Legal · United States
Data Processing Addendum
“Your AI Employee” · Article 28 GDPR. Effective date: September 27, 2026 · Last updated: September 27, 2026
1. Parties, scope and acceptance
This Data Processing Addendum (“DPA”) is between you, the customer named in the order (the “controller”), and Fabian Mahnke (doing business as “Vinci AI”), c/o IP-Management #10868, Ludwig-Erhard-Str. 18, 20459 Hamburg, Germany, [email protected] (the “processor”, “we”).
It applies to all personal data on your AI Employee’s server that we process on your behalf under the Terms of Service (the “Terms”, Section 7.2). For our website, your order and account, invoicing and support we are the controller ourselves; that processing is described in our Privacy Policy, not here.
You accept this DPA at checkout together with the Terms. It forms part of the Terms and lasts as long as the Terms plus the deletion period in Section 5. Defined terms have the meaning given in the EU General Data Protection Regulation (GDPR).
2. Standard contractual clauses
The standard contractual clauses between controllers and processors adopted by the European Commission in Implementing Decision (EU) 2021/915 of 4 June 2021 (the “SCCs”, eur-lex.europa.eu/eli/dec_impl/2021/915/oj) are incorporated into this DPA by reference and apply between you and us, with the following selections:
- Clause 5 (docking clause): not used.
- Clause 7.7 (use of sub-processors): Option 2, general written authorisation. You authorise the sub-processors listed in Annex IV. We inform you in writing at least 30 days before adding or replacing a sub-processor; you may object within that period, and if we cannot resolve the objection you may cancel the subscription under the Terms.
- Clause 7.3 and 10 (end of processing): at the end of the services we return your data (final export) and then delete it, as set out in Section 5 and in the Terms, Section 7.4. If you tell us in writing that you do not want the export, we delete without returning.
- Annexes: Annex I (parties), Annex II (description of the processing), Annex III (technical and organisational measures) and Annex IV (sub-processors) of the SCCs are the Annexes I–IV of this DPA below.
In case of conflict, the SCCs prevail over this DPA and the Terms (SCC Clause 4). Where this DPA repeats obligations of the SCCs in plainer words, the SCC text governs.
3. Our obligations as processor
- Instructions only. We process your server data only on your documented instructions: the standing instructions in the Terms (set up, update, monitor, support, export and delete your server; fetch and publish a web page when you instruct it; relay tool requests your AI Employee makes) and any further instructions you give us in writing, by email or Discord. If we believe an instruction infringes the GDPR or other applicable data-protection law, we tell you before acting. We process the data for no other purpose — never for our own purposes, never to train AI models, never to sell or share it.
- Confidentiality. Only persons bound by a duty of confidentiality process your data. Administrative access to your server is limited to our own business; we do not outsource administration. Our tax and legal advisers are bound by professional confidentiality.
- Security. We implement and maintain the technical and organisational measures in Annex III (Art. 32 GDPR) and review them when the Service changes.
- Sub-processors. We engage only the sub-processors in Annex IV, under written contracts that impose data-protection obligations equivalent to this DPA, and we remain responsible to you for their performance. Changes: Section 2, Clause 7.7.
- Data-subject requests. If a person whose data is on your server contacts us, we refer the request to you without undue delay and do not answer it ourselves unless you instruct us to. Taking into account the nature of the processing, we help you respond, for example by locating, exporting, correcting or deleting data on your server.
- Assistance. We help you meet your obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the information available to us.
- Personal data breaches. If we become aware of a breach affecting your server data, we notify you without undue delay and give you the information we have: what happened, which data and roughly how many people are affected, the likely consequences, and what we have done or propose to do. We document the breach and cooperate with you on any notification you have to make.
- Deletion and return. Section 5.
- Information and audits. On request we provide the information needed to demonstrate compliance with Art. 28 GDPR and this DPA, and we allow and contribute to audits, including inspections, conducted by you or an auditor you mandate, at reasonable intervals and with reasonable notice. Because your server is rented from Hetzner, physical inspection of the data centre is subject to Hetzner’s own rules; we provide Hetzner’s certifications and audit reports where available instead.
- Location. Your server data is stored in the European Union (Germany unless agreed otherwise). We do not transfer your server data outside the EU except through the sub-processors in Annex IV, each under an appropriate safeguard (Chapter V GDPR). Anthropic and Discord are not our sub-processors: what your AI Employee exchanges with Claude, and what you exchange with it through Discord, is processed under your own agreements with those providers.
