Data Processing Agreement (DPA)
Version: 1.0
Effective date: 16 July 2026
Last updated: 16 July 2026
Preamble
This Data Processing Agreement (hereinafter referred to as the "DPA") is concluded in accordance with Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR") and with Act No. 18/2018 Coll. on Personal Data Protection.
Contracting parties:
CONTROLLER:
Client — the entity registered in the VORA Lead Engine service (hereinafter referred to as the "Client").
PROCESSOR:
VORA s. r. o.
Company ID: 47 352 302
Tax ID: 2023866273, VAT ID: SK2023866273
Registered office: Čižmárska 540/9, 940 02 Nové Zámky, Slovak Republic
Registered in the Commercial Register of the District Court in Nitra, Section: Sro, Insert No. 34858/N
Represented by: Adam Halász, managing director
Contact: info@vora.sk
(hereinafter referred to as the "Processor" or "VORA")
This DPA takes effect upon Client registration in the VORA Lead Engine Service and forms an integral part of the Terms of Service (ToS) available at https://lead-engine.vora.sk/tos.
1. Definitions
- Service — the VORA Lead Engine software platform available at https://lead-engine.vora.sk.
- Personal Data — any information relating to an identified or identifiable natural person as defined in GDPR Art. 4(1).
- Processing — any operation performed on Personal Data as defined in GDPR Art. 4(2).
- Data Subjects — natural persons whose Personal Data is processed in the Service.
- Sub-processor — additional processor engaged by VORA to carry out Processing on behalf of the Client.
- Security Incident — a personal data breach as defined in GDPR Art. 4(12).
2. Subject matter and duration of Processing
2.1. Subject matter: VORA processes Personal Data on behalf of the Client exclusively for the purpose of providing the VORA Lead Engine Service pursuant to the Terms of Service.
2.2. Duration: The DPA is concluded for the duration of the Service Agreement between the Client and VORA. It automatically terminates upon termination of the Client's Subscription.
2.3. Nature of Processing: Automated processing through the software platform — collection, storage, categorization, transmission, display, deletion.
3. Scope of Processing
3.1. Categories of Personal Data
VORA processes the following categories of Personal Data on behalf of the Client:
Data about contacts (leads) generated by Radar or imported by the Client:
- Name and surname of the contact person (if available)
- Email address
- Phone number (if available)
- Company name, company ID, company address
- Position in the company (if available)
- Publicly available data from LinkedIn, company websites
Communication data:
- Content of sent cold emails (AI-generated or manual)
- Content of received replies (via IMAP or Gmail/Outlook API)
- Email metadata (send time, open time, intent classification)
Data about Client users:
- Name, email, phone number of Client team members
- Login credentials (hashed passwords, 2FA tokens)
- Activity in the Service (audit log)
3.2. Categories of Data Subjects
- Representatives of companies included in leads (contact persons)
- Client team members registered in the Account
- External senders of communication received via Inbox
3.3. Purposes of Processing
- Automatic company discovery (Radar) based on parameters defined by the Client
- Generation of personalized cold emails (AI)
- Sending and receiving emails on behalf of the Client
- Intent classification of received replies (AI)
- Storage of communication history in CRM features (VORA Board, Inbox)
- Optional integration with Pipedrive based on Client's instruction
4. Processor's obligations (VORA)
VORA undertakes to:
4.1. Process Personal Data exclusively on documented instructions from the Client — meaning based on the configuration of the Service which the Client sets in the Account (regions, business types, tone of communication, etc.). Any processing outside this framework is prohibited, except where required by EU or Member State law.
4.2. Ensure that persons authorized to process Personal Data are bound by a confidentiality obligation.
4.3. Implement all appropriate technical and organizational measures pursuant to GDPR Art. 32 — details in Article 6 of this DPA.
4.4. Not engage another processor without prior general written authorization from the Client. The current list of authorized sub-processors is in Article 5 of this DPA and in the Privacy Policy (https://lead-engine.vora.sk/privacy).
