This Data Processing Agreement ("DPA") is entered into between you, acting as data controller ("Controller"), and Octagon Solutions LLC, Florida, USA ("Processor"), and forms an integral part of the OctaDeploy Terms of Service. Where you use OctaDeploy to host applications that process personal data of third parties (your end users), this DPA governs that processing.
1. Definitions
"Personal Data", "Data Subject", "Processing", "Controller", "Processor", "Sub-processor", and "Supervisory Authority" have the meanings ascribed to them in the EU General Data Protection Regulation (GDPR) 2016/679.
2. Details of Processing
- Categories of data subjects: End users and visitors of the Controller's applications deployed on OctaDeploy
- Types of personal data: Any personal data submitted by end users to the Controller's applications; OctaDeploy does not prescribe or know the categories — the Controller determines what data its application collects
- Purpose and nature of processing: Providing compute, storage, networking, and related infrastructure hosting services for the Controller's applications
- Duration of processing: For the term of the service agreement plus 30 days after termination
3. Controller's Obligations
The Controller shall ensure that: (a) it has a lawful basis for processing the personal data it transmits to the Processor's infrastructure; (b) data subjects have been informed of the processing as required by GDPR; (c) any instructions given to the Processor are lawful; (d) it has implemented appropriate security measures on its application layer.
4. Processor's Obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller (the deployment and operation of the Controller's application constitutes such instructions)
- Ensure that persons authorised to process personal data are bound by confidentiality obligations
- Implement and maintain appropriate technical and organisational security measures (see Section 7)
- Assist the Controller in fulfilling its obligations to data subjects (Art. 15–21 GDPR) within 5 business days of a written request, to the extent technically feasible
- Notify the Controller promptly if, in the Processor's opinion, an instruction infringes applicable data protection law
- Delete or return all personal data upon termination as requested by the Controller, and provide written confirmation
- Make available all information reasonably necessary to demonstrate compliance with this DPA
5. Sub-processors
The Controller provides general authorisation for the Processor to engage the following sub-processors:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — dedicated server infrastructure (EU)
The Processor will inform the Controller by email at least 30 days in advance of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object. If the Controller objects on reasonable data protection grounds and the parties cannot resolve the matter, the Controller may terminate the agreement with 30 days written notice.
6. International Data Transfers
Where personal data is transferred from the EU/EEA to the USA (the Processor's country of incorporation), such transfers are governed by Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914, Module 2 (Controller to Processor). The SCCs are incorporated into this DPA by reference. The Processor will provide a signed copy upon written request. For transfers to Hetzner (Germany), no international transfer instrument is required as Germany is an EU member state.
7. Technical & Organisational Security Measures
The Processor maintains the following measures at the time of this DPA, subject to ongoing improvement:
- Encryption in transit: TLS 1.2 or higher for all connections to and from deployed applications
- Isolation: Each application runs in an isolated Docker container; applications cannot access each other's filesystems or networks
- Access control: Role-based access; server access restricted to authorised personnel; SSH key-based authentication only
- Patch management: Regular security patches applied to underlying OS and runtime dependencies
- Incident response: Documented incident detection and response procedure
- Backups: Available as a paid add-on; not enabled by default on all plans
8. Personal Data Breach Notification
The Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data. The notification shall include: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.
9. Data Subject Rights Assistance
The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection — Art. 15–21 GDPR) within 5 business days of a written request from the Controller. Assistance is limited to what is technically feasible given the Processor's infrastructure role.
10. Audit Rights
Upon 30 days written notice and no more than once per calendar year (unless mandated by a Supervisory Authority), the Controller may request: (a) completion of a security questionnaire; (b) access to relevant audit logs and documentation. Physical on-site audits may be arranged by agreement, subject to reasonable advance notice and confidentiality undertakings.
11. Termination
Upon termination of the service agreement, the Processor shall delete all personal data of the Controller's end users within 30 days, unless retention is required by applicable law, and shall provide written confirmation of deletion. The Controller may request return of data in a machine-readable format before deletion.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA shall limit either party's liability for breach of obligations under applicable data protection law.
13. Contact
Dieser Datenverarbeitungsvertrag ("DPA" / Auftragsverarbeitungsvertrag, "AVV") wird zwischen Ihnen als Verantwortlichem ("Verantwortlicher") und Octagon Solutions LLC, Florida, USA ("Auftragsverarbeiter") geschlossen und ist integraler Bestandteil der OctaDeploy-Nutzungsbedingungen. Soweit Sie OctaDeploy nutzen, um Anwendungen zu hosten, die personenbezogene Daten Dritter (Ihrer Endnutzer) verarbeiten, regelt dieser AVV diese Verarbeitung.
