VGS Hub logoVGS HubBack to site

Data Processing Agreement

Last updated: 13 August 2026

Vargas Digital SRL · Sat Vălișoara, Județul Cluj, Romania · CUI 41265668 · Reg. Com. J2019002466127 · EUID ROONRC.J2019002466127

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and Vargas Digital SRL ("Processor") and applies where the Processor processes personal data on the Controller's behalf through VGS Hub. It reflects Article 28 GDPR. Where the parties have signed a separate negotiated DPA, that document prevails.

1. Roles & scope

For personal data contained in Connected Accounts and collected via the Tracking module, the Controller determines the purposes and means of processing and the Processor processes such data only to provide the Service and on the Controller's documented instructions (including via the App's configuration). For the Processor's own account, billing and security data, the Processor acts as an independent controller under its Privacy Policy.

2. Processor obligations

3. Data‑subject requests & breach

The Processor will promptly notify the Controller of any request received directly from a data subject relating to the Controller's data and will not respond except on the Controller's instruction or as legally required. The Processor will notify the Controller without undue delay after becoming aware of a personal‑data breach affecting the Controller's data, with the information reasonably available to assist the Controller's own notification obligations.

4. Sub‑processors

The Controller provides general authorization for the Processor to engage sub‑processors. The Processor imposes data‑protection obligations on each sub‑processor equivalent to those in this DPA and remains liable for their performance. Current sub‑processors (Annex III):

Sub‑processorServiceProcessing locationTransfer safeguard
Hostinger International Ltd.Application hosting & databaseEuropean Union (Frankfurt, Germany)Within EEA
Stripe Payments Europe, Limited (with Stripe, Inc.)Subscription billing & payment processingEU / United StatesSCCs / EU‑US DPF
Anthropic, PBCAI‑assisted analysis of performance dataUnited StatesSCCs
Google LLCGoogle Ads / Analytics / Data Manager APIs you connectUnited States / globalSCCs / EU‑US DPF
Meta Platforms, Inc.Meta Marketing APIs you connectUnited States / globalSCCs / EU‑US DPF
TikTok / LinkedIn / MicrosoftRespective advertising APIs you connectUnited States / globalSCCs / EU‑US DPF

We will give the Controller advance notice of changes to sub‑processors (via the App or email) and an opportunity to object on reasonable data‑protection grounds.

5. International transfers

Where processing involves transfer of personal data outside the EEA, the parties rely on an adequacy decision, the European Commission's Standard Contractual Clauses (which are incorporated by reference and completed by the details in the Annexes), and/or the EU‑US Data Privacy Framework, with supplementary measures where appropriate.

6. Audits

The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and no more than once per year unless required by a supervisory authority or following a breach.

7. Term & liability

This DPA remains in effect while the Processor processes the Controller's personal data. Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by Romanian law.

8. California Consumer Privacy Act terms

This Section applies where the Controller is a "business" and the Processor is a "service provider" as those terms are defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act, and its implementing regulations (together, the "CCPA"). Terms used in this Section have the meanings given to them in the CCPA. This Section is intended to satisfy Cal. Civ. Code §1798.100(d) and 11 CCR §7051.

Nothing in this Section is an admission that either party is subject to the CCPA; it applies only to the extent the CCPA does.

Annex I - Details of processing

Subject matter & duration: provision of the VGS Hub Service for the term of the Controller's subscription.
Nature & purpose: collection, storage, organization, analysis, and transmission of advertising, analytics and conversion data to provide reporting, measurement, alerting and campaign‑management features; receipt and delivery of the Controller's lead‑form submissions to the destinations the Controller configures; and, where the Controller explicitly enables it, reading and updating the Controller's Merchant Center product listings.
Categories of data subjects: the Controller's personnel; the Controller's customers, leads and website visitors.
Categories of personal data: online identifiers; contact identifiers (email address and phone number), stored encrypted at rest and transmitted to advertising platforms only as SHA‑256 hashes; name and address data (first name, last name or full name, city, state / region, postal code and country), stored encrypted at rest; advertising click IDs; device/IP and event data; conversion and commercial values; lead‑form submissions, comprising the contact details and the full set of answers the data subject provided to the Controller's form; and account, campaign and product‑listing metadata. The parties do not intend for special‑category data to be processed.

Annex II - Technical & organizational measures

Annex III - Sub‑processors

As listed in Section 4 above, maintained current as the Service evolves.