4.5. Assist the Client in ensuring compliance with obligations pursuant to GDPR Art. 32 to 36 (security, breach notification, impact assessments, consultation with supervisory authority).
4.6. Assist the Client in responding to Data Subject requests pursuant to GDPR Art. 15 to 22 — particularly by providing technical tools for export, deletion or correction of data.
4.7. Upon termination of the Service, at the Client's choice, either return all Personal Data to the Client or delete it, and remove existing copies, unless EU or Member State law requires retention. Details in Article 12 of this DPA.
4.8. Provide the Client with all information necessary to demonstrate compliance with obligations under GDPR Art. 28 and enable audits — details in Article 10.
4.9. Inform the Client without undue delay if it considers that the Client's instruction violates GDPR or other data protection laws.
5. Sub-processors
5.1. The Client hereby grants VORA general written authorization to engage the following sub-processors:
Sub-processors in the EU:
- Supabase, Inc. (Ireland) — database hosting, authentication, edge functions
- Cloudflare, Inc. (global, EU priority nodes) — Workers hosting, DNS, CDN
- Stripe Payments Europe, Ltd. (Ireland) — payment processing
- Google Ireland Ltd. (EU multi-region) — Google Places API, Gmail API OAuth
- Microsoft Corporation (EU multi-region) — Outlook Graph API OAuth
- WebSupport, s. r. o. (Bratislava, SR) — email hosting for the vora.sk domain
Sub-processors outside the EU (United States of America):
- Anthropic, PBC (USA) — Claude AI for email generation and intent classification
- Email Hunter, LLC (Hunter.io) (USA) — email address verification
Optional sub-processors (only upon Client opt-in):
- Pipedrive OÜ (Estonia / servers possibly in the USA) — CRM synchronization
5.2. Changes to sub-processors. VORA is entitled to add or change sub-processors other than those listed in Section 5.1. VORA will inform the Client of planned changes by email at least 30 days in advance. The Client has the right to object to a change within 15 days of the notification; in such case, the Client has the right to terminate the agreement without penalty effective as of the date of the change.
5.3. VORA undertakes to conclude agreements with all sub-processors providing the same level of protection as this DPA, particularly the technical and organizational measures pursuant to GDPR Art. 32.
6. Security measures
VORA implements the following technical and organizational measures pursuant to GDPR Art. 32:
6.1. Technical measures
- Encryption of transmission — TLS 1.2 and higher for all communication
- Encryption at rest — Supabase databases are encrypted (AES-256)
- Row-Level access control — Row-Level Security (RLS) in Supabase prevents cross-access between Clients
- Two-factor authentication (2FA) — available and recommended for Owner and Admin users
- Audit log — tracking access and admin actions (90-day retention)
- Automated backups — daily, 30-day retention
- Attack protection — Cloudflare WAF, rate limiting, bot protection
6.2. Organizational measures
- Confidentiality obligation — all persons with access to Personal Data are bound by NDA
- Principle of least privilege — access only for the needs of a specific role
- Security policy — internal rules for access, password, device management
- Regular reviews — quarterly audit of access and incidents
6.3. Testing and evaluation
VORA regularly (at least once a year) evaluates the effectiveness of the measures implemented and, if necessary, adapts them to the current level of technology and threats.
7. Security incidents
7.1. In the event of a Security Incident (i.e. a Personal Data breach), VORA undertakes to:
- Notify the Client without undue delay, no later than 48 hours from becoming aware of the incident
- Provide the Client with all information necessary to fulfil its notification obligation to the supervisory authority pursuant to GDPR Art. 33 (nature of the breach, categories of Data Subjects, number, likely consequences, mitigation measures)
- Cooperate in investigations and remedial actions
7.2. The Client is responsible for fulfilling its 72-hour notification obligation to the Slovak Personal Data Protection Office pursuant to GDPR Art. 33.
