Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies where consostack processes personal data contained in Customer Content on your behalf as a processor under the GDPR. For data where we are the controller (your account and billing data), see the Privacy Policy.
1Roles
For Customer Content, you are the controller and consostack is the processor. Each party will comply with its obligations under applicable data-protection law, including the GDPR.
2Scope of processing
- Subject matter
- Hosting and operating your applications and databases.
- Duration
- For the term of your account, plus deletion periods.
- Nature & purpose
- Storage, computation, transmission, and serving of your application data.
- Data categories
- Whatever your application stores — determined and controlled by you.
- Data subjects
- Your end users and others whose data your application processes.
3Our obligations
- Process Customer Content only on your documented instructions (including via the Service).
- Ensure personnel are bound by confidentiality.
- Assist you, as reasonable, with security, breach notification, and data-subject requests.
4Security
We implement appropriate technical and organisational measures, including encryption in transit, per-organisation tenant isolation, access controls, and audit logging (see the Privacy Policy, Security).
5Sub-processors
You authorise the use of the sub-processors below. We remain responsible for their performance and will give notice of changes.
| Sub-processor | Purpose | Location |
|---|---|---|
| [Hetzner Online GmbH] | Compute & hosting infrastructure | EU (Germany) |
| Stripe | Payment processing | [EU/US] |
| [EMAIL PROVIDER] | Transactional email | [REGION] |
6Data subject requests
Taking into account the nature of the processing, we will assist you by appropriate measures to respond to requests from data subjects to exercise their GDPR rights. Where a data subject contacts us directly about your application, we will refer them to you.
7International transfers
Processing takes place in the EU. Any transfer outside the EEA by a sub-processor is covered by appropriate safeguards such as Standard Contractual Clauses.
8Breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Content, with information reasonably available to us to help you meet your own notification obligations.
9Deletion & return
On termination, we will delete or, on request, return Customer Content within a reasonable period, except where retention is required by law. [STATE DELETION PERIOD].
10Audits
We will make available information reasonably necessary to demonstrate compliance and, subject to confidentiality and reasonable notice, allow for audits as required by Article 28 GDPR. [STATE AUDIT PROCESS / FREQUENCY].