DPA · ART. 28 GDPR · TEMPLATE · v.A.13

Data Processing Addendum.

02 Definitions art. 02

'Controller' means the Customer receiving SmartPluvia services. 'Processor' means SmartPluvia Studio Sp. z o.o. 'Personal Data' means any information relating to an identified or identifiable natural person. Terms not defined here have the meaning given in GDPR Art. 4.

03 Scope of processing art. 03

The Processor processes Personal Data only on documented instructions from the Controller, expressed through use of the Service and this DPA. Categories of data: contact (email, name), technical (IP, user-agent), project (site metadata). Categories of subjects: users of the Controller's account.

04 Duration art. 04

This DPA takes effect on acceptance and continues for as long as the account is active. On termination the Processor returns or deletes all Personal Data within 30 days, except where retention is required by law.

05 Security art. 05

The Processor implements organizational and technical measures consistent with GDPR Art. 32: encryption at rest and in transit (TLS 1.3), authorization checks on every request, an admin audit log, and automated security testing on every change. Details — Annex II.

06 Subprocessors art. 06

The Controller grants the Processor general authorization to engage the subprocessors listed in Annex III. Changes — 30-day notice via email + dashboard. Right to object — within 14 days; if no resolution, the Controller may terminate.

07 Data subject rights art. 07

The Processor assists the Controller in fulfilling data subject requests (access, rectification, erasure, portability). Standard requests — via self-service in Settings; formal requests — via DPO email, response within 30 days.

08 Incidents art. 08

On a personal data breach the Processor notifies the Controller without undue delay and no later than 24 hours after detection. Notice includes: nature of the incident, categories and approximate count of subjects, likely consequences, mitigation measures.

09 Audit art. 09

The Controller may audit compliance with this DPA once per year, at the Controller's expense, with 30 days' notice. In lieu of an audit the Processor may provide its then-current security documentation.

10 Transfers outside the EEA art. 10

Transfers of Personal Data outside the EEA happen only under Standard Contractual Clauses (Module 2 — Processor to Processor) or to a recognized adequate jurisdiction. Current transfer list — Annex III.

III Annex III · Subprocessors vendors

Current as of the document update date. Changes — 30 days' notice via email and dashboard.

Subprocessor Service Location Transfer mechanism
Railway Corp. Hosting · managed PostgreSQL United States SCC
Cloudflare, Inc. DNS · R2 object storage United States SCC
Paddle.com Market Ltd Billing · merchant of record United Kingdom SCC
WayForPay Billing · payments (UA) Ukraine SCC
Resend, Inc. Transactional email United States SCC
AppSignal B.V. Error monitoring · APM Netherlands EEA
Plausible Analytics OÜ Anonymized usage analytics Tallinn, EE EU only · no PII
Cloudflare Inc. CDN · DDoS protection San Francisco, US SCC + ISO 27001
II Annex II · Technical measures controls
// ENCRYPTION

Encrypted at rest · TLS 1.3 in transit

// ACCESS

Password + Google sign-in · JWT with rotating refresh · admin audit log

// RESILIENCE

Managed PostgreSQL · object storage in Cloudflare R2

// NETWORK

TLS 1.3 · per-endpoint rate limiting · request size caps

// APPLICATION

Brakeman SAST · gem and npm advisory audits on every change

// VENDOR

DPA-signed subprocessors · 30-day change notice · audit

SIGN

Ready to sign?

Self-service signing in Settings → Billing → Legal. Owners sign on behalf of the organization. Counter-signed PDF — same section.