7.3. Contact for incidents: info@vora.sk (response within 24 h during business days).
8. Data Subject rights — assistance
8.1. Data Subjects exercise their rights under GDPR Art. 15 to 22 (access, rectification, erasure, restriction, portability, objection, automated decision-making) directly against the Client as Controller.
8.2. If VORA receives a Data Subject request, it forwards the request to the Client without undue delay and does not handle it independently unless authorized by the Client.
8.3. VORA provides the Client with technical tools to fulfil Data Subject rights:
- Data export — CSV export of leads, emails, activities (in Settings)
- Data deletion — function for deleting individual leads and GDPR delete request for complete removal
- Suppression list — technical unsubscribe for contacts from cold email campaigns
9. International data transfers
9.1. As stated in Article 5, some sub-processors (Anthropic, Hunter.io) are based in the USA — outside the European Economic Area.
9.2. Transfers take place on the basis of:
- Standard Contractual Clauses (SCC) approved by Commission Decision (EU) 2021/914
- Supplementary technical measures (encryption in transit TLS 1.2+, minimization of transferred data)
9.3. The Client has the right to request a copy of the SCCs concluded with VORA.
10. Right to audit
10.1. The Client has the right (at its own expense) to verify compliance by VORA with its obligations under this DPA:
- Through a questionnaire once a year — VORA responds within 30 days
- On-site (at VORA's premises) upon prior written notice at least 30 days in advance and at most once a year, unless there is a reasonable suspicion of a breach
10.2. The Client bears the cost of the audit, except where the audit reveals a significant breach by VORA — in which case VORA bears the costs.
10.3. VORA may present the Client with existing certification reports (e.g. sub-processor SOC 2, ISO 27001) instead of a separate audit.
11. Liability
11.1. Each party is liable for its breach of GDPR and this DPA. If both parties are liable for the same breach, liability is divided proportionally to their share of the damage.
11.2. VORA's liability arising from this DPA is limited in accordance with Article 11 of the Terms of Service — up to a maximum of the Subscription paid by the Client for the last 12 months.
11.3. VORA is entitled to claim compensation from the Client for damages caused by the Client's processing of Personal Data in a manner that violates GDPR (e.g. without a legal basis).
12. Termination and fate of data
12.1. This DPA automatically terminates upon termination of the Client's Subscription.
12.2. After termination, the Client has a 30-day grace period for exporting Personal Data via functions in Settings (CSV export).
12.3. After 30 days, VORA permanently deletes all of the Client's Personal Data from production systems. Backups will be deleted within an additional 60 days (90 days total).
12.4. Data necessary for fulfilling legal obligations (billing data pursuant to Act 431/2002 Coll. on accounting) will be retained for 10 years separately from production data.
12.5. Upon request, VORA will issue the Client a confirmation of deletion.
13. Governing law and disputes
13.1. This DPA is governed by the law of the Slovak Republic.
13.2. Disputes arising from this DPA will be resolved by the substantively and territorially competent court of the Slovak Republic.
13.3. If any provision of this DPA is invalid or unenforceable, the remaining provisions remain in force.
14. Final provisions
14.1. This DPA prevails over conflicting provisions of the ToS in matters of Personal Data processing.
14.2. Changes to this DPA are valid only in written form. VORA is entitled to unilaterally change the DPA with regard to changes in the legal framework or in the operation of the Service — VORA will inform the Client of significant changes at least 30 days in advance.
14.3. Contact for all questions regarding this DPA: info@vora.sk.
On behalf of the Processor (VORA s. r. o.):
Adam Halász
managing director
Nové Zámky, 16 July 2026
On behalf of the Controller (Client):
This DPA is accepted by the Client upon registration in the VORA Lead Engine Service or by separate signature of a PDF version of this DPA upon Client request by sending an email to info@vora.sk.
This DPA is a valid contract even without a separate handwritten signature — by accepting the ToS and starting to use the Service, the Client also accepts this DPA.
