Data processing agreement between SendVault and registered users — governing how we handle personal data on your behalf under GDPR Art. 28.
Data Processing Agreement
Preamble & Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Web Solution Jog690 S.R.L. ("Processor", "we") and the registered user of any of the Platforms listed above ("Controller", "you").
It governs the processing of personal data of your end users (visitors, recipients, or other third parties interacting with your account on a Platform) carried out by us on your behalf pursuant to Art. 28 GDPR. In the event of conflict, this DPA takes precedence over the respective Platform's Terms of Service with respect to data protection matters.
By using any Platform you accept this DPA for that Platform. A signed copy can be downloaded below.
↓ Download DPA as PDFDefinitions
- "Platform" – any SaaS service operated by the Processor under the domains jog690.link, jog690.cloud, or jog690.social.
- "Controller" – the registered user who determines the purposes and means of processing personal data of their end users on a Platform.
- "Processor" – Web Solution Jog690 S.R.L., operating the Platforms.
- "Customer Data" – personal data of end users processed by the Processor on behalf of the Controller via a Platform.
- "Sub-Processor" – any third party engaged by the Processor to process Customer Data.
- "Security Incident" – any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
- "GDPR" – EU Regulation 2016/679 and any applicable national implementations.
Nature of Processing
The Processor processes Customer Data solely to operate and provide the respective Platform in accordance with its Terms of Service and the Controller's instructions. No processing beyond this scope takes place without a separate written instruction. Processing under each Platform is carried out independently; data collected on one Platform is not used for purposes of another Platform unless explicitly agreed.
The Controller is solely responsible for ensuring a valid legal basis for any processing of personal data they initiate via a Platform (e.g. through tracking pixels, embedded scripts, contact forms, or similar features).
Obligations of the Processor
Confidentiality
The Processor ensures that all personnel authorized to process Customer Data are bound by confidentiality obligations and access Customer Data only to the extent necessary for their tasks.
Instructions
The Processor processes Customer Data only on documented instructions from the Controller. If required by EU or national law to process beyond those instructions, the Processor will inform the Controller in advance unless legally prohibited.
Assistance
The Processor will assist the Controller in fulfilling obligations under the GDPR, including responding to data subject requests, data protection impact assessments, and breach notifications.
Sub-Processors
The Controller hereby grants general authorization for the engagement of the following sub-processors, which are used across all Platforms unless otherwise noted:
| Provider | Location | Purpose | Status |
|---|---|---|---|
| INWX GmbH & Co. KG Prinzessinnenstr. 30, 10969 Berlin, Germany |
Germany | Domain registration | Active |
| Hetzner Online GmbH Industriestr. 25, 91710 Gunzenhausen, Germany |
Germany / EU | Platform hosting | Active |
| Cloudflare, Inc. 101 Townsend St., San Francisco, CA 94107, USA |
USA (R2 storage, EU-restricted) | Cloud storage, backups, CDN, DNS & bot protection (Cloudflare R2 & Cloudflare Turnstile) | Active |
The Processor will notify the Controller at least 30 days in advance before adding a new sub-processor. The Controller may object in writing within 14 days if there are demonstrable compliance concerns. If the objection cannot be resolved, the Controller may terminate the affected Platform's contract with 90 days' notice.
The Processor ensures each sub-processor is bound by data protection obligations equivalent to those in this DPA.
Data Subject Rights
The Processor will promptly notify the Controller of any requests received from data subjects regarding Customer Data and will not respond directly to such requests without the Controller's instruction, unless required by law.
The Processor will provide reasonable technical assistance to enable the Controller to fulfill data subject rights (access, rectification, erasure, restriction, portability) within the relevant Platform.
Security
The Processor implements appropriate technical and organizational measures pursuant to Art. 32 GDPR across all Platforms, including:
- SSL/TLS encryption for all data in transit
- Access control and user authentication
- Role-based access restrictions for personnel
- Regular backups and recovery testing
- Confidentiality agreements with all personnel with data access
- Logging of access and system events
In the event of a Security Incident, the Processor will notify the affected Controller(s) within 72 hours of becoming aware, investigate the incident, and take remedial action. Only Controllers on the affected Platform will be notified.
International Data Transfers
Where Customer Data is transferred outside the EEA, the Processor ensures an adequate level of protection through one of the following mechanisms:
- EU Commission adequacy decision for the destination country
- EU Standard Contractual Clauses (SCCs) with the sub-processor
- Certification under the EU-US Data Privacy Framework (where applicable)
Cloudflare, Inc. (USA) – transfer covered by EU Standard Contractual Clauses. Object storage (Cloudflare R2) is additionally restricted to EU data centers via Cloudflare's Jurisdictional Restrictions, so file/object data does not leave the EU regardless of the underlying corporate entity's location.
Term & Deletion
This DPA remains in force for the duration of the Controller's account on the respective Platform. Upon termination of an account, the Processor will delete all Customer Data related to that Platform within 90 days, including data held by sub-processors, unless statutory retention obligations require otherwise. Termination of an account on one Platform does not affect the Controller's data or accounts on other Platforms.
The Controller may request written confirmation of deletion.
Annex – Processing Details (Art. 28(3) GDPR)
Subject Matter & Duration
Operation of the respective jog690.link, jog690.cloud, or jog690.social SaaS platform for the duration of the Controller's account on that Platform.
Nature & Purpose
Hosting, storage, and transmission of data to provide each Platform's core features (e.g. biolink pages and URL shortening on jog690.link; file transfer and storage on jog690.cloud; social/community features on jog690.social), including related analytics and account management functionality.
Types of Personal Data
- End user IP addresses (anonymized in analytics)
- Browser and device information
- Referrer URLs and click/access data
- Any data embedded or collected by the Controller via pixels, scripts, forms, or platform-specific features
Categories of Data Subjects
Visitors, recipients, and other end users interacting with the Controller's account, page, or content on the respective Platform.
Controller Obligations
The Controller is responsible for ensuring a valid legal basis for all processing of end user data they initiate via a Platform, including maintaining their own privacy policy and obtaining any required consents.
Processor: Web Solution Jog690 S.R.L.
Strada Ion Slavici, Nr. 13 Cam. Nr. 1, Scara B, Ap. 18, 300539 Timișoara, Romania
Email: office@jog690.eu · VAT: RO38794995