Legal
Data Protection Addendum
This addendum sets out how data protection responsibilities are allocated between you and Vatlas, and gives your compliance team what it needs on record. It forms part of the Terms of Service and Sale and applies automatically, with nothing to sign.
Last updated 27 August 2026.
The short version. For the standard lookup service, Vatlas determines the purposes and the essential means — which sources to use, how to resolve a number, what to store and for how long — and therefore acts as a controller rather than as your processor. Where that is not the case, and we process data on your instructions, the Article 28 terms in section 5 apply to that processing. Section 1 explains how the line is drawn.
1. How the roles are allocated
A processor processes personal data on the documented instructions of a controller, without determining the purposes or the essential means itself. Whether that describes us depends on the processing, and roles follow what is actually done rather than the label a contract puts on it.
For the standard service, we are a controller. You send a VAT number; we decide which national register or which API answers it, whether to fall back to VIES, what to keep in our own database, how long to keep it, and when to refresh it. Those are decisions about the purposes and the essential means, and making them is what puts us in that role. You are a controller too, separately from us, for what you do with the results.
Where we act on your instructions, we are a processor. If we agree to process personal data for you without determining the purposes ourselves, that processing is governed by the Article 28 terms in section 5, which apply to it as of right. We do not ask you to accept one blanket qualification for everything, because one would not be accurate.
2. What we are the controller of
- the database of company records we build from official public registers, and its refresh cycle;
- the resolution of a VAT number against those registers, the national APIs and VIES;
- the call logs that enforce your quota and produce your usage history;
- your account, its credentials, and the billing data attached to it.
Each of these is described, with its purpose, legal basis and retention period, in the Privacy Policy — sections 3 and 7 for your account, and section 11 for the company records, which is also where the Article 14 information for the people concerned lives.
3. What this means for your own compliance
How you document us in your own record of processing is your call, and depends on the qualification that applies to what you actually do. Where you use the standard service, we are generally a separate controller receiving the VAT numbers you send us rather than a processor acting on your behalf, and your record would normally reflect that. Where the Article 28 terms in section 5 apply to a given processing, that processing would be documented accordingly. We are happy to confirm in writing which analysis we consider applicable to your use.
What remains yours in any case: your own legal basis for looking a company up, your own information notice to the people concerned where one is required, and your own retention decision on the records you store. We cannot take those on, and this addendum does not purport to.
4. What you need for your records
Who we are. JULIEN MAULNY EURL, 9 Rue des Colonnes, 75002 Paris, France — julien.maulny@tuta.io. No data protection officer is designated; see section 1 of the Privacy Policy.
What we receive from you. The VAT numbers you submit, and the account and billing data of the people in your organisation who hold credentials.
Who else is involved. OVH SAS hosts our servers and database in France. It is our processor: for the standard service, where we are the controller, OVH is not a subprocessor of yours, and it only becomes one — under section 5 — for a processing in which we act as your processor. Stripe handles payment for the Basic plan; its role varies with the processing, as set out in section 4 of the Privacy Policy. We use no analytics provider and no advertising network, and send transactional email from our own mail server.
Transfers. Our infrastructure is in France. Stripe may process data outside the EEA under the mechanisms described in section 6 of the Privacy Policy. We make no other transfer outside the EEA.
Security. Traffic is encrypted in transit; credentials are never stored in clear
and are authenticated against a one-way hash; a revoked key stops working within a minute;
session cookies are HttpOnly, host-only and SameSite=Lax, backed by an
origin check; card data never reaches our infrastructure; access to production data is limited to
what operating the service requires; and the published retention windows are enforced
automatically rather than by hand. These measures are reviewed as the service evolves, taking
into account the state of the art, the cost of implementation and the risks involved, as Article
32 requires. A fuller description is available on request under NDA.
Breach notification. What we owe depends on our role for the processing concerned. Where we act as your processor, Article 33(2) requires us to notify you without undue delay — that is our obligation, and the 72-hour deadline is not ours: it runs against you, as controller, for notifying your own supervisory authority. Where we act as controller, the Article 33 notification to our supervisory authority is ours to make. In either case, if a breach affects data you have sent us we will inform you without undue delay once we become aware of it, with the information then available and completed as the investigation progresses.
Deletion. You can delete your account at any time from the console. What that removes and what is retained, and for how long, is set out in section 7 of the Privacy Policy. You may ask for a copy of your account and usage data in a structured, machine-readable format before deleting.
5. Terms applying where we act as your processor
Where we process personal data on your documented instructions without determining the purposes ourselves — which the standard service described in section 1 does not involve — the following terms apply to that processing as of right, and constitute the agreement required by Article 28(3) of the GDPR. They are set out here so that no gap arises if that situation occurs.
For any such processing we undertake to:
- process the data only on your documented instructions, including as regards transfers to a third country, unless required otherwise by EU or member-state law, in which case we inform you before processing unless that law prohibits it;
- ensure that everyone authorised to process the data is bound by an appropriate duty of confidentiality;
- implement the technical and organisational measures required by Article 32;
- engage another processor only with your general written authorisation, informing you at least 30 days before adding or replacing one so that you can object on reasonable data protection grounds, and remaining fully liable to you for its performance;
- assist you, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise data subject rights, and refer any data subject who contacted us directly back to you rather than answering on the substance;
- assist you in complying with Articles 32 to 36, taking into account the nature of the processing and the information available to us, and notify you of any personal data breach without undue delay after becoming aware of it, so that you can meet the deadline Article 33 places on you as controller;
- at your choice, delete or return the data at the end of the service, subject to any retention the law imposes on us;
- make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to an audit — once a year on 30 days' notice at your expense in the ordinary course, and without those limits following a security incident affecting your data, a supervisory authority's request, or serious evidence of non-compliance. An equivalent third-party report may be offered in place of an on-site audit;
- inform you immediately if, in our opinion, an instruction infringes the GDPR or another data protection provision.
Article 28(3) requires the subject matter, duration, nature and purpose of the processing, and the categories of personal data and of data subjects, to be determined. For a processing of this kind they are agreed in a written statement of work — exchanged by email is enough — which we confirm before the processing begins and which, once confirmed, forms your documented instructions and an annex to this addendum. Absent such a confirmed statement, we do not process data on your behalf and there is nothing for these terms to attach to. The processing lasts only as long as we carry it out for you.
6. Precedence, changes and contact
Where this addendum conflicts with the Terms on a data protection matter, this addendum prevails. Nothing in the Terms limits either party's liability under the GDPR, which has its own regime. Substantial changes to this addendum are notified in the same way as changes to the Terms, under section 14 of the Terms of Service and Sale.
For anything relating to this addendum — a security questionnaire, an incident, or a document your compliance process needs on your own paper: julien.maulny@tuta.io.