Data Processing Agreement

Erstellt am 26 Mai, 2026Legal Documents • 8 Minuten gelesen

Data processing agreement between SendVault and registered users — governing how we handle personal data on your behalf under GDPR Art. 28.

Legal Information

Data Processing Agreement

jog690.link · jog690.cloud · jog690.social Web Solution Jog690 S.R.L. August 2026
Note: This Data Processing Agreement applies uniformly to all SaaS platforms operated by Web Solution Jog690 S.R.L. under the domains jog690.link, jog690.cloud, and jog690.social (each a "Platform", collectively the "Platforms"). Where a provision refers to "the Platform", it applies individually to whichever Platform the Controller has registered on — a Controller using more than one Platform is bound by this DPA separately for each.
01

Preamble & Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Web Solution Jog690 S.R.L. ("Processor", "we") and the registered user of any of the Platforms listed above ("Controller", "you").

It governs the processing of personal data of your end users (visitors, recipients, or other third parties interacting with your account on a Platform) carried out by us on your behalf pursuant to Art. 28 GDPR. In the event of conflict, this DPA takes precedence over the respective Platform's Terms of Service with respect to data protection matters.

By using any Platform you accept this DPA for that Platform. A signed copy can be downloaded below.

↓ Download DPA as PDF
02

Definitions

  • "Platform" – any SaaS service operated by the Processor under the domains jog690.link, jog690.cloud, or jog690.social.
  • "Controller" – the registered user who determines the purposes and means of processing personal data of their end users on a Platform.
  • "Processor" – Web Solution Jog690 S.R.L., operating the Platforms.
  • "Customer Data" – personal data of end users processed by the Processor on behalf of the Controller via a Platform.
  • "Sub-Processor" – any third party engaged by the Processor to process Customer Data.
  • "Security Incident" – any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
  • "GDPR" – EU Regulation 2016/679 and any applicable national implementations.
03

Nature of Processing

The Processor processes Customer Data solely to operate and provide the respective Platform in accordance with its Terms of Service and the Controller's instructions. No processing beyond this scope takes place without a separate written instruction. Processing under each Platform is carried out independently; data collected on one Platform is not used for purposes of another Platform unless explicitly agreed.

The Controller is solely responsible for ensuring a valid legal basis for any processing of personal data they initiate via a Platform (e.g. through tracking pixels, embedded scripts, contact forms, or similar features).

04

Obligations of the Processor

Confidentiality

The Processor ensures that all personnel authorized to process Customer Data are bound by confidentiality obligations and access Customer Data only to the extent necessary for their tasks.

Instructions

The Processor processes Customer Data only on documented instructions from the Controller. If required by EU or national law to process beyond those instructions, the Processor will inform the Controller in advance unless legally prohibited.

Assistance

The Processor will assist the Controller in fulfilling obligations under the GDPR, including responding to data subject requests, data protection impact assessments, and breach notifications.

05

Sub-Processors

The Controller hereby grants general authorization for the engagement of the following sub-processors, which are used across all Platforms unless otherwise noted:

Provider Location Purpose Status
INWX GmbH & Co. KG
Prinzessinnenstr. 30, 10969 Berlin, Germany
Germany Domain registration Active
Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Germany
Germany / EU Platform hosting Active
Cloudflare, Inc.
101 Townsend St., San Francisco, CA 94107, USA
USA (R2 storage, EU-restricted) Cloud storage, backups, CDN, DNS & bot protection (Cloudflare R2 & Cloudflare Turnstile) Active

The Processor will notify the Controller at least 30 days in advance before adding a new sub-processor. The Controller may object in writing within 14 days if there are demonstrable compliance concerns. If the objection cannot be resolved, the Controller may terminate the affected Platform's contract with 90 days' notice.

The Processor ensures each sub-processor is bound by data protection obligations equivalent to those in this DPA.

06

Data Subject Rights

The Processor will promptly notify the Controller of any requests received from data subjects regarding Customer Data and will not respond directly to such requests without the Controller's instruction, unless required by law.

The Processor will provide reasonable technical assistance to enable the Controller to fulfill data subject rights (access, rectification, erasure, restriction, portability) within the relevant Platform.

07

Security

The Processor implements appropriate technical and organizational measures pursuant to Art. 32 GDPR across all Platforms, including:

  • SSL/TLS encryption for all data in transit
  • Access control and user authentication
  • Role-based access restrictions for personnel
  • Regular backups and recovery testing
  • Confidentiality agreements with all personnel with data access
  • Logging of access and system events

In the event of a Security Incident, the Processor will notify the affected Controller(s) within 72 hours of becoming aware, investigate the incident, and take remedial action. Only Controllers on the affected Platform will be notified.

08

International Data Transfers

Where Customer Data is transferred outside the EEA, the Processor ensures an adequate level of protection through one of the following mechanisms:

  • EU Commission adequacy decision for the destination country
  • EU Standard Contractual Clauses (SCCs) with the sub-processor
  • Certification under the EU-US Data Privacy Framework (where applicable)

Cloudflare, Inc. (USA) – transfer covered by EU Standard Contractual Clauses. Object storage (Cloudflare R2) is additionally restricted to EU data centers via Cloudflare's Jurisdictional Restrictions, so file/object data does not leave the EU regardless of the underlying corporate entity's location.

09

Term & Deletion

This DPA remains in force for the duration of the Controller's account on the respective Platform. Upon termination of an account, the Processor will delete all Customer Data related to that Platform within 90 days, including data held by sub-processors, unless statutory retention obligations require otherwise. Termination of an account on one Platform does not affect the Controller's data or accounts on other Platforms.

The Controller may request written confirmation of deletion.

10

Annex – Processing Details (Art. 28(3) GDPR)

Subject Matter & Duration

Operation of the respective jog690.link, jog690.cloud, or jog690.social SaaS platform for the duration of the Controller's account on that Platform.

Nature & Purpose

Hosting, storage, and transmission of data to provide each Platform's core features (e.g. biolink pages and URL shortening on jog690.link; file transfer and storage on jog690.cloud; social/community features on jog690.social), including related analytics and account management functionality.

Types of Personal Data

  • End user IP addresses (anonymized in analytics)
  • Browser and device information
  • Referrer URLs and click/access data
  • Any data embedded or collected by the Controller via pixels, scripts, forms, or platform-specific features

Categories of Data Subjects

Visitors, recipients, and other end users interacting with the Controller's account, page, or content on the respective Platform.

Controller Obligations

The Controller is responsible for ensuring a valid legal basis for all processing of end user data they initiate via a Platform, including maintaining their own privacy policy and obtaining any required consents.

Processor: Web Solution Jog690 S.R.L.

Strada Ion Slavici, Nr. 13 Cam. Nr. 1, Scara B, Ap. 18, 300539 Timișoara, Romania

Email: office@jog690.eu  ·  VAT: RO38794995

↓ Download DPA as PDF