Skip to main content
Velqa
← Back to home

Data Processing Agreement (DPA)

Last updated: July 3, 2026 — compliant with GDPR Article 28

1. Parties

This Data Processing Agreement (“DPA”) supplements Velqa's Terms of Service. Quantyl Core LLC, Velqa's publisher, acts as processor within the meaning of the GDPR. The customer, when transmitting personal data of its own end users via the API, acts as data controller.

2. Purpose and duration

This DPA applies for the entire duration of the customer's use of the API and ends upon account closure, subject to the legal retention periods described in the Privacy Policy.

3. Nature and purpose of processing

Velqa processes data transmitted by the customer solely to route the request to the selected language model, return the generated response, handle usage billing, and detect abuse. The content of requests and responses (prompts/completions) is neither used to train a model nor resold, and is not retained beyond processing the request — with two exceptions, required for the features concerned: Sandbox agent conversations are kept for 30 days, and media generated from the Playground for 7 to 90 days depending on the plan. Both are deleted automatically when that period ends.

4. Data categories and data subjects

Depending on how the customer uses the API, the data processed may include: the content of requests and responses transmitted via the API key, technical metadata (timestamp, model called, token volume), and any other data the customer chooses to include in its calls. The data subjects are the customer's end users.

5. Processor obligations

  • process data only on the customer's documented instructions;
  • ensure the confidentiality of persons authorized to access the data;
  • implement the security measures of GDPR Article 32;
  • obtain the customer's prior consent before engaging any new sub-processor;
  • assist the customer in exercising data subjects' rights;
  • cooperate with any reasonable audit on 30 days' notice;
  • notify any data breach without undue delay;
  • delete or return the data at the end of the contract, unless legally required otherwise.

6. Authorized sub-processors

The following sub-processors are authorized:

  • OVHcloud (hosting, EU — France);
  • Stripe (payment processing only);
  • DeepInfra and Novita (the language model inference providers actually routed to today, passthrough processing of requests/responses, no training or retention beyond request processing);
  • Resend (transactional email delivery);
  • Sentry (application error reports);
  • Google (Google Analytics 4, loaded only after consent, and reCAPTCHA);
  • Cloudflare R2 (storage of media generated from the Playground).

7. Security measures

Encryption of data at rest (AES-256) and in transit (TLS 1.3), isolation of virtual API keys, role-based access control, immediate revocation of compromised keys from the dashboard, and technical audit logs.

8. International transfers

Primary hosting is located in the European Union (OVHcloud, France). Some inference providers are located outside the EU; the corresponding transfers rely on the European Commission's standard contractual clauses (EU 2021/914) or an equivalent mechanism.

9. Contact

For any question about this DPA, or to sign a countersigned version, contact [email protected].

10. Page Agent and retention

For Page Agent, selected DOM content and prompts are sent to authorized inference subprocessors listed in the current provider register. Session metadata is deleted no later than 90 days, aggregates after 24 months, and the encrypted technical idempotency cache after 15 minutes. The customer must authenticate and authorize the user, check Origin/CSRF, and never expose an sk_pa_ key.