Data processing agreement
Last updated 9 October 2026
What this agreement covers
This agreement forms part of the Master service agreement, or of the Terms of service on the Free plan, and applies whenever easythings processes personal data on a customer's behalf. It sets out the terms Article 28 of the General Data Protection Regulation (GDPR) requires. The customer is the controller of that data and easythings is its processor. For the data we collect through this website, and to run our own customer accounts and billing, we are a controller instead, as our Privacy policy explains.
What we process, by where the service runs
In cloud we provision, we host the customer's tools and process:
- tool data: whatever the customer's tools store and the people using them enter;
- platform data: users' names, work email addresses and identity provider identifiers, their roles, the record of who deployed or rolled back what and when, and access logs.
Self-hosted, the tools and their data stay in the customer's own cloud account, and easythings has no access to them. We process platform data only. The customer's cloud provider is the customer's own processor, not ours.
Details of the processing
- Purpose: hosting the customer's tools, signing people in, enforcing roles and keeping the deploy record.
- Data subjects: the customer's staff and contractors who use easythings, and anyone whose data the customer chooses to put in its tools.
- Duration: the term of the agreement, plus the deletion period below.
- Special categories of data: only if the customer chooses to put them in a tool, and the customer tells us in the order.
Our commitments
- We process personal data only on the customer's documented instructions: this agreement, the order and how the customer configures the service. We tell the customer if an instruction seems to break the law.
- Everyone at easythings with access to personal data is bound by confidentiality.
- We do not sell personal data, and do not use tool data for anything beyond providing the service.
- We help the customer respond to requests from data subjects, carry out impact assessments and consult the supervisory authority, where the service alone does not let it do so.
Security measures
- Data encrypted in transit with TLS 1.2 or later, and at rest.
- Each customer's tools and data isolated from every other customer's.
- Sign-in only through the customer's own identity provider, with roles that separate bringing a tool in from using one.
- Staff access to production on a least-privilege basis, logged and reviewed.
- A record of every deploy and rollback that the customer can review.
Sub-processors
The customer authorizes us to use these sub-processors for the service in cloud we provision:
- Amazon Web Services EMEA SARL (Luxembourg): cloud hosting and storage, in a European Union region;
- DigitalOcean, LLC (United States): cloud hosting and storage, in European Union data centres.
Each is bound by written terms that protect personal data at least as well as this agreement, and we remain responsible for them. We announce a new sub-processor at least 30 days before it starts. The customer may object within that time on reasonable data protection grounds; if we cannot resolve the objection, the customer may end the affected service and we refund fees prepaid for the period not yet used.
Where the data is
In cloud we provision, data is stored in the European Union. DigitalOcean is a United States company, so its access to that data may be a transfer outside the European Union; it relies on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. Self-hosted, tool data stays wherever the customer's cloud account keeps it.
Security incidents
We notify the customer within 48 hours of becoming aware of a breach affecting its personal data, with what we know at that point: what happened, the data and people likely affected, and what we are doing about it. We keep the customer informed as we learn more, so it can meet its own 72-hour duty to the supervisory authority.
Audits
We make available the information needed to show we comply with this agreement. Once a year, or after a breach, the customer may audit that compliance itself or through an independent auditor bound by confidentiality, with 30 days' notice and at its own cost.
Return and deletion
The customer can export its data at any time during the term and for 30 days after it ends. We then delete the personal data we hold for the customer within 30 days, unless the law requires us to keep it. Self-hosted, we never hold tool data, so this applies to platform data only.
Liability and law
Liability under this agreement follows the limits in the Master service agreement, except where the GDPR does not allow them. Portuguese law governs this agreement and the courts of Lisbon decide any dispute.
Contact
Questions about this agreement? Contact us on WhatsApp.