Legal

Data Processing Agreement

This DPA forms part of the Terms of Service between Sawyglobe LLC ("Hostkeplo", the "Processor") and the Customer (the "Controller"). It governs processing of personal data carried out by Hostkeplo on the Customer's behalf under the EU General Data Protection Regulation 2016/679 ("GDPR").

Last updated: June 22, 2026 · Version: 1.0


1. Roles and scope

1.1 The Customer is the controller (or processor acting for a third-party controller) and Hostkeplo is the processor of personal data contained in Customer Content processed via the Services. 1.2 Hostkeplo processes personal data only on documented instructions from the Customer, including those set out in this DPA and the Terms, unless required by EU/Member State law (in which case Hostkeplo informs the Customer unless legally prohibited).

2. Subject matter, duration, nature and purpose

3. Processor obligations

Hostkeplo will: 1. process personal data only per the Customer's documented instructions (Section 1.2); 2. ensure persons authorised to process data are bound by confidentiality; 3. implement appropriate technical and organisational measures (Section 6 / Annex 2); 4. respect the conditions for engaging sub-processors (Section 4); 5. assist the Customer, taking into account the nature of processing, in responding to data subject requests (Section 5); 6. assist the Customer with security, breach notification, data protection impact assessments and prior consultation (Articles 32–36 GDPR); 7. at the Customer's choice, delete or return personal data after the end of the Services (Section 9); 8. make available information necessary to demonstrate compliance and allow for audits (Section 8).

4. Sub-processors

4.1 The Customer provides general authorisation for Hostkeplo to engage sub-processors listed in Annex 3 (e.g. the data-center/IaaS provider). 4.2 Hostkeplo will impose data-protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible for their performance. 4.3 Hostkeplo will give at least 30 days' notice of intended additions or replacements of sub-processors, allowing the Customer to object on reasonable data-protection grounds.

5. Data subject rights

Hostkeplo will, by appropriate technical and organisational measures and insofar as possible, assist the Customer in fulfilling its obligation to respond to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection). Requests Hostkeplo receives directly will be forwarded to the Customer without undue delay.

6. Security

Hostkeplo implements measures appropriate to the risk, including those in Annex 2 — e.g. encryption in transit (TLS), access controls, network firewalls and intrusion prevention, daily backups, patch management, logging and monitoring, and physical security provided by EU data-center operators.

7. Personal data breach

Hostkeplo will notify the Customer without undue delay and within 48 hours of becoming aware of a personal data breach affecting Customer personal data, providing the information reasonably available to enable the Customer to meet its own notification obligations under Articles 33–34 GDPR.

8. Audits

Hostkeplo will make available information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by the Customer or an auditor it mandates, on reasonable prior notice, no more than once per year (or after a breach), subject to confidentiality and not unreasonably disrupting operations. Where available, third-party certifications/reports (e.g. ISO 27001 of sub-processors) may be provided to satisfy audit requests.

9. Return or deletion

On termination of the Services, Hostkeplo will, at the Customer's choice, delete or return all personal data and delete existing copies within 14 days, unless EU/Member State law requires storage. Backup copies are deleted on their normal rotation cycle.

10. International transfers

Personal data is processed within the EU/EEA. If any transfer outside the EEA becomes necessary, Hostkeplo will ensure an appropriate transfer mechanism under Chapter V GDPR (e.g. adequacy decision or Standard Contractual Clauses) is in place before transferring.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms, to the extent permitted by law. In case of conflict between this DPA and the Terms regarding data protection, this DPA prevails.


Annex 1 — Details of processing

Annex 2 — Technical and organisational measures

Annex 3 — Approved sub-processors

Sub-processor Role Location
IONOS SE IaaS / data-center (compute, storage, network) EU (Germany)
Stripe Payment processing (billing data) US (Standard Contractual Clauses)

(Keep this list accurate. Notify customers before adding or changing sub-processors per Section 4.3.)


Signatures

For the Customer (Controller): ___ Name: _ Date: For Hostkeplo (Processor): ___ Name: _ Date: ______