Version dated 2 October 2026. Applies to orders expressly incorporating this version. This agreement is between the Customer identified in the Order Form and the Provider identified in the Terms.
1. Roles and scope
The Customer determines the purposes and essential means of processing in its instance and acts as controller. The Provider acts as processor for operations on its behalf. If the Customer is itself a processor, it confirms authority to engage the Provider and passes on relevant instructions; the Provider then acts as subprocessor. Actual operations determine the roles.
The Provider may be a separate controller for its prospects, contractual contacts, invoices and legal obligations within its privacy notice. This separate role does not permit repurposing entrusted data.
2. Processing description
The subject is implementation, operation, maintenance, security, support and exit of the ordered instance and modules. Authorised operations include instructed collection, hosting, strictly necessary access, technical copying, indexing, organisation, file transformation, previews, making data available, requested communications, export and deletion. Processing lasts for the services followed only by agreed return and purge periods.
Data subjects include Customer employees, contractors, partners, clients, authorised guests, communication recipients and people appearing in content or metadata. Data may include names, business emails, company, role, groups, region, preferences, accounts and sessions, protected authentication materials, IP addresses and security records, views/searches/downloads, invitations, licence acceptances, images and metadata, product records, histories, module business data and email delivery reports. The specific schedule removes unused categories and describes module-specific fields.
Special-category data under GDPR Article 9 and criminal-offence data require additional written instructions and safeguards. Passwords and secrets must not be entered into free-text fields, tickets or business content.
3. Instructions and confidentiality
The Provider processes only on documented instructions comprising the contract, processing specification and requests from authorised contacts, including transfer instructions. If it considers an instruction unlawful under data-protection law, it immediately informs the Customer and pauses that operation pending clarification. If law requires processing, it gives prior notice unless legally prohibited.
Authorised personnel are bound by confidentiality, receive data-protection awareness training and have need-based access that is reviewed and revoked when unnecessary. The Provider neither trains AI models on Customer data nor sells it. New processing or an AI supplier requires prior specification updates and, where required, subprocessor authorisation.
4. Security
The Provider implements risk-appropriate measures under GDPR Article 32. The security specification records actual implementation per component and any justified alternative before production. Proposed minimum commitments include encrypted connections; named, least-privilege technical access and stronger authentication where available; secret protection; logical instance isolation and network restrictions; password hashing; patch management; proportionate logging; protected backups and tested restoration; incident response; controlled deletion and periodic security review.
The specification separately identifies encryption at rest for databases, objects and backups, and key management. HTTPS is not proof of complete encryption at rest. It distinguishes host and Provider controls. No ISO, SOC or other certification is asserted. Security is not substantially reduced during the contract without adequate compensating measures.
5. Subprocessors
The Customer gives general authorisation for subprocessors in the accepted initial specification, stating each legal entity, service, data categories, storage/access countries and transfer safeguards. Hetzner and OVHcloud are infrastructure options to identify per instance, not blanket authorisations of all services or locations.
The Provider gives at least thirty days’ written notice before adding or replacing a subprocessor, with relevant details. Within that period the Customer may object on reasoned data-protection grounds. The parties seek a solution; if none is reasonably available before the new party’s involvement, the Customer may end the affected service without penalty for that reason, with unused prepayments refunded and data returned. The new party receives no data for that Customer until the objection is resolved or the service ends.
The Provider imposes at least equivalent protection obligations and remains fully responsible to the Customer for their performance. A storage or identity provider contracted directly by the Customer is not automatically a Provider subprocessor. Each actor’s role follows the actual data flow.
6. Locations and transfers
Authorised countries are specified for servers, backups, CDNs, remote support and email. Transfers outside the EEA require documented instructions and a lawful GDPR Chapter V mechanism: an adequacy decision actually covering the recipient and processing, or appropriate safeguards such as relevant standard contractual clauses, transfer assessment and supplementary measures where needed. The Provider supplies relevant information.
A European primary server does not mean the entire service involves no international transfers. The Provider assesses official access requests, challenges them where necessary and possible, limits disclosure to necessity and informs the Customer unless prohibited.
7. Assistance and individual rights
The Provider promptly forwards direct data-subject requests to the designated Customer contact and does not substantively answer except on instruction or legal obligation. It assists with access, correction, erasure, restriction, objection and portability considering the processing and available means. Product functions assist but do not replace assessment of requests or handling backups and third-party systems.
The Provider supplies reasonably necessary assistance for security, impact assessments, prior consultation and GDPR Articles 32–36. Ordinary assistance and work required by its own breach are included. Exceptional work outside scope may be quoted in advance, but a fee dispute does not suspend urgent statutory duties.
8. Personal data breaches
The Provider notifies the Customer’s security contact of a relevant personal data breach without undue delay after becoming aware. Initial notice does not wait for a completed investigation. It gives known facts, estimated scope and nature, subject and data categories, likely consequences, mitigation and contact details; further information follows without undue delay.
The Provider preserves useful evidence, mitigates and cooperates. The Customer decides authority and individual notifications unless the Provider has its own legal duty. A controller’s potential seventy-two-hour deadline is not a waiting period for the Provider. Contacts and the out-of-hours alert process are specified in the agreed processing record before production.
9. Documentation and audits
The Provider maintains required documentation and records, demonstrates compliance and makes necessary information available. The Customer or an independent confidential auditor may conduct relevant audits, initially documentary and then on-site or technical where necessary, without accessing other customers’ data or compromising security.
Fifteen business days’ notice and annual frequency apply to ordinary audits but do not limit audits required by incidents, substantiated compliance concerns, authorities or law. Ordinary external audit costs are borne by the Customer; the Provider pays to remedy its own non-compliance. Regulatory powers remain unrestricted.
10. Return and deletion
At the end of services, the Provider returns or deletes personal data at the Customer’s choice, then deletes copies unless law requires retention. The Services Schedule provides at least thirty days for retrieval after transition unless lawful earlier deletion is instructed. Production deletion follows within thirty days and backups expire on the documented rotation no later than ninety days after production deletion.
Pending expiry, backups remain protected, unavailable for routine use and subject to reapplied deletions if restored. Legal retention exceptions are documented and limited in data and duration. Deletion is certified on request. These periods do not authorise continuing active processing after its purpose ends.
11. Instance specification to complete and accept
- Customer, any upstream controller, business purpose and precise processing purposes.
- Both parties’ privacy/security contacts, authorised instruction contacts and processing period.
- Instance, modules, actual data and subject categories, volumes and restrictions.
- Server, database, storage, backup and support-access countries.
- One entry per subprocessor: legal identity, service, data, countries, Article 28 contract, transfer mechanism and authorisation date.
- Customer-contracted connectors, flows and permissions; SMTP, SSO, breached-password checks, CDN and AI if any.
- Retention by category: accounts, sessions, activity, searches, audits, server logs, invitations, business history, downloads, newsletters, exports and backups.
- Effective controls, responsibilities, restoration tests and last verification date.
Retention periods are defined in the specific processing record according to the purposes and configured before production. Software defaults do not replace this assessment. Residual limitations and module-specific settings are documented.
12. Effect
This DPA takes effect with the incorporating Order Form and completed specification and continues until entrusted data is deleted. It prevails over conflicting personal-data provisions without limiting individual rights or statutory obligations.