OctaDeploy
← Home

Data Processing Agreement

Last updated: 12 July 2026  ·  Octagon Solutions LLC, Florida, USA

Datenverarbeitungsvertrag

Zuletzt aktualisiert: 12. Juli 2026  ·  Octagon Solutions LLC, Florida, USA

Ugovor o obradi podataka

Zadnje ažuriranje: 12. juli 2026.  ·  Octagon Solutions LLC, Florida, SAD

This Data Processing Agreement ("DPA") is entered into between you, acting as data controller ("Controller"), and Octagon Solutions LLC, Florida, USA ("Processor"), and forms an integral part of the OctaDeploy Terms of Service. Where you use OctaDeploy to host applications that process personal data of third parties (your end users), this DPA governs that processing.

1. Definitions

"Personal Data", "Data Subject", "Processing", "Controller", "Processor", "Sub-processor", and "Supervisory Authority" have the meanings ascribed to them in the EU General Data Protection Regulation (GDPR) 2016/679.

2. Details of Processing

  • Categories of data subjects: End users and visitors of the Controller's applications deployed on OctaDeploy
  • Types of personal data: Any personal data submitted by end users to the Controller's applications; OctaDeploy does not prescribe or know the categories — the Controller determines what data its application collects
  • Purpose and nature of processing: Providing compute, storage, networking, and related infrastructure hosting services for the Controller's applications
  • Duration of processing: For the term of the service agreement plus 30 days after termination

3. Controller's Obligations

The Controller shall ensure that: (a) it has a lawful basis for processing the personal data it transmits to the Processor's infrastructure; (b) data subjects have been informed of the processing as required by GDPR; (c) any instructions given to the Processor are lawful; (d) it has implemented appropriate security measures on its application layer.

4. Processor's Obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller (the deployment and operation of the Controller's application constitutes such instructions)
  • Ensure that persons authorised to process personal data are bound by confidentiality obligations
  • Implement and maintain appropriate technical and organisational security measures (see Section 7)
  • Assist the Controller in fulfilling its obligations to data subjects (Art. 15–21 GDPR) within 5 business days of a written request, to the extent technically feasible
  • Notify the Controller promptly if, in the Processor's opinion, an instruction infringes applicable data protection law
  • Delete or return all personal data upon termination as requested by the Controller, and provide written confirmation
  • Make available all information reasonably necessary to demonstrate compliance with this DPA

5. Sub-processors

The Controller provides general authorisation for the Processor to engage the following sub-processors:

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — dedicated server infrastructure (EU)

The Processor will inform the Controller by email at least 30 days in advance of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object. If the Controller objects on reasonable data protection grounds and the parties cannot resolve the matter, the Controller may terminate the agreement with 30 days written notice.

6. International Data Transfers

Where personal data is transferred from the EU/EEA to the USA (the Processor's country of incorporation), such transfers are governed by Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914, Module 2 (Controller to Processor). The SCCs are incorporated into this DPA by reference. The Processor will provide a signed copy upon written request. For transfers to Hetzner (Germany), no international transfer instrument is required as Germany is an EU member state.

7. Technical & Organisational Security Measures

The Processor maintains the following measures at the time of this DPA, subject to ongoing improvement:

  • Encryption in transit: TLS 1.2 or higher for all connections to and from deployed applications
  • Isolation: Each application runs in an isolated Docker container; applications cannot access each other's filesystems or networks
  • Access control: Role-based access; server access restricted to authorised personnel; SSH key-based authentication only
  • Patch management: Regular security patches applied to underlying OS and runtime dependencies
  • Incident response: Documented incident detection and response procedure
  • Backups: Available as a paid add-on; not enabled by default on all plans

8. Personal Data Breach Notification

The Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data. The notification shall include: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.

9. Data Subject Rights Assistance

The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection — Art. 15–21 GDPR) within 5 business days of a written request from the Controller. Assistance is limited to what is technically feasible given the Processor's infrastructure role.

10. Audit Rights

Upon 30 days written notice and no more than once per calendar year (unless mandated by a Supervisory Authority), the Controller may request: (a) completion of a security questionnaire; (b) access to relevant audit logs and documentation. Physical on-site audits may be arranged by agreement, subject to reasonable advance notice and confidentiality undertakings.

11. Termination

Upon termination of the service agreement, the Processor shall delete all personal data of the Controller's end users within 30 days, unless retention is required by applicable law, and shall provide written confirmation of deletion. The Controller may request return of data in a machine-readable format before deletion.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA shall limit either party's liability for breach of obligations under applicable data protection law.

