Data processing agreement

Last updated 9 October 2026

What this agreement covers

This agreement forms part of the Master service agreement, or of the Terms of service on the Free plan, and applies whenever easythings processes personal data on a customer's behalf. It sets out the terms Article 28 of the General Data Protection Regulation (GDPR) requires. The customer is the controller of that data and easythings is its processor. For the data we collect through this website, and to run our own customer accounts and billing, we are a controller instead, as our Privacy policy explains.

What we process, by where the service runs

In cloud we provision, we host the customer's tools and process:

Self-hosted, the tools and their data stay in the customer's own cloud account, and easythings has no access to them. We process platform data only. The customer's cloud provider is the customer's own processor, not ours.

Details of the processing

Our commitments

Security measures

Sub-processors

The customer authorizes us to use these sub-processors for the service in cloud we provision:

Each is bound by written terms that protect personal data at least as well as this agreement, and we remain responsible for them. We announce a new sub-processor at least 30 days before it starts. The customer may object within that time on reasonable data protection grounds; if we cannot resolve the objection, the customer may end the affected service and we refund fees prepaid for the period not yet used.

Where the data is

In cloud we provision, data is stored in the European Union. DigitalOcean is a United States company, so its access to that data may be a transfer outside the European Union; it relies on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. Self-hosted, tool data stays wherever the customer's cloud account keeps it.

Security incidents

We notify the customer within 48 hours of becoming aware of a breach affecting its personal data, with what we know at that point: what happened, the data and people likely affected, and what we are doing about it. We keep the customer informed as we learn more, so it can meet its own 72-hour duty to the supervisory authority.

Audits

We make available the information needed to show we comply with this agreement. Once a year, or after a breach, the customer may audit that compliance itself or through an independent auditor bound by confidentiality, with 30 days' notice and at its own cost.

Return and deletion

The customer can export its data at any time during the term and for 30 days after it ends. We then delete the personal data we hold for the customer within 30 days, unless the law requires us to keep it. Self-hosted, we never hold tool data, so this applies to platform data only.

Liability and law

Liability under this agreement follows the limits in the Master service agreement, except where the GDPR does not allow them. Portuguese law governs this agreement and the courts of Lisbon decide any dispute.

Contact

Questions about this agreement? Contact us on WhatsApp.