Data Processing Addendum
1. Roles
When you deploy applications and databases, they may contain personal data of your own users. For that data you are the controller and DebutDeploy is your processor. This Addendum ("DPA") applies to that processing and supplements our Terms of Service. Where UK GDPR or EU GDPR applies, this DPA is intended to satisfy Article 28.
2. Scope of processing
Subject matter: hosting and operating your applications and databases. Duration: for the term of your account. Nature and purpose: storage, compute, backup, and transmission as directed by you through the Service. Data types and subjects: determined by you — whatever your workloads contain.
3. Our commitments
- Process personal data only on your documented instructions (using the Service is your instruction), including as regards international transfers, unless law requires otherwise.
- Immediately inform you if, in our opinion, an instruction infringes UK GDPR, EU GDPR, or other applicable data protection law.
- Ensure people authorised to process it are under confidentiality obligations.
- Apply appropriate technical and organisational security measures (see Security).
- Assist you, so far as reasonable, with data subject requests, security, breach notification, and DPIAs.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data.
- At your choice, delete or return all personal data at the end of the service and delete existing copies, unless law requires us to retain them.
- Make available all information necessary to demonstrate compliance with these obligations, and allow for and contribute to audits and inspections conducted by you or an auditor you mandate, on reasonable notice and subject to confidentiality.
4. Subprocessors
You authorise us to use the subprocessors below to deliver the Service. We impose on each subprocessor data-protection obligations materially equivalent to those in this DPA (as required by Article 28(4)), and we remain fully responsible to you for their performance. We will give you at least 30 days' notice before adding or replacing a subprocessor so you can object on reasonable data-protection grounds; if we cannot resolve a legitimate objection, you may terminate the affected part of the Service.
Subprocessor register
| Subprocessor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud compute, storage & networking (where your apps and databases run) | Germany & Finland (EU) |
| Stripe, Inc. / Stripe Payments Europe | Payment processing & billing | EU & USA |
| GitHub, Inc. | OAuth sign-in & source-repository access for deploys | USA |
| Google LLC | OAuth sign-in | USA |
[Email/notification provider] | Transactional email [confirm if used] | [region] |
5. International transfers
Where a subprocessor processes personal data outside the UK/EEA — currently Stripe, GitHub, and Google in the United States — the transfer is made under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (IDTA), supported by a transfer risk assessment that we maintain and keep under review. [Counsel to confirm the per-vendor mechanism and whether to also rely on the EU-US / UK Data Privacy Framework.]
6. Contact
To exercise rights under this DPA or raise a subprocessor objection: privacy@debutdepoly.com. [Have counsel confirm this DPA and whether a signed version is offered to customers.]