VELA / dpa
All legal

Data Processing Addendum

Effective 23 May 2026 · Version 2.0 · UK GDPR & EU GDPR

This DPA forms part of the Terms between Vela ("Processor") and the Business Customer ("Controller") and governs personal data the Processor processes on the Controller's behalf when routing traffic through the Vela B2B residential proxy.

1.Subject matter, nature & purpose

Transit-only processing — establishing a SOCKS5 / HTTP CONNECT session from the Controller's client through a residential exit node, plus per-byte metering, billing and security operations.

2.Roles & obligations

The Controller is data controller for traffic it sends; Vela processes it solely on documented instructions. Personnel are bound by confidentiality; technical and organisational measures are documented in the Security page.

3.Sub-processors

Sub-processorPurposeLocation
Ultimate VPSPrivacy-focused server hosting and control-plane infrastructureNon-EU hosting region (jurisdictional separation; GDPR/DPA commitments retained)
Stripe Payments EuropePayment processingIE / global
CloudflareDNS, edge TLS (marketing only)Global
Residential exit-node operatorsLast-mile egress under consentUK + EU

4.Personal data breach

The Processor will notify the Controller without undue delay and within 72 hours of becoming aware of a breach affecting Controller Personal Data.

© 2026 vela.watch
Home · Terms · Privacy · AUP · DPA · Security