GDPR & HIPAA Compliance

Compliance built into
the architecture.

VS3 was designed for regulated industries. GDPR and HIPAA requirements are not an afterthought — they are encoded into the storage architecture, audit trail, and key management layer.

Note: This page should be reviewed by your legal team. For DPA or BAA requests, contact saadi@vautra.com


GDPR

General Data Protection
Regulation

What Vautra Collects

Account data: name, email, billing information

Content data: files — encrypted end-to-end, never read by Vautra

Usage and technical data for platform operation

Payment data processed via PCI-DSS certified partners

Legal Basis for Processing

Art. 6(1)(b) — Contractual necessity for service delivery

Art. 6(1)(a) — Consent for marketing communications

Art. 6(1)(c) — Legal obligation compliance

Art. 6(1)(f) — Legitimate interest for security monitoring

Where Your Data Is Stored

EU users stored preferentially in the European region

Files encrypted at rest (AES-256) and in transit (TLS 1.3)

International transfers protected by SCCs and adequacy decisions

Region selection enforced at the infrastructure level

Data Retention

Account data: 90 days post-deletion then purged

Uploaded files: removed within 30 days of deletion

Billing records: retained for 7 years

Audit logs: 12 months active access, 5 years archived

Your GDPR Rights

Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17)

Restriction (Art. 18), Portability (Art. 20), Object (Art. 21)

Withdraw Consent (Art. 7(3)) at any time

All requests responded to within 30 days

Data Processing Agreement

DPA available for all enterprise clients

Covers Controller/Processor roles and sub-processor list

Breach notification within 72 hours

Includes SCCs and audit rights


HIPAA

Health Insurance Portability
and Accountability Act

Technical Safeguards

AES-256 encryption at rest (NIST SP 800-111)

TLS 1.3 encryption in transit

Access controls with role-based permissions

Automatic logoff and session management

Audit Controls

Real-time audit log of all file access, share and deletion events

Anryton blockchain object proofs for tamper-proof verification

Audit log export in CSV, JSON or PDF format

Real-time alerts for suspicious access events

Breach Notification

Covered Entity notified within 60 days (target: 10 business days)

AES-256 encryption qualifies for HIPAA Encryption Safe Harbor (NIST SP 800-111)

Incident response team activated on detection

Full documentation provided for regulatory reporting

Request a Business Associate Agreement

Template provided within 5 business days · Contact: saadi@vautra.com

Request BAA

Powered by Anryton

A blockchain audit layer
you can verify independently.

VS3 uses Anryton — Vautra's own EVM-compatible private Layer 1 blockchain built on Cosmos SDK with Tendermint consensus — to store object proofs for every file action.

Anryton is fully owned and operated within the Vautra ecosystem — it is not a third-party dependency. Learn more at anryton.com →