Enterprise trust

Data processing should be bounded before deployment.

This page summarizes the data-processing architecture Veklom is designed to support for enterprise deployments. It is not a substitute for an executed Data Processing Addendum between the relevant legal entities.

01

Roles

Controller, processor and subprocessor roles depend on the customer deployment, connected services and applicable agreement. Veklom should not label a party as controller or processor universally when the real data flow can differ by deployment.

02

Processing scope

Account, workspace and authentication data required to operate the service.
Operational metadata, policy decisions and evidence generated by governed execution.
Integration metadata needed for services explicitly enabled by the operator.
Application payloads only where a selected capability requires them for the requested operation.
03

Security model

Veklom separates tenant/session state, consequence authority, host-sensitive execution and durable evidence into different boundaries. Deployment-specific technical and organizational measures should be documented in the executed agreement rather than inferred from product marketing.

04

Subprocessors and transfers

Any third party that processes customer personal data on Veklom's behalf should be disclosed in the applicable subprocessor list and contractual terms. A service used only for source control, DNS or another limited purpose should not be described as processing data it never receives.

05

Requests and deletion

Data-subject requests, deletion obligations, retention and export procedures depend on the deployment and governing agreement. Durable evidence may require a different retention policy from ephemeral runtime identity or ordinary account state.

Truth boundary

An enterprise DPA becomes binding only through the applicable executed agreement. This public page describes product architecture and negotiation posture; it does not create certification, residency or transfer guarantees by itself.