4. Your obligations as controller
You are responsible for the lawfulness of the processing, for the instructions you give, for informing the people whose data you process, and for ensuring that your data has a lawful basis to be processed by us. You will not instruct your AI Employee to store or process data that the Terms exclude (Section 8 of the Terms: protected health information under HIPAA, payment card data, government or export-controlled data, data of children under 13).
5. Duration, deletion and return
- Export at any time: on request, a complete export of your server data as a compressed archive with a checksum, within five business days.
- At the end of the subscription: within 14 days we make a final export, send it to you, delete the server at Hetzner and send you proof of deletion (Hetzner’s confirmation that no server with your identifier remains). We keep our copy of the final export for 30 days so you can retrieve it, then delete it. The Discord bot is deleted and the tool-account token is revoked at the same time.
- Metadata of tool requests (time, your server’s short name, service, endpoint, status, duration, cost — no request content) is kept for 12 months.
- Support correspondence about your server is kept for 3 years after the last message.
- We keep no backups or snapshots of your server; after deletion, nothing remains except the final export copy during its 30-day retrieval period and the records above.
6. Liability and governing law
Liability under this DPA follows the Terms, Section 13, to the extent the law permits. This DPA is governed by the law that governs the Terms (Section 17 of the Terms). Nothing in this Section limits the rights of data subjects or the powers of supervisory authorities under the GDPR.
Annex I — List of parties
| Role | Who |
|---|---|
| Controller | The customer identified in the order: the name, company name and email address given at checkout. Contact person: the person named in the order. |
| Processor | Fabian Mahnke (doing business as “Vinci AI”), c/o IP-Management #10868, Ludwig-Erhard-Str. 18, 20459 Hamburg, Germany. Contact: Fabian Mahnke, [email protected]. |
Annex II — Description of the processing
| Item | Description |
|---|---|
| Categories of data subjects | You and your staff; your customers, prospects, suppliers and other business contacts whose data you let your AI Employee handle; visitors of a web page we publish for you (server logs kept by the hosting sub-processor). |
| Categories of personal data | Identity and contact data (names, email addresses, phone numbers, company names, addresses); business correspondence and notes; content you or your AI Employee create (texts, documents, web pages, plans); the AI Employee’s memory database, task list, project files, working rules, scheduled jobs and logs; local transcripts of its sessions (kept by Claude Code for 30 days by default); your Discord username and ID; search terms and prompts submitted to the tool account. |
| Sensitive data | Not intended. Special categories of data (Art. 9 GDPR) and the data excluded by Section 8 of the Terms (HIPAA, payment card, government/export-controlled, children under 13) must not be processed on the server. If you nevertheless place such data there, the measures in Annex III apply; no additional measures are agreed. |
| Nature of the processing | Hosting and storage on a dedicated virtual server; installation, configuration, updating, monitoring and restarting of the software on it; support at your request; export as an archive; deletion; fetching, checking and publishing a web page on your instruction; relaying requests your AI Employee makes to the tool services and recording their metadata. |
| Purpose | Providing and maintaining the “Your AI Employee” service under the Terms. |
| Duration | For the term of the subscription; deletion within 14 days after it ends; our export copy 30 days; tool-request metadata 12 months; support correspondence 3 years after the last message (Section 5). |
| Frequency | Continuous. |
| Processing by sub-processors | Annex IV: subject matter, nature and duration per sub-processor. |
Annex III — Technical and organisational measures
Measures in place for your server and for our operations around it. They describe what is actually configured; nothing here is aspirational.
- Dedicated server. Each customer has a virtual server of their own at Hetzner, in an EU data centre (Germany by default). No customer shares a server, a folder or a database with another customer.
- Network firewall. A Hetzner Cloud firewall in front of the server: inbound SSH (port 22) only from our fixed network address; inbound HTTP/HTTPS (80/443) for your setup page and the web server (TLS certificates from Let’s Encrypt); outbound traffic limited to HTTPS, HTTP, DNS, NTP and the port of our tool relay.
- Administrative access. SSH with keys only, no passwords. The setup key is kept in our access-restricted secrets store. Administrative access is used only for setup, updates, monitoring, support, export and deletion, and is not outsourced.
