Data Processing Agreement
Last updated: August 6, 2026
This Data Processing Agreement ("DPA") forms part of the Visork Terms of Service (the "Agreement") between the customer identified in the Agreement ("Customer") and Filip Šedivý, sole trader (OSVČ), registered in the Czech Trade Licensing Register (živnostenský rejstřík), Business ID (IČ): 05435561, Hledíková 3008/2, Praha 10, 106 00, Czech Republic ("Processor").
It reflects the parties' agreement on the processing of personal data under Article 28(3) GDPR. To obtain a countersigned copy of this DPA, or to discuss enterprise amendments, contact hello@visork.com.
1. Definitions
- GDPR means Regulation (EU) 2016/679. The terms personal data, data subject, processing, controller, processor, personal data breach, and supervisory authority have the meanings given in the GDPR.
- Customer Personal Data means personal data contained in Customer Content (as defined in the Agreement) that the Processor processes on behalf of the Customer.
- Sub-processor means any processor engaged by the Processor to process Customer Personal Data.
- Service has the meaning given in the Agreement.
2. Roles and Scope
The Customer acts as controller of Customer Personal Data. Where the Customer itself acts as a processor for a third-party controller, the Customer warrants that it is authorized to engage the Processor as a sub-processor and that its instructions are consistent with the controller's instructions.
The Processor processes Customer Personal Data only on behalf of the Customer and only for the purpose of providing the Service.
Each party complies with the obligations that apply to it under the GDPR and other applicable data-protection law.
3. Processing on Documented Instructions
The Processor processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by EU or member-state law to which the Processor is subject (see Section 13).
The parties agree that the Customer's complete and final documented instructions consist of: the Agreement, this DPA, and the configuration and API options made available by the Service and selected by the Customer. Additional instructions require prior written agreement of the parties.
The Processor shall inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.
4. Customer Obligations
The Customer is responsible for:
- ensuring a valid legal basis for the processing of Customer Personal Data, including — where the content of submitted material involves special categories of personal data (Article 9 GDPR) or data relating to criminal offences (Article 10 GDPR) — the applicable conditions or authorizations,
- providing data subjects with the information required by Articles 13 and 14 GDPR,
- ensuring that its instructions comply with applicable law,
- submitting only such Customer Content as is necessary for the Permitted Purpose defined in the Agreement.
5. Confidentiality of Personnel
The Processor ensures that all persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process Customer Personal Data only on a need-to-know basis.
6. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, the Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk (Article 32 GDPR).
The measures currently implemented are described in Annex 2. The Processor may update them from time to time, provided the updates do not materially reduce the overall level of protection.
7. In-Memory Analysis; Model Training; Retention After Analysis
7.1 In-memory analysis
Analysis of submitted content takes place entirely in volatile memory (RAM). Submitted content is not written to persistent storage for the purpose of the analysis itself. Any retention of Customer Personal Data is a separate processing step that occurs only after the analysis completes, in the cases described in this Section and in Section 13.
7.2 No model training by default
By default, the Processor does not use Customer Personal Data to train, fine-tune, or evaluate machine-learning models, and does not build profiles from Customer Personal Data.
Customer Personal Data may be used to train or fine-tune models — whether general models or models specific to the Customer — only where the parties have expressly agreed so in writing, or where the Customer has enabled such use through the configuration of the Service (Section 7.5). Such an agreement or configuration forms part of the Customer's documented instructions (Section 3).
7.3 Human review of flagged content; perceptual hashes
Where an analysis indicates that submitted content is likely illegal or harmful, the Processor may retain the flagged item after the analysis for confirmation by a limited number of authorized personnel, bound by confidentiality (Section 5) and acting on a need-to-know basis.
Where a human reviewer confirms the material as harmful, the Processor may derive a perceptual hash of the item — a compact numerical fingerprint that enables re-identification of the same or visually similar material but does not permit reconstruction of the content — and store it in a hash database maintained for the Service as a whole. Hashes in that database are used solely to accelerate the identification of already-confirmed material in subsequent analyses, including analyses performed for other customers. No hash is stored on the basis of an automated verdict alone.
7.4 Deletion by default
Except where content is retained under Section 7.3, preserved under Section 13, or retained under an agreement or configuration referred to in Sections 7.2 and 7.5, submitted content is deleted promptly after the analysis completes and results are returned.
