This Data Processing Addendum ("DPA") forms part of the VibeCode Terms of Service between VibeCode Technologies Pvt. Ltd. ("Processor", "we") and the Customer ("Controller", "you") whenever we process personal data on your behalf — typically when you use VibeCode Hiring, Enterprise, or the API.
1. Roles
You are the Controller of personal data you upload or collect through VibeCode (candidate profiles, applicant notes, team members). We act as your Processor and only process that data on your documented instructions, primarily via the product UI and API.
2. Scope of processing
- ▸ Subject matter: providing the VibeCode Hiring / Enterprise service.
- ▸ Duration: for the term of your subscription plus 30 days for deletion.
- ▸ Nature: hosting, storage, retrieval, display, analytics and back-ups.
- ▸ Data types: names, emails, work history, portfolio links, application content, messages.
- ▸ Data subjects: your team members, candidates, and community members you interact with.
3. Security measures
- ▸ Encryption in transit (TLS 1.2+) and at rest (AES-256).
- ▸ Row-level security on every tenant table; least-privilege service roles.
- ▸ SSO + optional SAML for Enterprise; 2FA available for all accounts.
- ▸ Audit logs for admin actions, retained 12 months.
- ▸ Annual third-party penetration test; findings tracked to closure.
- ▸ Background-checked personnel with signed confidentiality agreements.
4. Sub-processors
We use a short list of vetted sub-processors, each bound by a DPA at least as protective as this one. Current list:
- ▸ AWS (ap-south-1, Mumbai) — primary hosting & storage.
- ▸ Supabase — managed Postgres, auth and storage.
- ▸ Cloudflare — CDN, WAF and DDoS protection.
- ▸ Resend — transactional email delivery.
- ▸ Sentry — error monitoring (scrubbed PII).
We give 30 days' notice before adding or replacing a sub-processor. You may object in writing; if we can't resolve the objection you can terminate the affected service.
5. International transfers
Primary storage is in India (ap-south-1). Where data leaves India (e.g. Sentry, Resend), transfers rely on Standard Contractual Clauses (EU) and equivalent DPDP-compliant mechanisms.
6. Data subject rights
We help you respond to access, rectification, deletion, portability and objection requests within 7 business days. Most requests can be fulfilled by you directly from the admin dashboard.
7. Breach notification
We will notify you without undue delay, and in any case within 48 hours, of any confirmed personal-data breach affecting your data, along with known scope, impact and remediation steps.
8. Audits
You may audit our compliance once per year with 30 days' notice, or rely on our latest SOC 2 Type II / ISO 27001 report (available under NDA to Enterprise customers).
9. Deletion and return
On termination we delete or return your personal data within 30 days, except where retention is required by law. Certificate of deletion available on request.
10. Governing law
This DPA is governed by the laws of India, with jurisdiction in Bengaluru. For EU data subjects, GDPR terms take precedence where mandated.
Countersigned DPA (PDF) available for Hiring and Enterprise customers. Email vibecoderindia@gmail.com with your company name and billing entity to receive a copy. Last updated 15 July 2026.