Data Processing Addendum.
'Controller' means the Customer receiving SmartPluvia services. 'Processor' means SmartPluvia Studio Sp. z o.o. 'Personal Data' means any information relating to an identified or identifiable natural person. Terms not defined here have the meaning given in GDPR Art. 4.
The Processor processes Personal Data only on documented instructions from the Controller, expressed through use of the Service and this DPA. Categories of data: contact (email, name), technical (IP, user-agent), project (site metadata). Categories of subjects: users of the Controller's account.
This DPA takes effect on acceptance and continues for as long as the account is active. On termination the Processor returns or deletes all Personal Data within 30 days, except where retention is required by law.
The Processor implements organizational and technical measures consistent with GDPR Art. 32: encryption at rest and in transit (TLS 1.3), authorization checks on every request, an admin audit log, and automated security testing on every change. Details — Annex II.
The Controller grants the Processor general authorization to engage the subprocessors listed in Annex III. Changes — 30-day notice via email + dashboard. Right to object — within 14 days; if no resolution, the Controller may terminate.
The Processor assists the Controller in fulfilling data subject requests (access, rectification, erasure, portability). Standard requests — via self-service in Settings; formal requests — via DPO email, response within 30 days.
On a personal data breach the Processor notifies the Controller without undue delay and no later than 24 hours after detection. Notice includes: nature of the incident, categories and approximate count of subjects, likely consequences, mitigation measures.
The Controller may audit compliance with this DPA once per year, at the Controller's expense, with 30 days' notice. In lieu of an audit the Processor may provide its then-current security documentation.
Transfers of Personal Data outside the EEA happen only under Standard Contractual Clauses (Module 2 — Processor to Processor) or to a recognized adequate jurisdiction. Current transfer list — Annex III.
Current as of the document update date. Changes — 30 days' notice via email and dashboard.
| Subprocessor | Service | Location | Transfer mechanism |
|---|---|---|---|
| Railway Corp. | Hosting · managed PostgreSQL | United States | SCC |
| Cloudflare, Inc. | DNS · R2 object storage | United States | SCC |
| Paddle.com Market Ltd | Billing · merchant of record | United Kingdom | SCC |
| WayForPay | Billing · payments (UA) | Ukraine | SCC |
| Resend, Inc. | Transactional email | United States | SCC |
| AppSignal B.V. | Error monitoring · APM | Netherlands | EEA |
| Plausible Analytics OÜ | Anonymized usage analytics | Tallinn, EE | EU only · no PII |
| Cloudflare Inc. | CDN · DDoS protection | San Francisco, US | SCC + ISO 27001 |
Encrypted at rest · TLS 1.3 in transit
Password + Google sign-in · JWT with rotating refresh · admin audit log
Managed PostgreSQL · object storage in Cloudflare R2
TLS 1.3 · per-endpoint rate limiting · request size caps
Brakeman SAST · gem and npm advisory audits on every change
DPA-signed subprocessors · 30-day change notice · audit
Ready to sign?
Self-service signing in Settings → Billing → Legal. Owners sign on behalf of the organization. Counter-signed PDF — same section.