1. Begriffsbestimmungen
"Personenbezogene Daten", "Betroffene Person", "Verarbeitung", "Verantwortlicher", "Auftragsverarbeiter", "Unterauftragsverarbeiter" und "Aufsichtsbehörde" haben die Bedeutung gemäß EU-DSGVO 2016/679.
2. Einzelheiten der Verarbeitung
- Kategorien betroffener Personen: Endnutzer und Besucher der auf OctaDeploy gehosteten Anwendungen des Verantwortlichen
- Arten personenbezogener Daten: Alle personenbezogenen Daten, die Endnutzer in die Anwendungen des Verantwortlichen eingeben; OctaDeploy kennt die Kategorien nicht — der Verantwortliche bestimmt, welche Daten seine Anwendung erhebt
- Zweck und Art der Verarbeitung: Bereitstellung von Rechen-, Speicher-, Netzwerk- und verwandten Infrastruktur-Hosting-Diensten
- Dauer der Verarbeitung: Für die Laufzeit des Servicevertrags zuzüglich 30 Tage nach Beendigung
3. Pflichten des Verantwortlichen
Der Verantwortliche stellt sicher, dass: (a) er eine Rechtsgrundlage für die Verarbeitung hat; (b) betroffene Personen informiert wurden; (c) erteilte Weisungen rechtmäßig sind; (d) er auf Anwendungsebene geeignete Sicherheitsmaßnahmen implementiert hat.
4. Pflichten des Auftragsverarbeiters
Der Auftragsverarbeiter wird:
- Personenbezogene Daten nur auf dokumentierte Weisung des Verantwortlichen verarbeiten
- Sicherstellen, dass zur Verarbeitung befugte Personen zur Vertraulichkeit verpflichtet sind
- Geeignete technische und organisatorische Schutzmaßnahmen implementieren und aufrechterhalten (vgl. Abschnitt 7)
- Den Verantwortlichen bei der Erfüllung von Betroffenenrechten (Art. 15–21 DSGVO) unterstützen
- Den Verantwortlichen benachrichtigen, wenn eine Weisung gegen geltendes Datenschutzrecht verstößt
- Alle personenbezogenen Daten nach Beendigung löschen oder zurückgeben und schriftlich bestätigen
5. Unterauftragsverarbeiter
Der Verantwortliche erteilt eine allgemeine Genehmigung für folgende Unterauftragsverarbeiter:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland — dedizierte Server-Infrastruktur (EU)
Der Auftragsverarbeiter informiert den Verantwortlichen mindestens 30 Tage im Voraus über beabsichtigte Änderungen bei Unterauftragsverarbeitern.
6. Internationale Datenübermittlungen
Übermittlungen personenbezogener Daten aus der EU/EWR in die USA unterliegen Standardvertragsklauseln gemäß Durchführungsbeschluss (EU) 2021/914, Modul 2 (Verantwortlicher zu Auftragsverarbeiter), die hiermit in diesen AVV einbezogen werden. Eine unterzeichnete Kopie ist auf Anfrage erhältlich.
7. Technische und organisatorische Maßnahmen
- Verschlüsselung während der Übertragung: TLS 1.2 oder höher
- Isolation: Jede Anwendung läuft in einem isolierten Docker-Container
- Zugriffskontrolle: Rollenbasierter Zugang; SSH-Schlüsseln-Authentifizierung
- Patch-Management: Regelmäßige Sicherheitsupdates für Betriebssystem und Laufzeitabhängigkeiten
- Incident Response: Dokumentiertes Verfahren zur Erkennung und Reaktion auf Vorfälle
8. Meldung von Datenpannen
Der Auftragsverarbeiter meldet Datenpannen unverzüglich und in jedem Fall innerhalb von 72 Stunden nach Bekanntwerden an den Verantwortlichen, mit Angaben zu Art, betroffenen Personen, Datensätzen, wahrscheinlichen Folgen und ergriffenen Maßnahmen.
9. Auditrechte
Nach 30-tägiger schriftlicher Ankündigung, höchstens einmal pro Kalenderjahr, kann der Verantwortliche: (a) einen Sicherheitsfragebogen anfordern; (b) Zugang zu relevanten Audit-Logs und Dokumentationen erhalten.
10. Beendigung
Nach Beendigung des Servicevertrags löscht der Auftragsverarbeiter alle personenbezogenen Daten der Endnutzer des Verantwortlichen innerhalb von 30 Tagen und bestätigt dies schriftlich.
