Skip to content

Legal · Last updated June 9, 2026

GDPR Compliance & EU Data Protection

How Vibely meets the requirements of the GDPR and UK GDPR for individuals in the European Economic Area and the United Kingdom.

1. Who this page is for

This page is for individuals in the European Economic Area (EEA) and the United Kingdom. It summarizes how Vibely meets the requirements of the General Data Protection Regulation (GDPR) and, for UK users, the UK GDPR. It supplements — and does not replace — our full Privacy Policy at /privacy-policy, which controls in the event of any conflict.

2. Lawful basis for processing

We rely on the following lawful bases to process your personal data:

  • Contract performance — to create your account, run agent loops on your behalf, and provide the service you signed up for.
  • Legitimate interests — to secure the platform, prevent abuse, and improve product reliability, balanced against your rights and expectations.
  • Consent — for optional communications, such as marketing emails, which you can withdraw at any time.

3. International data transfers

Vibely is operated from India by Mana Intelligence Pvt Ltd, and its production infrastructure is hosted in the United States (AWS us-east-1). Personal data from EEA and UK users is transferred to and processed in the United States under Standard Contractual Clauses (SCCs) approved by the European Commission, which impose contractual safeguards on how that data is handled. The same SCC mechanism covers our China-based AI inference subprocessors (DeepSeek, Moonshot AI) — see the full list at /subprocessors. EU and India hosting regions are targeted for the second half of 2026.

4. EU representative (Article 27)

In accordance with Article 27 of the GDPR, Vibely has appointed an EU representative to serve as a point of contact for supervisory authorities and data subjects in the European Union. Contact [email protected] for the representative’s details.

5. Your rights as a data subject

Under the GDPR you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing (including for direct marketing). To exercise any of these rights, email [email protected]; we will respond within the timeframes required by law. You also have the right to lodge a complaint with your local data protection supervisory authority.

6. Data Processing Agreement

A Data Processing Agreement (DPA) reflecting GDPR Article 28 requirements is available for enterprise review. Contact [email protected] to request it.

7. Subprocessors

We share personal data with a small, deliberate set of subprocessors — cloud hosting, AI inference, payments, observability, and email — under written data protection agreements. The current list is published at /subprocessors.

8. Security measures

We encrypt data in transit (TLS 1.3) and at rest (AES-256), gate access to production systems behind SSO and multi-factor authentication, and log that access. See /security for our full security and compliance posture.

9. Data retention

Project data is retained for as long as your account is active. You can delete projects at any time. When you close your account, we delete your personal data within 30 days, except where retention is required by law.

10. Contact

For GDPR questions or to exercise your rights, email [email protected]. Vibely is operated by Mana Intelligence Pvt Ltd, incorporated in India.

Questions about this document? Email[email protected].