Vythos

Data Processing Agreement

How we process your workspace's personal data

Version 1.0 · 3 October 2026

This agreement is part of the Vythos Terms of Service and applies to every plan. Accepting the Terms accepts it. If you need a signed copy, write to michael@vythos.tech.

Between the customer named in the Vythos account (the Customer, controller) and VYTHOS TECH LIMITED, company number 17470263, 2 Twyford Avenue, London, England, W3 9QA (Vythos, processor).

  1. Definitions

    Terms such as personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings in the UK GDPR and, where it applies, the EU GDPR (Data Protection Law, including the UK Data Protection Act 2018). Customer Personal Data is personal data in the content the Customer and its users put into Vythos, described in Annex 1. Services are the Vythos services under the Terms of Service.

  2. Roles and instructions

    The Customer is the controller of Customer Personal Data and Vythos its processor. Vythos processes Customer Personal Data only on the Customer's documented instructions: this agreement, the Terms of Service, and the Customer's use and configuration of the Services — what its users connect, upload, ask, keep and delete. Vythos tells the Customer if it believes an instruction breaks Data Protection Law, unless the law forbids it.

    Vythos does not sell Customer Personal Data, use it for advertising or profiling, or use it to train AI models.

  3. Vythos's obligations

    Vythos will: (a) ensure everyone authorised to process Customer Personal Data is bound by confidentiality; (b) implement the measures in Annex 2; (c) follow clause 6 for sub-processors; (d) help the Customer answer data subject requests, including through the export, erasure and per-source deletion built into the Services; (e) help the Customer with security, breach notification, impact assessments and prior consultation (Articles 32–36), taking into account what Vythos knows; (f) delete or return Customer Personal Data at the end of the Services (clause 10); and (g) make available the information needed to show compliance with this agreement, and allow audits (clause 9).

  4. The Customer's obligations

    The Customer is responsible for having a lawful basis for the processing it instructs, for the notices it owes the people whose data its content holds — including people mentioned in documents and messages — and for deciding what its users connect. The Customer will not intentionally connect sources whose main content is special category data (health, HR or biometric data, for example) or criminal offence data unless it has assessed that this is lawful and necessary.

  5. Security

    Vythos maintains the measures in Annex 2 and may improve them, never reducing the overall level of protection.

  6. Sub-processors

    The Customer authorises the sub-processors listed on the sub-processors page. Vythos will give at least 30 days' notice of a new or replacement sub-processor of Customer Personal Data, by email to the workspace owner and on that page. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may end the affected Services and receive a pro-rata refund of prepaid fees. Vythos imposes data protection terms on each sub-processor that protect Customer Personal Data at least as well as this agreement, and remains liable for its sub-processors.

  7. International transfers

    Customer Personal Data is stored and processed in the European Union (Annex 1). Vythos will not transfer it to a country without an adequacy decision unless an appropriate safeguard is in place: the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, as applicable. Where this agreement is itself a transfer from the EU to Vythos in the UK, it relies on the EU's adequacy decision for the UK; should that lapse, the parties agree that the EU Standard Contractual Clauses (Module 2) are incorporated.

  8. Data subject requests

    If Vythos receives a request about Customer Personal Data, it will pass it to the Customer within 5 working days and will not answer it unless authorised — except that users may use the self-service tools for their own data.

  9. Breaches and audits

    Vythos will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it, with what is known — its nature, the categories and approximate numbers involved, likely consequences, and measures taken — and update the Customer as more is known.

    Vythos will answer reasonable written questions about its compliance and provide its current security documentation. Where that is not enough, the Customer, or an independent auditor bound by confidentiality, may audit on 30 days' notice, once a year, at its own cost, without access to other customers' data.

  10. End of the Services

    On termination, the Customer may export its data for 30 days. Vythos then deletes Customer Personal Data from its live systems; deleted data leaves encrypted backups within 14 days. Vythos may keep what law requires it to keep. A workspace deleted by its owner is deleted at once in the same way.

  11. General

    This agreement lasts as long as Vythos processes Customer Personal Data. Liability is as limited in the Terms of Service. If this agreement and the Terms of Service conflict on data protection, this agreement prevails. It is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex 1 — Details of processing

Subject matter and durationProviding the Services, for the term of the Customer's subscription, plus clause 10
Nature and purposeStoring, indexing, searching and retrieving the Customer's content; reading rule values with an AI model; answering users' questions with an AI model; delivering rules and memory to the users' own AI tools; deleting and exporting on instruction
Data subjectsThe Customer's users; its staff, contractors, clients and clients' staff; correspondents and others named in connected documents and messages; CRM contacts
Personal dataIdentification and contact details; job and business details; the content of documents, emails, chat messages and CRM records; questions and answers; connected-account identifiers
Special categoriesNot intended. May occur incidentally in content the Customer connects (clause 4)
LocationMicrosoft Azure, Sweden Central (EU); AI processing in the Azure OpenAI EU Data Zone; backups in Azure's paired region in Sweden
RetentionWhile the workspace exists; deleted on the Customer's or a user's instruction; see clause 10

Annex 2 — Technical and organisational measures

Annex 3 — Sub-processors

As listed on the sub-processors page on the date the Customer accepted the Terms. Today, for workspace content: Microsoft (Azure hosting, Azure OpenAI and Azure Communication Services).