Dropvik
Get started
Dropvik

Data processing agreement

This text is a template. Replace the bracketed fields with your company details and have the document reviewed by legal counsel before publishing.

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the terms of use between [Company name], [address] ("Processor") and the customer using the service ("Controller"). It applies whenever the Controller uses the service to store or transfer files containing personal data.

1. Subject matter and duration

The Processor stores and delivers files uploaded by the Controller or by third parties on the Controller's behalf, for the retention period selected per transfer. The DPA lasts as long as the Controller's account exists.

2. Nature and purpose of processing

Storage, transmission, optional virus and content scanning, download logging (IP address, user agent, country, time) and e-mail notifications. The Processor does not inspect file contents for any other purpose.

3. Categories of data and data subjects

Any personal data contained in uploaded files; e-mail addresses of senders and recipients; technical access data. Data subjects: the Controller's employees, customers, partners and recipients.

4. Obligations of the Processor

  • Process personal data only on documented instructions of the Controller (the settings chosen in the service).
  • Ensure confidentiality of personnel with access to data.
  • Implement appropriate technical and organisational measures: encryption in transit (TLS), optional end-to-end encryption, access control, isolated storage, logging, backups and automatic deletion after the retention period.
  • Assist the Controller with data subject requests and with demonstrating compliance.
  • Delete or return all personal data at the end of the service, unless retention is required by law.
  • Notify the Controller without undue delay after becoming aware of a personal data breach.

5. Sub-processors

The Processor uses the following sub-processors: [hosting provider, e.g. Hetzner Online GmbH, Germany] (servers and object storage), [Cloudflare, Inc.] (network security and content delivery), [e-mail provider] (transactional e-mail). The Controller will be informed of intended changes and may object on reasonable grounds.

6. International transfers

Data is stored in [data centre location, e.g. Germany / EU]. Transfers outside the EEA take place only under appropriate safeguards (standard contractual clauses).

7. Audit

The Processor makes available all information necessary to demonstrate compliance and allows for audits conducted by the Controller or an auditor mandated by the Controller, with reasonable notice.

8. Liability and governing law

Liability follows the terms of use. This DPA is governed by the law of [country].

Contact for data protection matters: [[email protected]].