Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the terms of use between [Company name], [address] ("Processor") and the customer using the service ("Controller"). It applies whenever the Controller uses the service to store or transfer files containing personal data.
1. Subject matter and duration
The Processor stores and delivers files uploaded by the Controller or by third parties on the Controller's behalf, for the retention period selected per transfer. The DPA lasts as long as the Controller's account exists.
2. Nature and purpose of processing
Storage, transmission, optional virus and content scanning, download logging (IP address, user agent, country, time) and e-mail notifications. The Processor does not inspect file contents for any other purpose.
3. Categories of data and data subjects
Any personal data contained in uploaded files; e-mail addresses of senders and recipients; technical access data. Data subjects: the Controller's employees, customers, partners and recipients.
4. Obligations of the Processor
- Process personal data only on documented instructions of the Controller (the settings chosen in the service).
- Ensure confidentiality of personnel with access to data.
- Implement appropriate technical and organisational measures: encryption in transit (TLS), optional end-to-end encryption, access control, isolated storage, logging, backups and automatic deletion after the retention period.
- Assist the Controller with data subject requests and with demonstrating compliance.
- Delete or return all personal data at the end of the service, unless retention is required by law.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
5. Sub-processors
The Processor uses the following sub-processors: [hosting provider, e.g. Hetzner Online GmbH, Germany] (servers and object storage), [Cloudflare, Inc.] (network security and content delivery), [e-mail provider] (transactional e-mail). The Controller will be informed of intended changes and may object on reasonable grounds.
6. International transfers
Data is stored in [data centre location, e.g. Germany / EU]. Transfers outside the EEA take place only under appropriate safeguards (standard contractual clauses).
7. Audit
The Processor makes available all information necessary to demonstrate compliance and allows for audits conducted by the Controller or an auditor mandated by the Controller, with reasonable notice.
8. Liability and governing law
Liability follows the terms of use. This DPA is governed by the law of [country].
Contact for data protection matters: [[email protected]].