Volent
FeaturesIntegrationsPricing
  • ENEnglish
  • UAУкраїнська
  • PLPolski
  • DEDeutsch
Write to us
FeaturesIntegrationsPricing
  • ENEnglish
  • UAУкраїнська
  • PLPolski
  • DEDeutsch

Data Processing Agreement

Version 1.0 · effective 2026-10-02

Terms of ServicePrivacy PolicyData Processing AgreementCookie PolicyImprint

This Data Processing Agreement ("DPA") governs the processing of personal data by the Operator on behalf of the Customer in the course of providing the Service. It is intended to satisfy Article 28 GDPR.

Parties and roles. The Customer is the controller. The Operator, Volent, is the processor. "Volent" or "the Service" means the hosted project management service. "User" means an individual using a workspace. "Workspace" means a tenant, reachable at its own subdomain. "Customer Data" means everything a Customer or its Users put into a Workspace.

This DPA does not apply where the Operator acts as controller — account data and marketing-site data — which is governed by the Privacy Policy.

1. Subject matter, duration, nature and purpose

Subject matter. The processing of Customer Data by the Operator in order to provide the Service to the Customer.

Duration. For as long as the Customer's Workspace exists, and thereafter only as described in section 9.

Nature and purpose. Hosting, storage, structuring, retrieval, transmission, display and deletion of Customer Data as required to operate a multi-tenant project and issue tracker: boards, backlogs, sprints, work items, comments, team chat and file attachments; the sending of transactional and notification email where mail is configured; and, where enabled, repository integration and the optional AI text generation feature. The purpose is limited to providing the Service and does not include any independent purpose of the Operator.

Feedback to the Operator. A message a User sends to the Operator from inside the Service, with the account and Workspace details attached to it, is the Operator's own data and is described in the Privacy Policy. If a User includes Customer Data in such a message, the Operator uses it only to answer that message, keeps it no longer than the message itself, and otherwise treats it under this DPA.

Categories of data subjects. The Customer's Users, and any natural person whose personal data a Customer or its Users place into Customer Data — for example colleagues, contractors, customers or other individuals named in a work item, comment, chat message or attachment.

Categories of personal data. Identity and contact data of Users (email address, display name, avatar image URL, interface language, timezone, password hash); authentication records, including the browser user-agent string retained on a "remember me" record; and any personal data contained in Customer Data, whose content is determined by the Customer and not by the Operator.

No special categories of personal data under Article 9 GDPR are required by the Service. The Customer must not place special-category or criminal-offence data into Customer Data unless it has first agreed additional terms with the Operator in writing.

2. Processing on documented instructions

The Operator processes Customer Data only on the Customer's documented instructions, including as regards transfers to a third country, unless required to do so by Union or Member State law or by the law of Ukraine, in which case the Operator will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

The Customer's documented instructions consist of: this DPA; the Terms of Service; the configuration choices the Customer and its administrators make in the Service; and the Customer's and its Users' use of the Service's functions. Use of the Service is the instruction.

The Operator will inform the Customer without delay if, in the Operator's opinion, an instruction infringes the GDPR or other applicable data protection law. The Operator may suspend the execution of that instruction until it is confirmed, amended or withdrawn.

3. Confidentiality

The Operator ensures that persons authorised to process Customer Data are bound by an obligation of confidentiality, whether contractual or statutory, and that access is limited to what a person needs in order to perform their task. Where the Operator engages any assistant or contractor with access to Customer Data, that person is placed under an equivalent written confidentiality obligation before access is granted.

4. Security of processing (Article 32)

The Operator implements the technical and organisational measures set out in Annex 2, having regard to the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to data subjects.

The measures in Annex 2 are an exhaustive statement of what is implemented. No further measure should be inferred, and in particular: the Operator has obtained no certification, no SOC 2 report, no ISO 27001 certificate and no third-party penetration test report, and holds no code of conduct approved under Article 40 GDPR. Any statement to the contrary is not made by the Operator.

The Operator may update the measures over time provided the level of protection is not reduced.

