Skip to content

Data Processing Agreement (DPA)

Last updated: 14 July 2026

This Data Processing Agreement ("DPA") supplements the Terms of Service and governs the processing of personal data that Dverse Studio ("Processor") carries out on behalf of the Customer ("Controller") in providing the Service, pursuant to Art. 28 GDPR. This is a draft provided for informational purposes and subject to legal review.

1. Subject matter and duration

The Processor processes the personal data of the Controller's end customers solely to provide the Service, for the duration of the contract. Upon termination, data is handled as set out in the Terms of Service.

2. Roles

The Customer acts as independent Controller for the data of its own end customers. The Provider acts as Processor, processing data solely on the Controller's documented instructions.

3. Security measures

The Provider implements appropriate technical and organizational measures pursuant to Art. 32 GDPR: encryption of data in transit, per-tenant data isolation (database-level row-level security), restricted and logged administrative access, periodic backups.

4. Sub-processors

The Provider engages the following sub-processors, bound by the same safeguards set out in this DPA:

Hetzner Online GmbH — infrastructure hosting (servers, database, storage) — Germany (EU).

Stripe Payments Europe Ltd — payment processing and billing — Ireland (EU).

Cloudflare, Inc. — DNS, CDN, network delivery and security — United States, based on Standard Contractual Clauses (SCC).

Zoho Corporation — transactional email delivery — European Union.

The Provider will inform the Controller of any addition or replacement of sub-processors, giving the Controller the opportunity to object on legitimate grounds.

5. Assistance to the Controller

The Provider assists the Controller, within reasonable limits, in ensuring compliance with obligations relating to security of processing, data breach notification, impact assessments, and responding to data subject requests.

6. Deletion upon termination

Upon termination of the contract, at the Controller's request, the Provider deletes or returns all personal data processed on its behalf, unless retention is required by applicable law.

7. Contact

For any request relating to this DPA, please write to [email protected].