consostackpreview
Legal

Data Processing Addendum

Effective: [EFFECTIVE DATE]Last updated: [EFFECTIVE DATE]
Template notice for the operator (remove before publishing): product-grounded template, not legal advice. Fill every [PLACEHOLDER] and have it reviewed by qualified counsel in [JURISDICTION] before publishing.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies where consostack processes personal data contained in Customer Content on your behalf as a processor under the GDPR. For data where we are the controller (your account and billing data), see the Privacy Policy.

1Roles

For Customer Content, you are the controller and consostack is the processor. Each party will comply with its obligations under applicable data-protection law, including the GDPR.

2Scope of processing

Subject matter
Hosting and operating your applications and databases.
Duration
For the term of your account, plus deletion periods.
Nature & purpose
Storage, computation, transmission, and serving of your application data.
Data categories
Whatever your application stores — determined and controlled by you.
Data subjects
Your end users and others whose data your application processes.

3Our obligations

4Security

We implement appropriate technical and organisational measures, including encryption in transit, per-organisation tenant isolation, access controls, and audit logging (see the Privacy Policy, Security).

5Sub-processors

You authorise the use of the sub-processors below. We remain responsible for their performance and will give notice of changes.

Sub-processorPurposeLocation
[Hetzner Online GmbH]Compute & hosting infrastructureEU (Germany)
StripePayment processing[EU/US]
[EMAIL PROVIDER]Transactional email[REGION]

6Data subject requests

Taking into account the nature of the processing, we will assist you by appropriate measures to respond to requests from data subjects to exercise their GDPR rights. Where a data subject contacts us directly about your application, we will refer them to you.

7International transfers

Processing takes place in the EU. Any transfer outside the EEA by a sub-processor is covered by appropriate safeguards such as Standard Contractual Clauses.

8Breach notification

We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Content, with information reasonably available to us to help you meet your own notification obligations.

9Deletion & return

On termination, we will delete or, on request, return Customer Content within a reasonable period, except where retention is required by law. [STATE DELETION PERIOD].

10Audits

We will make available information reasonably necessary to demonstrate compliance and, subject to confidentiality and reasonable notice, allow for audits as required by Article 28 GDPR. [STATE AUDIT PROCESS / FREQUENCY].

Privacy Policy → Terms of Service → Contact →