- Least privilege on the server. Your AI Employee runs under its own unprivileged service user. Its credential files are readable only by that user (mode 600); its secrets directory is restricted to that user (mode 700). The setup page’s state is readable only by its own user; the one-time setup link is stored on the server only as a SHA-256 hash, is valid only until setup is completed and at most 48 hours after it is sent, and a daily check shuts the setup page down once 24 hours have passed after completion or expiry.
- Sign-in handling. The code you paste during Claude sign-in is handed to Claude Code on your server and is never written to a log or file; the setup web server runs without an access log. The Claude access token stays in the service user’s home directory; a daily check reads only its expiry date. We do not copy, move or use the token.
- Block list. The AI Employee’s configuration contains a deny list of commands and actions it must never run.
- No outbound keys on your server. Your server holds no credentials for our hosting, email or publishing accounts. A web page is published only by our side fetching it from your server after your instruction (pull, never push); the page is checked before it goes live.
- Tool relay. Requests to DataForSEO and the Gemini API pass through our relay with a per-customer token and a monthly usage cap. The relay records metadata only (time, your server’s short name, service, endpoint, status, duration, cost), never the content of a request. The token can be revoked at any time and is revoked when your server is deleted.
- Discord. The bot answers only in the server or channel you set up and only to your Discord ID (allow list). The bot token is stored on your server with restricted permissions and in our access-restricted secrets store; we do not read your Discord conversations; the bot is deleted when the subscription ends.
- Encryption in transit. TLS for web and email traffic, SSH for administration. Requests to the tool services go over HTTPS.
- Availability and monitoring. The service is supervised by the operating system’s service manager and restarted automatically if it stops; a daily check on your server reports whether the Claude sign-in is still valid; security updates are applied by us. We keep no backups or snapshots of your server — you can request an export at any time (Section 5).
- Export and deletion with proof. Before a server is deleted, its data is exported as a compressed archive with a SHA-256 checksum and the archive is verified; only then is the server deleted. Deletion is verified against Hetzner’s API afterwards and the result is recorded as proof, which you receive. The export never contains the Claude sign-in token or the Discord bot token.
- Our own systems. Setup links, bot tokens and relay tokens are kept in a secrets store with restricted file permissions on our operations server; order records live at Stripe; our operations server and mailbox are hosted in Germany (Frankfurt am Main).
- Incident handling. Breaches affecting your data are notified to you without undue delay (Section 3.7), documented, and followed up with you.
- Confidentiality of persons. Only persons bound by a duty of confidentiality have access; administration is not outsourced.
Annex IV — Sub-processors
| Sub-processor | Purpose and data | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting of your dedicated server: all server data. Duration: term of the subscription plus deletion period. | Germany (Nuremberg or Falkenstein); Finland only if agreed with you | Data processing agreement with Hetzner |
| Hostinger International Ltd., Cyprus | Our operations server and mailbox: setup links, bot and relay tokens, tool-request metadata, your final export copy (30 days), support correspondence. | Germany (Frankfurt am Main) | Data processing agreement with Hostinger |
| Stripe Payments Europe, Limited, Ireland (with Stripe, Inc. as affiliate) | Order and payment records that identify you as the controller (name, email, company). No server data. | EU and US | Stripe DPA; EU-US Data Privacy Framework; Standard Contractual Clauses |
| Brevo (Sendinblue GmbH), Köpenicker Str. 126, 10179 Berlin, Germany | Service emails to you (setup, reminders, notices): your name and email address. No server data. | EU | DPA in Brevo’s terms |
| Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA | Only if you ask us to publish a web page: hosting of that page and its visitor logs. | US | DPA; EU-US Data Privacy Framework |
| DataForSEO | Only when your AI Employee uses the tool account: the search terms it submits. | US / EU | DataForSEO’s terms |
| Google LLC (Gemini API, paid tier) | Only when your AI Employee uses the tool account: the prompts it submits. Google states that paid-tier prompts and responses are not used to improve its products. | US / EU | Google’s data processing terms for the paid Gemini API |
Not sub-processors: Anthropic PBC (Claude, under your own subscription) and Discord Inc. (under your own Discord account). Your AI Employee sends prompts to Anthropic and receives your messages through Discord under your own agreements with those providers; we are not a party to that processing.
← Back to Your AI Employee