Data Processing Agreement (DPA)
Last updated: 14 July 2026
This Data Processing Agreement ("DPA") supplements the Terms of Service and governs the processing of personal data that Dverse Studio ("Processor") carries out on behalf of the Customer ("Controller") in providing the Service, pursuant to Art. 28 GDPR. This is a draft provided for informational purposes and subject to legal review.
1. Subject matter and duration
The Processor processes the personal data of the Controller's end customers solely to provide the Service, for the duration of the contract. Upon termination, data is handled as set out in the Terms of Service.
2. Roles
The Customer acts as independent Controller for the data of its own end customers. The Provider acts as Processor, processing data solely on the Controller's documented instructions.
3. Security measures
The Provider implements appropriate technical and organizational measures pursuant to Art. 32 GDPR: encryption of data in transit, per-tenant data isolation (database-level row-level security), restricted and logged administrative access, periodic backups.
4. Sub-processors
The Provider engages the following sub-processors, bound by the same safeguards set out in this DPA:
Hetzner Online GmbH — infrastructure hosting (servers, database, storage) — Germany (EU).
Stripe Payments Europe Ltd — payment processing and billing — Ireland (EU).
Cloudflare, Inc. — DNS, CDN, network delivery and security — United States, based on Standard Contractual Clauses (SCC).
Zoho Corporation — transactional email delivery — European Union.
The Provider will inform the Controller of any addition or replacement of sub-processors, giving the Controller the opportunity to object on legitimate grounds.
5. Assistance to the Controller
The Provider assists the Controller, within reasonable limits, in ensuring compliance with obligations relating to security of processing, data breach notification, impact assessments, and responding to data subject requests.
6. Deletion upon termination
Upon termination of the contract, at the Controller's request, the Provider deletes or returns all personal data processed on its behalf, unless retention is required by applicable law.
7. Contact
For any request relating to this DPA, please write to [email protected].