Ovaj Ugovor o obradi podataka ("DPA") zaključuje se između vas kao rukovaoca podacima ("Rukovalac") i Octagon Solutions LLC, Florida, SAD ("Obrađivač") te čini sastavni dio Uvjeta korištenja OctaDeployja. Kada OctaDeploy koristite za hosting aplikacija koje obrađuju osobne podatke trećih osoba (vaših krajnjih korisnika), ovaj DPA uređuje tu obradu.
1. Definicije
"Osobni podaci", "Subjekt podataka", "Obrada", "Rukovalac", "Obrađivač", "Podobrađivač" i "Nadzorno tijelo" imaju značenja dodijeljena im u EU Općoj uredbi o zaštiti podataka (GDPR) 2016/679.
2. Pojedinosti obrade
- Kategorije subjekata podataka: Krajnji korisnici i posjetitelji aplikacija Rukovaoca deployanih na OctaDeployu
- Vrste osobnih podataka: Svi osobni podaci koje krajnji korisnici dostavljaju aplikacijama Rukovaoca; OctaDeploy ne propisuje ni ne zna kategorije — Rukovalac određuje koje podatke njegova aplikacija prikuplja
- Svrha i priroda obrade: Pružanje računalnih, pohranjivih, mrežnih i srodnih usluga infrastrukturnog hostinga za aplikacije Rukovaoca
- Trajanje obrade: Za trajanje ugovora o servisu i 30 dana nakon raskida
3. Obveze Rukovaoca
Rukovalac osigurava da: (a) ima pravnu osnovu za obradu osobnih podataka; (b) subjekti podataka su obaviješteni o obradi; (c) dane upute Obrađivaču su zakonite; (d) je implementirao odgovarajuće sigurnosne mjere na razini aplikacije.
4. Obveze Obrađivača
Obrađivač će:
- Obrađivati osobne podatke samo temeljem dokumentiranih uputa Rukovaoca
- Osigurati da su osobe ovlaštene za obradu vezane obvezama povjerljivosti
- Implementirati i održavati odgovarajuće tehničke i organizacijske sigurnosne mjere (vidi Odjeljak 7)
- Pomagati Rukovaocu u ispunjavanju obveza prema subjektima podataka (čl. 15–21 GDPR-a)
- Obavijestiti Rukovaoca ako smatra da uputa krši primjenjivo pravo zaštite podataka
- Izbrisati ili vratiti sve osobne podatke po raskidu i pismeno to potvrditi
5. Podobrađivači
Rukovalac daje opće odobrenje za angažiranje sljedećih podobrađivača:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Njemačka — namjenska serverska infrastruktura (EU)
Obrađivač će obavijestiti Rukovaoca najmanje 30 dana unaprijed o namjeravanim promjenama podobrađivača.
6. Međunarodni prijenosi podataka
Prijenosi osobnih podataka iz EU/EEP-a u SAD uređeni su standardnim ugovornim klauzulama temeljem Provedbene odluke Komisije (EU) 2021/914, Modul 2 (Rukovalac prema Obrađivaču), koje su ovim uključene u ovaj DPA uputom. Potpisana kopija dostupna je na pisani zahtjev.
7. Tehničke i organizacijske sigurnosne mjere
- Enkripcija u prijenosu: TLS 1.2 ili viši za sve veze
- Izolacija: Svaka aplikacija radi u izolovanom Docker kontejneru
- Kontrola pristupa: Pristup zasnovan na ulogama; SSH autentifikacija ključevima
- Upravljanje zakrpama: Redovita primjena sigurnosnih zakrpa na OS i runtime ovisnosti
- Odgovor na incidente: Dokumentirana procedura za detekciju i odgovor na incidente
8. Obavijest o povredi osobnih podataka
Obrađivač će obavijestiti Rukovaoca bez nepotrebnog odgađanja i u svakom slučaju u roku od 72 sata od saznanja o povredi osobnih podataka koja utječe na Rukovaočeve podatke.
9. Pravo na reviziju
Po pisanoj obavijesti od 30 dana, jednom godišnje, Rukovalac može zatražiti: (a) popunjavanje sigurnosnog upitnika; (b) pristup relevantnim revizijskim logovima i dokumentaciji.
10. Raskid
Po raskidu ugovora o servisu, Obrađivač će izbrisati sve osobne podatke krajnjih korisnika Rukovaoca u roku od 30 dana i pismeno to potvrditi.