5. Subprocessors

The Customer gives the Operator general written authorisation to engage subprocessors. The subprocessors authorised as at the effective date of this DPA are:

SubprocessorRoleStatus
Google (Sign-In)Federated authenticationOnly if the Operator configures a Google client; otherwise disabled
Google (Gemini API)Optional AI text generation, invoked only when a User presses the buttonOnly if an API key is configured; otherwise the endpoints return HTTP 503 and the control is hidden
SMTP providerTransactional email: verification codes, invitations, digests; delivery of feedback Users send to the OperatorOff by default; enabled by configuration
GitHub / GitLabRepository integrationPer-Workspace opt-in
Hosting providerServers and infrastructureAlways

Object storage for file attachments is operated by the Operator and is therefore not a subprocessor. If the Operator moves it to a managed provider, that provider is a subprocessor and the change procedure below applies to it.

Two providers that appear in the Service are not subprocessors. Anthropic: where a Workspace runs AI agents, it does so on the Customer's own Anthropic account and API key, under the Customer's own agreement with Anthropic. Anthropic therefore acts for the Customer and not for the Operator; the Operator sends it Customer Data only on the Customer's instruction, by the use of that function, and the Customer is responsible for its agreement with Anthropic, including where Anthropic processes data. If the Operator ever supplies the account or key itself, Anthropic becomes a subprocessor and the change procedure below applies. The payment provider that acts as Merchant of Record under the Terms of Service sells in its own name and keeps its own records of the purchase; it does not process Customer Data on the Operator's behalf.

The Operator imposes on each subprocessor, by contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each subprocessor's obligations.

Changes. The Operator will inform the Customer of any intended addition or replacement of a subprocessor at least 30 days before that subprocessor begins processing Customer Data, by email to the Customer's administrator contact or by a notice in the Service. The Customer may object on reasonable data protection grounds within those 30 days. If the objection cannot be resolved, the Customer may terminate the affected part of the Service and this DPA without penalty, and section 9 applies to the Customer Data concerned.

6. Assistance with data subject requests

Taking into account the nature of the processing, the Operator assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights under Chapter III GDPR.

The honest position on how this works:

  • There is no self-service export function. Account deletion is self-service: a User can delete their own account (Profile → Delete account). The erasure is carried out automatically one month after the User confirms the request — within the Article 12(3) deadline, not after it; during that window the account is blocked and the User can cancel the request. The erasure is also cancelled by the Service, and nothing is erased, where at that point the User still owns a Workspace other Users are working in or is its only administrator — the User is emailed the reason and may request again once it is resolved. When carried out, it erases that User's identity and anonymises their membership records while the content they created stays with the Workspace. The Operator performs access, copy, correction, restriction, portability, objection and any erasure going beyond that manually, on request sent to [email protected].
  • The Customer's administrator can already remove a User from a Workspace directly, which revokes that User's access and anonymises that User's email address on the workspace-user record. Administrators can also edit and delete work items, comments, chat messages and attachments within the Workspace through the ordinary interface.
  • Where a data subject contacts the Operator directly about Customer Data, the Operator will not respond to the substance of the request but will forward it to the Customer without undue delay, unless legally required to respond.

The Operator's manual assistance is provided free of charge for a reasonable volume of requests.

7. Personal data breach notification

The Operator notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, so that the Customer can meet its own obligations under Articles 33 and 34 GDPR.

The notification will describe, to the extent known at the time and supplemented as further information becomes available:

  • the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and to mitigate its adverse effects;
  • a contact point for further information.

The Operator will not notify a supervisory authority or affected data subjects on the Customer's behalf unless the Customer instructs it to do so in writing.

8. Data protection impact assessments and prior consultation

The Operator assists the Customer with data protection impact assessments under Article 35 GDPR and with prior consultation of a supervisory authority under Article 36 GDPR, taking into account the nature of the processing and the information available to the Operator.

That assistance is proportionate to the Operator's size and resources: it takes the form of written answers about the processing, the architecture and the measures in Annex 2, rather than the production of bespoke assessment documentation.