13. Contact

Octagon Solutions LLC — Data Processing Inquiries Email: support@octadeploy.com
Subject line: "DPA Request – [your company name]"

Dieser Datenverarbeitungsvertrag ("DPA" / Auftragsverarbeitungsvertrag, "AVV") wird zwischen Ihnen als Verantwortlichem ("Verantwortlicher") und Octagon Solutions LLC, Florida, USA ("Auftragsverarbeiter") geschlossen und ist integraler Bestandteil der OctaDeploy-Nutzungsbedingungen. Soweit Sie OctaDeploy nutzen, um Anwendungen zu hosten, die personenbezogene Daten Dritter (Ihrer Endnutzer) verarbeiten, regelt dieser AVV diese Verarbeitung.

1. Begriffsbestimmungen

"Personenbezogene Daten", "Betroffene Person", "Verarbeitung", "Verantwortlicher", "Auftragsverarbeiter", "Unterauftragsverarbeiter" und "Aufsichtsbehörde" haben die Bedeutung gemäß EU-DSGVO 2016/679.

2. Einzelheiten der Verarbeitung

  • Kategorien betroffener Personen: Endnutzer und Besucher der auf OctaDeploy gehosteten Anwendungen des Verantwortlichen
  • Arten personenbezogener Daten: Alle personenbezogenen Daten, die Endnutzer in die Anwendungen des Verantwortlichen eingeben; OctaDeploy kennt die Kategorien nicht — der Verantwortliche bestimmt, welche Daten seine Anwendung erhebt
  • Zweck und Art der Verarbeitung: Bereitstellung von Rechen-, Speicher-, Netzwerk- und verwandten Infrastruktur-Hosting-Diensten
  • Dauer der Verarbeitung: Für die Laufzeit des Servicevertrags zuzüglich 30 Tage nach Beendigung

3. Pflichten des Verantwortlichen

Der Verantwortliche stellt sicher, dass: (a) er eine Rechtsgrundlage für die Verarbeitung hat; (b) betroffene Personen informiert wurden; (c) erteilte Weisungen rechtmäßig sind; (d) er auf Anwendungsebene geeignete Sicherheitsmaßnahmen implementiert hat.

4. Pflichten des Auftragsverarbeiters

Der Auftragsverarbeiter wird:

  • Personenbezogene Daten nur auf dokumentierte Weisung des Verantwortlichen verarbeiten
  • Sicherstellen, dass zur Verarbeitung befugte Personen zur Vertraulichkeit verpflichtet sind
  • Geeignete technische und organisatorische Schutzmaßnahmen implementieren und aufrechterhalten (vgl. Abschnitt 7)
  • Den Verantwortlichen bei der Erfüllung von Betroffenenrechten (Art. 15–21 DSGVO) unterstützen
  • Den Verantwortlichen benachrichtigen, wenn eine Weisung gegen geltendes Datenschutzrecht verstößt
  • Alle personenbezogenen Daten nach Beendigung löschen oder zurückgeben und schriftlich bestätigen

5. Unterauftragsverarbeiter

Der Verantwortliche erteilt eine allgemeine Genehmigung für folgende Unterauftragsverarbeiter:

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland — dedizierte Server-Infrastruktur (EU)

Der Auftragsverarbeiter informiert den Verantwortlichen mindestens 30 Tage im Voraus über beabsichtigte Änderungen bei Unterauftragsverarbeitern.

6. Internationale Datenübermittlungen

Übermittlungen personenbezogener Daten aus der EU/EWR in die USA unterliegen Standardvertragsklauseln gemäß Durchführungsbeschluss (EU) 2021/914, Modul 2 (Verantwortlicher zu Auftragsverarbeiter), die hiermit in diesen AVV einbezogen werden. Eine unterzeichnete Kopie ist auf Anfrage erhältlich.

7. Technische und organisatorische Maßnahmen

  • Verschlüsselung während der Übertragung: TLS 1.2 oder höher
  • Isolation: Jede Anwendung läuft in einem isolierten Docker-Container
  • Zugriffskontrolle: Rollenbasierter Zugang; SSH-Schlüsseln-Authentifizierung
  • Patch-Management: Regelmäßige Sicherheitsupdates für Betriebssystem und Laufzeitabhängigkeiten
  • Incident Response: Dokumentiertes Verfahren zur Erkennung und Reaktion auf Vorfälle

8. Meldung von Datenpannen

Der Auftragsverarbeiter meldet Datenpannen unverzüglich und in jedem Fall innerhalb von 72 Stunden nach Bekanntwerden an den Verantwortlichen, mit Angaben zu Art, betroffenen Personen, Datensätzen, wahrscheinlichen Folgen und ergriffenen Maßnahmen.

9. Auditrechte

Nach 30-tägiger schriftlicher Ankündigung, höchstens einmal pro Kalenderjahr, kann der Verantwortliche: (a) einen Sicherheitsfragebogen anfordern; (b) Zugang zu relevanten Audit-Logs und Dokumentationen erhalten.

10. Beendigung

Nach Beendigung des Servicevertrags löscht der Auftragsverarbeiter alle personenbezogenen Daten der Endnutzer des Verantwortlichen innerhalb von 30 Tagen und bestätigt dies schriftlich.