7.5 Service tiers and configuration defaults
The retention and model-training options applicable to the Customer's use of the Service are stated in the Service settings. On paid tiers, retention of submitted content beyond Section 7.3 and its use for model training are disabled by default. Where the Service is provided free of charge, retention of submitted content and its use for model improvement may be enabled by default; the applicable defaults are disclosed at sign-up, and the Customer may disable them at any time in the Service settings. The configuration selected by the Customer forms part of the Customer's documented instructions (Section 3).
7.6 Storage of retained content
Customer Personal Data retained under this Section or Section 13 is stored within the EU on dedicated storage infrastructure subject to heightened security measures: the storage systems are not directly reachable from the public internet and are accessed exclusively over an encrypted internal protocol (Annex 2).
7.7 Service telemetry
Aggregated, de-identified service telemetry that contains no Customer Personal Data (for example, request volumes, latency, error rates, and score distributions) is not subject to this DPA.
8. Sub-processors
The Customer grants the Processor general written authorization to engage Sub-processors for the processing of Customer Personal Data. The current list of Sub-processors is set out in Annex 3.
The Processor will announce any intended addition or replacement of Sub-processors at least fourteen (14) days in advance — by updating this page and, for registered customers, by email — giving the Customer the opportunity to object. If the Customer objects on reasonable data-protection grounds and the parties cannot find a solution, the Customer may terminate the affected Service and will receive a pro-rata refund of unused paid credits.
The Processor imposes on each Sub-processor, by way of contract, data-protection obligations materially equivalent to those in this DPA, and remains liable to the Customer for the performance of the Sub-processor's obligations.
9. Assistance with Data Subject Rights
Taking into account the nature of the processing, the Processor assists the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising data subjects' rights (Chapter III GDPR).
Given the processing model described in Section 7, the Processor typically holds no Customer Personal Data after an analysis completes, other than data retained under Sections 7 and 13. If a data subject contacts the Processor directly regarding Customer Personal Data, the Processor will refer the request to the Customer without undue delay and will not respond on the merits except as instructed by the Customer or required by law.
10. Personal Data Breach
The Processor notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
The notification includes, to the extent available, the information listed in Article 33(3) GDPR, and the Processor provides reasonable cooperation with the Customer's obligations under Articles 33 and 34 GDPR. Notification of, or response to, a breach is not an acknowledgment of fault or liability.
11. Data Protection Impact Assessments
Taking into account the nature of the processing and the information available to it, the Processor provides reasonable assistance to the Customer with data protection impact assessments (Article 35 GDPR) and prior consultations with supervisory authorities (Article 36 GDPR), insofar as they relate to the processing of Customer Personal Data under this DPA.
12. Audits
The Processor makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
Audits: (a) may take place at most once per twelve (12) months, unless a personal data breach has occurred or a supervisory authority requires otherwise, (b) require at least thirty (30) days' prior written notice, (c) take place during normal business hours and must not unreasonably disrupt the Processor's operations, (d) are subject to confidentiality obligations, and (e) must not give access to data of other customers. The Processor may first satisfy an audit request by providing relevant documentation, third-party attestations, or certifications, where these reasonably address the Customer's inquiry.
13. Preservation, Archiving, Disclosure, and Reporting
The Processor may preserve, disclose, or report Customer Personal Data where required by EU or member-state law to which the Processor is subject, or by a binding order of a court or competent authority — including legal obligations relating to child sexual abuse material.
In addition, where the outcome of an analysis, the legal qualification of submitted content, or the need to enable competent public authorities to act so justifies, the Processor may preserve (archive) the content concerned together with associated metadata (for example, technical attributes of the submission and the related detection result), for the purposes of compliance with legal obligations, cooperation with competent public authorities, and the establishment, exercise, or defence of legal claims. Such data is retained no longer than these purposes require and is stored as described in Section 7.6.
In these cases, the Processor informs the Customer of the preservation, disclosure, or report, unless the law prohibits such information on important grounds of public interest or informing the Customer would prejudice an official investigation or proceedings.
14. International Transfers
Customer Personal Data is processed on infrastructure located in the European Union.
The Processor will not transfer Customer Personal Data outside the EU/EEA unless the transfer is safeguarded in accordance with Chapter V GDPR (adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism) and reflected in Annex 3.
15. Deletion and Return
Submitted content is deleted after analysis as described in Section 7, except where it is retained under Section 7 or preserved under Section 13.