9. Deletion or return of Customer Data

On termination of the Service relationship, and at the Customer's choice, the Operator deletes or returns all Customer Data and deletes existing copies, unless Union or Member State law or the law of Ukraine requires further storage.

  • The Customer must state its choice — return or deletion — within 30 days of termination. If no choice is stated within that period, the Operator deletes the Customer Data.
  • Where return is chosen, the return is performed manually by the Operator on request to [email protected], because the product contains no export tool. The Operator will provide the Customer Data in a commonly used machine-readable format within 30 days of the request.
  • Deletion is carried out within 30 days of the Customer's instruction, or of the expiry of the 30-day choice period.
  • Deleting a Workspace deletes the Customer Data it contains. A deletion confirmed by the Workspace owner is the Customer's instruction under this section: use of the Service is the instruction (section 2), and an owner who acts for an organisation does so within the authority the Terms of Service require. The deletion begins 14 to 15 days after the confirmation (at the start of the next day in UTC after 14 full days) unless an administrator of the Workspace cancels it, and until then the Workspace is locked for all its Users and the administrators are told by email when the deletion is scheduled and when it is cancelled. The Operator's own copy of the Customer Data is erased within 30 days of the confirmation; within that time the Operator also requests the deletion or deactivation of the objects created on the Workspace's behalf at subprocessors and at the Customer's own providers (section 5). An object that a provider refuses or fails to delete within 7 days after the deletion begins is recorded by its identifier, without personal data, and the email that reports the completion to the Workspace's administrators names it. The Workspace's subscription, if any, is cancelled when the deletion begins. A copy of an API key that the Workspace stored with the Operator is erased; the key itself remains valid with its provider until the Customer revokes it there. Afterwards the Operator keeps only a record of the Workspace's identifier, the dates of the deletion and any such unremoved objects, without personal data. Erased data can remain in storage media until it is overwritten in the ordinary course of operation; it is no longer accessible through the Service.
  • A Customer that wants its Customer Data returned requests the return before confirming the deletion. The Operator cannot return Customer Data once the deletion has begun, so a Customer that has not received what it requested cancels the deletion first; a confirmed deletion that is not cancelled supersedes a pending return request.
  • A Workspace whose last remaining member deleted their account is erased in the same way when that deletion is carried out, without the 14 to 15 day wait. The scheduled deletions the Service performs during the relationship are those described in this section, the erasure of a User account one month after that User confirmed its deletion (section 6), the 30-day purge of trashed work items, the daily sweep of expired or revoked "remember me" records and the 14-day expiry of invitations.

10. Audit and information rights

The Operator makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, on written request to [email protected], and responds within 30 days.

The Operator allows for and contributes to audits, including inspections, conducted by the Customer or by an auditor mandated by the Customer. Such audits are subject to reasonable conditions: at least 30 days' written notice, no more than once per calendar year unless a personal data breach or a supervisory authority requires otherwise, during normal working hours, without disproportionate disruption to the Service, and subject to confidentiality. The auditor must not be a competitor of the Operator. The Customer bears its own audit costs.

In the first instance the Operator may satisfy an audit request by providing written answers and documentation, given that no certification or third-party audit report exists.

11. International transfers

The Operator does not transfer Customer Data to a third country except as described here and in the Privacy Policy.

Google, in its capacity as authentication provider and as provider of the Gemini API, is a recipient established in the United States. Where Customer Data is transferred to Google, the transfer is made on the standard legal basis available at the time of the transfer — an adequacy decision under Article 45 GDPR where one applies to the recipient, otherwise the European Commission's Standard Contractual Clauses under Article 46(2)(c) GDPR, together with the transfer safeguards Google publishes for the relevant service. Both of those subprocessors are inactive unless configured.

Where a Workspace runs AI agents on the Customer's own Anthropic account (section 5), the Customer Data sent there goes to a provider established in the United States on the Customer's instruction and under the Customer's own agreement with that provider, which governs the transfer.

The Operator holds no certification and makes no claim to one. The Customer authorises the Operator to conclude Standard Contractual Clauses with a subprocessor on the Customer's behalf where that is required to give effect to this DPA.

