and is responsible for ensuring it has a lawful basis to process their data, as set out in the Terms of Service.
5. Controller's instructions
Vilmak will process personal data only on the Controller's documented instructions, which are given by the Controller's configuration and use of the Service, and as otherwise agreed in writing, unless required to do otherwise by law — in which case Vilmak will inform the Controller before processing, unless prohibited from doing so.
6. Confidentiality
Vilmak will ensure that any personnel authorised to process personal data are subject to a duty of confidentiality.
7. Security measures
Vilmak implements appropriate technical and organisational measures, including:
- Hashing of passwords — never stored in plain text.
- Encryption at rest of the Controller's connected email-sending account credentials.
- Off-site backups (IONOS Object Storage), in addition to local backups.
- Tenant-level data isolation — each tenant can only access its own data.
- Role-based access control within the platform.
- Restriction of access to production systems and customer data to authorised personnel.
- Logging of support-access ("impersonation") to a Controller's account by Vilmak staff, used only where necessary to resolve a specific support issue.
8. Sub-processors
The Controller authorises Vilmak to engage the following sub-processors:
- IONOS Cloud Ltd. (company number 3953678) — for hosting the platform's server and database.
- IONOS Cloud Ltd. (company number 3953678) — for sending transactional emails (password resets, account notifications).
- IONOS Object Storage — for off-site backup storage (stored in the EU, eu-central-3 region, Berlin, Germany).
- Stripe — for payment and subscription billing processing.
Vilmak will inform the Controller of any intended changes to sub-processors, giving the Controller a reasonable opportunity to object on reasonable data-protection grounds. Vilmak remains responsible for the acts and omissions of its sub-processors as if they were its own.
9. International transfers
Personal data is stored primarily within the United Kingdom, with off-site backups stored within the European Economic Area (Berlin, Germany). The UK's data protection framework recognises the EEA as providing an adequate level of protection, so no additional transfer safeguards are currently required. If Vilmak engages a sub-processor outside the UK or EEA in a jurisdiction not covered by adequacy regulations, Vilmak will put in place an appropriate transfer mechanism (such as the UK's International Data Transfer Addendum) before doing so.
10. Assistance with data subject rights
Vilmak will, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures to respond to requests from data subjects exercising their rights under data protection law. Where a data subject contacts Vilmak directly, Vilmak will refer the request to the Controller and provide reasonable assistance as required. The Service already provides an automated self-service means for a data subject to unsubscribe, which the Controller should treat as satisfying an objection to further marketing without needing to contact Vilmak separately.
11. Personal data breach
Vilmak will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide reasonably available information to help the Controller meet its own breach-notification obligations.
12. Data protection impact assessments
Vilmak will provide reasonable assistance to the Controller, taking into account the nature of processing and information available to Vilmak, where the Controller is required to carry out a data protection impact assessment or consult with a supervisory authority.
13. Audits
On reasonable written notice, and no more than once per year (except following a security incident), Vilmak will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA. Audits will in the first instance be conducted remotely, through documentation and written responses to reasonable questions; an on-site or physical inspection will only be arranged where reasonably necessary and by mutual agreement on timing. Any audit must be conducted in a manner that does not provide the Controller with access to any other tenant's data or systems, is subject to reasonable confidentiality safeguards, and is at the Controller's own cost unless the audit identifies a material breach of this DPA by Vilmak.
14. Deletion or return of data
On termination of the Service, Vilmak will, at the Controller's choice, delete or return all personal data processed on the Controller's behalf, and will delete existing copies, within the timeframe set out in the Terms of Service, except to the extent retention is required by applicable law or to the limited extent necessary to maintain suppression records as described in the Privacy Policy.
15. Liability
Liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
16. General
This DPA is governed by the laws of England and Wales. In the event of any conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.