/legal/dpa

Data Processing

A data-processing agreement records how one party handles personal data on another party’s behalf. Vulos publishes free and open-source software and operates no service that holds your data, so there is no such relationship to write down — and no DPA to sign. This page explains what we do instead: we give you the software, under a licence, and the data stays with you.

MIT OR Apache-2.0No data leaves your machine for usLast reviewed 2026-07-24

Section 1

What Vulos publishes

Vulos is one operating system, plus a suite of open-source apps that run on it. You download it, you install it on hardware you own or on a machine you rent from a provider of your choosing, and you run it. That is the whole relationship.

There is no hosted product. There is no Vulos account, nothing to sign in to at vulos.org, no managed hosting, and no billing — we charge nobody. Your files, mail, calendar, contacts, keys and AI context sit on your machine. Keeping them there is a design goal of the project, not a side effect: the software is built so that your data never has to reach us, and it does not.

Section 2

Who is responsible for what

Because we never receive your data, we are neither a processor nor an operator (POPIA s1) of it, and neither a controller nor a responsible party. Those roles belong elsewhere:

PartyRole
VulosPublisher of the software. We write an operating system and a set of apps and give them away under an open-source licence. We receive no data from your box, hold no accounts for you, and bill you nothing.
YouOperator of your own machine. You install the software on hardware you own or rent, you decide what it stores, and you hold the keys. Under POPIA you are the Responsible Party for that data; under the GDPR, the Controller.
Your infrastructure providerWhoever you rent a machine, a disk or a network from — a VPS host, a storage provider, your own cupboard. If a data-processing agreement is needed for the place your data physically sits, it is between you and them.
Your usersThe people whose personal information ends up on your box, if you run Vulos for anyone besides yourself. Their rights run against you, because you are the one holding their data.

We engage no sub-processors for user data, because we hold no user data. The only third parties that exist anywhere in the picture are the host of this website and the host of the source code — both listed at /legal/subprocessors.

Section 3

The licence is the agreement

The operating system and every app in the suite are dual-licensed MIT OR Apache-2.0, at your option. Both licence texts ship in each repository as LICENSE-MIT and LICENSE-APACHE. Pick whichever suits you; you do not need to tell us which. In plain language, the licence grants you the right to:

  • Use the software for anything, including commercially, with no fee and no permission needed.
  • Study it — the complete source is published, so you can read exactly what it does.
  • Modify it, for yourself or for anyone else.
  • Redistribute it, modified or not, and sublicense or sell copies.
  • Self-host it — run it on your own hardware, a rented server, or a machine you operate for other people.
  • Fork it and carry on without us, permanently. The grant does not expire and we cannot revoke it for code already released.

The conditions are the ordinary open-source ones. Under MIT you keep the copyright notice and permission notice in copies you distribute. Under Apache-2.0 you keep the notices, state significant changes you made, and pass the licence along; Apache-2.0 also gives you an express patent licence from every contributor, which terminates if you sue over patents in the software. Neither licence grants rights in the Vulos name or logo (Apache-2.0 s6) — a fork is free, but it needs its own name.

The KOTVA specification, published separately, is licensed CC BY 4.0 so anyone may implement it with attribution.

Section 4

As-is, with no warranty

The software is provided “as is”, without warranty of any kind, express or implied — including the warranties of merchantability, fitness for a particular purpose and non-infringement. That is the licence text itself, not an extra term we add.

It follows that we are not liable for what happens when you run it: not for lost data, downtime, damage, or any other claim arising from the software or from dealings in it. You decide whether running it is appropriate for what you need, and you carry that risk — Apache-2.0 s7 puts it in exactly those words. Where the law of your country will not permit a disclaimer that broad, the law wins; we do not claim more protection than it allows.

This cuts both ways

Because we make no promises about the software, we also make none about your data: we cannot lose it, leak it, hand it to anyone or hold it hostage, because we never have it. The protection you get is structural, not contractual — read the source and check.

Section 5

If you run Vulos for other people

Self-hosting for a family, a team or a business puts you in the seat we are not in. Practically, that means:

  • You are the Responsible Party (POPIA) or Controller (GDPR) for the personal information on your box, and you need a lawful basis for holding it.
  • You answer data-subject requests — access, correction, deletion, objection — directly, because you are the only one who can reach the data.
  • You choose your infrastructure, and any processing agreement for it is between you and that provider.
  • You own security and backups: updates, access control, disk encryption, keeping copies, and telling people if something goes wrong.
  • You set your own retention. The software imposes no expiry and we impose none, because we cannot see the data to expire it.

Where your obligations are non-trivial — regulated data, staff records, health or financial information — take your own legal advice. We can tell you how the software behaves; we cannot advise on your duties.

Section 6

Reachability

Reaching a box behind a home router needs something in the middle. By default Vulos uses the built-in Vulos relay — a role of the same open-source binary, run by you on a box with a public IP. It forwards an encrypted stream between your browser and your box: it holds no keys and cannot read what passes through it. Because you operate it, no third party sits in the path.

You may run your own relay nodes, reach your box directly over a static IP or your own domain, or point at an experimental broker such as Pier (an open-source broker we host, you self-run, or somebody else’s). Moving between them is a configuration change — there is no account to close and nothing to migrate. Source at github.com/vul-os/pier.

Section 7

Which words govern

The operative terms are the licence files in the repositories — LICENSE-MIT and LICENSE-APACHE. This page describes them in plain language so you can see what you are getting; where a description here and the licence text differ, the licence text is what counts.


Contact

Still need something signed?

Tell us what your reviewer is looking for

Procurement forms often assume a vendor holds the data. If yours does, write to us and we will describe the architecture in whatever detail your reviewer needs — where data sits, who holds keys, what crosses the network. What we will not do is sign an agreement that describes processing we do not perform.

Email privacy@vulos.org