12. Precedence and acceptance

This DPA forms part of the agreement between the Customer and the Operator. In the event of a conflict between this DPA and the Terms of Service on a matter of personal data protection, this DPA prevails. On all other matters the Terms of Service prevail. Where this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

The Customer accepts this DPA by accepting the Terms of Service and using the Service; no signature is required and none needs to be requested. A Customer that requires a countersigned copy may request one at [email protected].

If any provision of this DPA is invalid, the remainder stays in force. This DPA is governed by the law of Ukraine, without prejudice to the mandatory application of the GDPR, and the courts of Ukraine have jurisdiction.

Version 1.0. Effective 2026-10-02.

13. Annexes

Annex 1 — Details of the processing

ItemDetail
Subject matterProcessing of Customer Data by the Operator in order to provide the Service to the Customer
DurationFor the lifetime of the Customer's Workspace, plus the deletion or return period in section 9
Nature of the processingHosting, storage, structuring, retrieval, transmission, display and deletion; sending of transactional and notification email where configured; repository integration and optional AI text generation where enabled
Purpose of the processingOperating a multi-tenant project and issue tracker for the Customer: boards, backlogs, sprints, work items, comments, team chat and file attachments. No independent purpose of the Operator
Categories of data subjectsThe Customer's Users; any natural person named or described in Customer Data by the Customer or its Users
Categories of personal dataEmail address; display name; avatar image URL; interface language; timezone; password hash; authentication records including the browser user-agent string retained on a "remember me" record; any personal data contained in work items, comments, chat messages and file attachments
Special categoriesNone required by the Service; not permitted without additional written terms
Frequency of processingContinuous, for as long as the Workspace is in use
RetentionTrashed work items purged 30 days after being trashed; expired or revoked "remember me" records swept daily; invitations expire 14 days after issue; a User account whose deletion was confirmed by its User is erased one month after the confirmation unless cancelled; a Workspace whose deletion its owner confirmed is erased starting 14 to 15 days after the confirmation, unless cancelled, and within 30 days of it; other content, including chat messages and attachments, persists until deleted by its Users, on request or with the Workspace
SubprocessorsAs listed in section 5

Annex 2 — Technical and organisational measures

These are the measures actually implemented. Nothing beyond this list is implemented or claimed.

AreaMeasure
Encryption at restEmail addresses are encrypted at field level, with keys held outside the database. A keyed deterministic index stored alongside them permits lookup by email
Credential storagePasswords are stored only as hashes and cannot be read by the Operator
Encryption in transitTLS for traffic to and from the Service
Session securitySession cookies are HttpOnly, Secure and SameSite=Lax; a sliding 8-hour idle timeout applies; the session identifier is rotated periodically during a session
Persistent sign-in"Remember me" is a rotating credential series, burned on sign-out; expired or revoked records are swept daily
Request integrityCSRF protection on state-changing requests
Tenant isolationEnforced in the authorisation layer: a Workspace resolves from its subdomain and every access is authorised against that Workspace
Integration securityOutbound webhooks are filtered against server-side request forgery; inbound webhooks are signature-verified
Abuse resistanceRate limiting on authentication endpoints
Access minimisationAccess to Customer Data is limited to what is needed to operate the Service and to persons under a confidentiality obligation
DeletionTrashed work items purged after 30 days; a User account erased one month after its User confirmed the deletion, unless cancelled; a Workspace is erased, starting 14 to 15 days and finishing within 30 days after its owner confirmed the deletion unless cancelled, together with the objects created on its behalf at providers (an object a provider refuses to delete is recorded by its identifier, without personal data); other deletion performed by the Operator on request
CertificationNone. No SOC 2, no ISO 27001, no third-party penetration test report, no approved code of conduct

Related documents: the Terms of Service, the Privacy Policy, the Cookie Policy and the Imprint.

Volent

A task tracker built around your process.

Product

FeaturesIntegrationsPricing

Legal

Terms of ServicePrivacy PolicyData Processing AgreementCookie PolicyImprint
© 2026 Volent