Octagon Solutions LLC — Datenschutzanfragen E-Mail: support@octadeploy.com
Betreff: "DPA-Anfrage – [Ihr Unternehmensname]"

Ovaj Ugovor o obradi podataka ("DPA") zaključuje se između vas kao rukovaoca podacima ("Rukovalac") i Octagon Solutions LLC, Florida, SAD ("Obrađivač") te čini sastavni dio Uvjeta korištenja OctaDeployja. Kada OctaDeploy koristite za hosting aplikacija koje obrađuju osobne podatke trećih osoba (vaših krajnjih korisnika), ovaj DPA uređuje tu obradu.

1. Definicije

"Osobni podaci", "Subjekt podataka", "Obrada", "Rukovalac", "Obrađivač", "Podobrađivač" i "Nadzorno tijelo" imaju značenja dodijeljena im u EU Općoj uredbi o zaštiti podataka (GDPR) 2016/679.

2. Pojedinosti obrade

  • Kategorije subjekata podataka: Krajnji korisnici i posjetitelji aplikacija Rukovaoca deployanih na OctaDeployu
  • Vrste osobnih podataka: Svi osobni podaci koje krajnji korisnici dostavljaju aplikacijama Rukovaoca; OctaDeploy ne propisuje ni ne zna kategorije — Rukovalac određuje koje podatke njegova aplikacija prikuplja
  • Svrha i priroda obrade: Pružanje računalnih, pohranjivih, mrežnih i srodnih usluga infrastrukturnog hostinga za aplikacije Rukovaoca
  • Trajanje obrade: Za trajanje ugovora o servisu i 30 dana nakon raskida

3. Obveze Rukovaoca

Rukovalac osigurava da: (a) ima pravnu osnovu za obradu osobnih podataka; (b) subjekti podataka su obaviješteni o obradi; (c) dane upute Obrađivaču su zakonite; (d) je implementirao odgovarajuće sigurnosne mjere na razini aplikacije.

4. Obveze Obrađivača

Obrađivač će:

  • Obrađivati osobne podatke samo temeljem dokumentiranih uputa Rukovaoca
  • Osigurati da su osobe ovlaštene za obradu vezane obvezama povjerljivosti
  • Implementirati i održavati odgovarajuće tehničke i organizacijske sigurnosne mjere (vidi Odjeljak 7)
  • Pomagati Rukovaocu u ispunjavanju obveza prema subjektima podataka (čl. 15–21 GDPR-a)
  • Obavijestiti Rukovaoca ako smatra da uputa krši primjenjivo pravo zaštite podataka
  • Izbrisati ili vratiti sve osobne podatke po raskidu i pismeno to potvrditi

5. Podobrađivači

Rukovalac daje opće odobrenje za angažiranje sljedećih podobrađivača:

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Njemačka — namjenska serverska infrastruktura (EU)

Obrađivač će obavijestiti Rukovaoca najmanje 30 dana unaprijed o namjeravanim promjenama podobrađivača.

6. Međunarodni prijenosi podataka

Prijenosi osobnih podataka iz EU/EEP-a u SAD uređeni su standardnim ugovornim klauzulama temeljem Provedbene odluke Komisije (EU) 2021/914, Modul 2 (Rukovalac prema Obrađivaču), koje su ovim uključene u ovaj DPA uputom. Potpisana kopija dostupna je na pisani zahtjev.

7. Tehničke i organizacijske sigurnosne mjere

  • Enkripcija u prijenosu: TLS 1.2 ili viši za sve veze
  • Izolacija: Svaka aplikacija radi u izolovanom Docker kontejneru
  • Kontrola pristupa: Pristup zasnovan na ulogama; SSH autentifikacija ključevima
  • Upravljanje zakrpama: Redovita primjena sigurnosnih zakrpa na OS i runtime ovisnosti
  • Odgovor na incidente: Dokumentirana procedura za detekciju i odgovor na incidente

8. Obavijest o povredi osobnih podataka

Obrađivač će obavijestiti Rukovaoca bez nepotrebnog odgađanja i u svakom slučaju u roku od 72 sata od saznanja o povredi osobnih podataka koja utječe na Rukovaočeve podatke.

9. Pravo na reviziju

Po pisanoj obavijesti od 30 dana, jednom godišnje, Rukovalac može zatražiti: (a) popunjavanje sigurnosnog upitnika; (b) pristup relevantnim revizijskim logovima i dokumentaciji.

10. Raskid

Po raskidu ugovora o servisu, Obrađivač će izbrisati sve osobne podatke krajnjih korisnika Rukovaoca u roku od 30 dana i pismeno to potvrditi.

Octagon Solutions LLC — Upiti o obradi podataka Email: support@octadeploy.com
Predmet: "DPA zahtjev – [naziv vaše tvrtke]"
Home Privacy Policy Terms of Service DPA support@octadeploy.com
© 2026 Octagon Solutions LLC. All rights reserved.