Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of ManyVector's Terms of Service and governs the processing of personal data by ManyVector Inc. on behalf of customers.
Effective date: January 1, 2026 — Last updated: July 2026
1. Definitions
"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data. In the context of this DPA, the Customer is the Controller.
"Processor" means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller. In the context of this DPA, ManyVector Inc. is the Processor.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection law including the GDPR, CCPA, and similar regulations.
"Processing" means any operation or set of operations which is performed on Personal Data, whether or not by automated means.
"Data Subject" means any identified or identifiable natural person whose Personal Data is processed.
"Sub-processor" means any Processor engaged by ManyVector Inc. to carry out Processing activities on behalf of the Customer.
2. Data Controller / Processor Relationship
The parties acknowledge that, for the purposes of applicable data protection legislation, the Customer is the Controller and ManyVector Inc. is the Processor with respect to any Personal Data processed through the ManyVector platform in connection with the Services.
ManyVector Inc. processes Personal Data only to the extent necessary to provide the Services and only in accordance with the documented instructions of the Customer as set out in this DPA and the Terms of Service.
ManyVector Inc.'s core architecture is designed to minimize the Personal Data it holds. For most configurations, vector data (including embeddings of text that may be derived from Personal Data) is stored exclusively in the Customer's own object storage bucket (S3, GCS, R2, etc.). ManyVector Inc. does not retain copies of that data on its own infrastructure.
3. Processing Instructions
ManyVector Inc. shall process Personal Data only in accordance with the Customer's documented and lawful instructions, including those set out in this DPA and the Terms of Service. The Customer instructs ManyVector Inc. to process Personal Data for the purposes of: (a) providing the vector search and retrieval services; (b) performing the Customer's queries and upsert operations; and (c) any other processing necessary to deliver the Services as described in the Terms of Service.
If ManyVector Inc. is required by applicable law to process Personal Data for any purpose other than as instructed by the Customer, ManyVector Inc. shall inform the Customer of that legal requirement before processing, unless such notification is prohibited by law.
ManyVector Inc. shall immediately inform the Customer if, in its opinion, any instruction given by the Customer infringes applicable data protection legislation.
4. Security Measures
ManyVector Inc. shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. These measures include, without limitation:
Encryption in transit. All Personal Data transmitted between the Customer and ManyVector Inc. is encrypted using TLS 1.2 or higher.
Encryption at rest. Any Personal Data held by ManyVector Inc. (e.g., account metadata, API keys, query logs in managed deployments) is encrypted at rest using AES-256 or equivalent.
Access controls. Access to Personal Data within ManyVector Inc.'s infrastructure is restricted to employees and contractors who require it for their role. Multi-factor authentication is required for all internal system access. Least-privilege access principles are enforced.
Audit logging. ManyVector Inc. maintains audit logs of access to its production systems and reviews them periodically for anomalies.
Security assessments. ManyVector Inc. conducts periodic security assessments, including penetration testing, and remediates identified vulnerabilities in a timely manner.
5. Sub-processors
The Customer provides general written authorization for ManyVector Inc. to engage Sub-processors, subject to the requirements of this section.
ManyVector Inc. shall: (a) ensure that Sub-processors are bound by data processing terms that impose obligations at least equivalent to those imposed on ManyVector Inc. under this DPA; (b) remain liable to the Customer for the acts and omissions of its Sub-processors to the same extent as if ManyVector Inc. itself had performed those acts or omissions; and (c) maintain an up-to-date list of Sub-processors and make it available to the Customer on request.
ManyVector Inc. shall provide the Customer with reasonable notice of any intended changes to Sub-processors (additions or replacements) and allow the Customer a reasonable opportunity to object. Current Sub-processors include cloud infrastructure providers and operational tooling vendors. Contact hello@manyvector.com for the current Sub-processor list.
6. Data Subject Rights
ManyVector Inc. shall assist the Customer by appropriate technical and organizational measures, insofar as possible, with the fulfilment of the Customer's obligations to respond to requests from Data Subjects exercising their rights under applicable data protection law (including rights of access, rectification, erasure, restriction, portability, and objection).
Upon receiving a Data Subject request that relates to Personal Data processed by ManyVector Inc. on behalf of the Customer, ManyVector Inc. shall promptly notify the Customer. ManyVector Inc. shall not respond to such requests directly unless instructed to do so by the Customer or required by applicable law.
The Customer is responsible for ensuring that it has a lawful basis for processing Personal Data through the Service and for responding to Data Subject requests in accordance with applicable law.
7. Breach Notification
In the event of a Personal Data breach affecting Personal Data processed by ManyVector Inc. on behalf of the Customer, ManyVector Inc. shall notify the Customer without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.
Such notification shall include, to the extent known at the time: (a) a description of the nature of the breach; (b) the categories and approximate number of Data Subjects and Personal Data records affected; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach and to mitigate its possible adverse effects.
ManyVector Inc. shall cooperate with the Customer and provide such information as reasonably requested to assist the Customer in meeting its own obligations to notify supervisory authorities and affected Data Subjects under applicable law.
8. International Data Transfers
Where Personal Data originating from the European Economic Area (EEA), United Kingdom, or Switzerland is transferred to a country that has not been deemed to provide an adequate level of data protection, ManyVector Inc. shall ensure that such transfers are made subject to appropriate safeguards in accordance with applicable law.
Such safeguards may include Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement, or other legally recognized mechanisms. ManyVector Inc. will enter into applicable SCCs or equivalent agreements with the Customer on request.
For self-hosted deployments, vector data and operational data remain within the Customer's own infrastructure in the jurisdiction the Customer selects. ManyVector Inc. does not transfer that data.
9. Term and Termination
This DPA shall remain in effect for the duration of the Customer's use of the Services and shall automatically terminate upon expiration or termination of the Terms of Service.
Upon termination of the Services, ManyVector Inc. shall, at the Customer's election, return or delete all Personal Data in its possession that was processed on behalf of the Customer, except to the extent ManyVector Inc. is required to retain such data by applicable law.
Provisions of this DPA that by their nature should survive termination (including confidentiality, indemnification, and data return/deletion obligations) shall survive the termination of this DPA.
10. Contact
For questions about this DPA, to request an executed copy, or to discuss custom DPA terms for your organization, please contact:
ManyVector Inc.
Email: hello@manyvector.com
Website: manyvector.com