Vellaci
Swiss + EU data residency policy

Where your data will live

Last updated: 26 May 2026. This page describes the target architecture for the Vellaci European launch. Items still being migrated are marked “in progress” below — they are not yet part of the contractually-enforceable sub-processor list.

Status, 26 May 2026 — Vellaci is in the middle of moving its infrastructure into the Swiss + EU perimeter described below. Until each provider is reconfigured in its EU region, that line is labelled “in progress”. We do not silently downgrade your privacy posture: when an item flips from “in progress” to live, you will be notified by email and the change will be recorded in the page history.

Where each piece of data is stored (target architecture)

Why this matters — the Swiss + EU legal stack

Vellaci is built to meet two regimes at once:

Switzerland's adequacy decision under the GDPR remains valid as of 2026, so personal data can flow between EU/EEA and Switzerland without additional safeguards. The target Vellaci architecture (see above) keeps your relationship graph inside the Swiss + EU perimeter; until the migration completes, some sub-processors still operate from a non-EU region — see the “in progress” labels in the table above.

Sub-processor list (target — public & versioned at launch)

Once this list reaches its target configuration, any subsequent change will be announced at least 30 days in advance via email to the org admin.

Your rights — and the single click that exercises them

Data Processing Agreement (DPA)

Family or Pro customers acting as data controllers (e.g. a household admin, a small advisory firm) can sign Vellaci's standard DPA on request. It incorporates the EU Standard Contractual Clauses and the FDPIC's Swiss SCC variant where applicable.

What we don't do

Contact

Data protection officer: privacy@vellaci.ch · Postal: Vellaci, c/o the founder, Switzerland (precise address provided in the DPA).