Upon termination of the Agreement, the Processor deletes any remaining Customer Personal Data within thirty (30) days — or, at the Customer's prior written request, returns it — and deletes existing copies, unless EU or member-state law requires further storage or the data remains subject to preservation under Section 13. Perceptual hashes derived under Section 7.3 from material confirmed as harmful may be retained after termination for the sole purpose of detecting and preventing the further dissemination of such material. Upon request, the Processor confirms deletion in writing.
16. Liability
The allocation of liability between the parties towards data subjects follows Article 82 GDPR. In all other respects, the liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, to the extent permitted by applicable law.
17. Term, Precedence, and Governing Law
This DPA takes effect together with the Agreement and remains in force for as long as the Processor processes Customer Personal Data.
In case of conflict between this DPA and the Agreement with respect to the processing of personal data, this DPA prevails. Mandatory provisions of applicable data-protection law prevail over both.
This DPA is governed by the laws of the Czech Republic.
Annex 1 — Details of Processing
Subject matter: Automated analysis of Customer Content submitted via the Service for the purpose of detecting illegal or harmful material.
Duration: The term of the Agreement. Each individual content item is analysed in volatile memory and retained only in the cases described in Sections 7 and 13.
Nature and purpose: Automated, machine-learning-based risk analysis of submitted content (initially images), performed in volatile memory and returning probabilistic detection results to support the Customer's trust & safety, content-moderation, and legal-compliance workflows. Ancillary processing comprises: human review of flagged content and derivation of perceptual hashes of human-confirmed material (Section 7.3), preservation of flagged content and associated metadata where legally justified (Section 13), and — only under an express agreement or Customer-selected configuration — retention and use of submitted content for model training (Sections 7.2 and 7.5).
Categories of data subjects: The Customer's end users; individuals depicted in or identifiable from submitted content, which may include minors.
Categories of personal data: Images or other media and associated metadata submitted via the API, including any personal data contained within them. Given the detection purpose, submitted content may include special categories of personal data (Article 9 GDPR — for example, data concerning a person's sex life) and data relating to criminal offences (Article 10 GDPR).
Retention: Submitted content is analysed in volatile memory and deleted promptly after analysis, unless it is retained for human review of flagged content (Section 7.3), preserved under Section 13, or retained under an agreement or configuration referred to in Sections 7.2 and 7.5. Detection results and audit-log entries, which do not contain the submitted media, are retained for the term of the Agreement or as configured by the Customer. Perceptual hashes of human-confirmed material are retained for as long as they serve the detection purpose described in Section 7.3.
Annex 2 — Technical and Organizational Measures
- Encryption of data in transit (TLS 1.2 or higher).
- In-memory analysis: submitted content is analysed in volatile memory (RAM) and is not written to persistent storage for the purpose of analysis.
- Automated deletion of submitted content after analysis, except in the retention cases defined in Sections 7 and 13.
- Isolated storage for retained content: dedicated storage systems without direct reachability from the public internet, accessed exclusively over an encrypted internal protocol, with encryption at rest.
- EU data residency for Customer Personal Data.
- No use of Customer Personal Data for model training on paid tiers by default; such use only under an express written agreement or a configuration selected by the Customer, subject to the free-of-charge defaults in Section 7.5.
- Access control based on least privilege and need-to-know; multi-factor authentication for administrative access.
- Network segmentation and firewalling between environments.
- Logging, monitoring, and audit trails for processing operations and administrative access.
- Vulnerability management and timely application of security updates.
- Secure software development practices.
- Documented incident-response process.
- Confidentiality commitments for all persons authorized to process data.
- Due diligence and contractual safeguards for Sub-processors.
- Periodic review and testing of the effectiveness of these measures.
Annex 3 — Sub-processors
Current Sub-processors engaged in the processing of Customer Personal Data:
| Sub-processor | Purpose of processing | Processing location | Transfer safeguard |
|---|---|---|---|
| Vercel Inc., Delaware, USA | Hosting and content delivery of the website and customer dashboard | United States | EU–US Data Privacy Framework and/or Standard Contractual Clauses |
| EU cloud infrastructure provider — to be named before general availability of the API | AI inference on Customer Content submitted via the API, transient storage during processing, and audit logs | European Union | Not applicable — no transfer outside the EU/EEA |
The identity of the EU cloud infrastructure provider is available on request at hello@visork.com and will be published in this Annex before general availability of the API.
Service providers that process only personal data for which the Processor is itself the controller — contact-form handling, correspondence, accounting, and payments — are not Sub-processors under this DPA. They are listed in the Privacy Policy.
Changes to this list are announced in accordance with Section 8.