Data Processing Agreement

Last updated: [DATE] · Effective from: [DATE]

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Ptolemy Technologies Ltd, trading as Servano (“Servano”, “we”, the “Processor”) and the customer accepting those Terms (the “Customer”, the “Controller”). It applies automatically to every plan whenever the Customer’s use of the Service involves personal data governed by Regulation (EU) 2016/679 (“GDPR”) or the UK GDPR. No separate signature is required; a signed copy is available on request.

1. Roles

For the personal data contained in the applications, databases, files and logs that the Customer deploys or stores on the Service (“Customer Data”), the Customer is the controller and Servano is the processor. Servano processes Customer Data only on the Customer’s documented instructions as set out in this DPA and the Terms.

For data about the Customer itself (account, billing, support), Servano is an independent controller and the Privacy Policy applies instead.

2. Details of processing (Annex I)

ItemDescription
Subject matterHosting, building, running and storing the Customer's applications, static sites, databases and related data.
DurationFor the term of the Customer's account, plus the deletion period in section 9.
Nature and purposeStorage, execution, transmission and backup of Customer Data as needed to provide the Service. No analysis or use for Servano's own purposes.
Categories of data subjectsDetermined by the Customer — typically the Customer's own end users, customers, employees or contacts.
Categories of personal dataDetermined by the Customer — any personal data the Customer's applications process, including identifiers, contact details, content and technical data such as IP addresses in logs.
Special categoriesNot intended. The Customer must not process special-category data (Art. 9 GDPR) on the Service without prior written agreement.

3. Servano's obligations

Servano shall:

  • process Customer Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by EU, Member State or UK law — in which case Servano will inform the Customer before processing, unless the law prohibits this;
  • ensure that persons authorised to process Customer Data are bound by confidentiality obligations;
  • implement the technical and organisational measures in section 6 (Annex II);
  • respect the conditions in section 5 for engaging sub-processors;
  • assist the Customer, by appropriate technical and organisational measures and insofar as possible, in responding to data-subject requests (section 8);
  • assist the Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, impact assessments), taking into account the nature of the processing and the information available to Servano;
  • delete or return all Customer Data at the end of the Service as set out in section 9;
  • make available all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as set out in section 10;
  • inform the Customer immediately if, in Servano's opinion, an instruction infringes the GDPR or other applicable data-protection law.

4. Customer's obligations

The Customer warrants that it:

  • has a lawful basis for the processing of Customer Data and has provided all required notices to data subjects;
  • is entitled to transfer Customer Data to Servano for processing under this DPA;
  • will not upload data that it is not permitted to process on infrastructure of the kind described in section 6;
  • remains responsible for the security of its own application code, credentials and access management within its account.

5. Sub-processors

The Customer gives general authorisation for Servano to engage the sub-processors listed at servano.io/legal/subprocessors. Servano imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains fully liable to the Customer for their performance.

Servano will notify the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees.

Static-site hosting runs on infrastructure owned and operated by Servano in Athens, Greece, and is not a sub-processing arrangement.

6. Security measures (Annex II)

Customer Data is stored exclusively on servers located in the European Union (Helsinki, Finland; Athens, Greece). Servano applies the following measures, reviewed at least annually:

  • encryption in transit (TLS 1.2 or higher) for all connections to the Service, with certificates issued and renewed automatically;
  • encryption at rest: every volume holding customer data or container images is encrypted with LUKS2 (AES-XTS-512), and environment variables are additionally encrypted with AES-256-GCM before storage;
  • administrative access to production systems only over SSH with key-based authentication; password authentication disabled; access restricted to named personnel on a need-to-know basis;
  • host firewalls, automated intrusion prevention and automatic security updates on all production systems;
  • logical isolation between customer workloads at the container level and per-customer storage quotas;
  • daily backups, encrypted before they leave the server and retained within the EU on separate infrastructure, written to an append-only target so that a compromised production host cannot delete them; restores are tested automatically every month;
  • audit logging of privileged actions in the control plane, including every reveal of a stored secret;
  • redundant storage (RAID 1) and uninterruptible power on self-operated infrastructure.

7. International transfers

Customer Data at rest remains in the European Union. Ptolemy Technologies Ltd is established in the United Kingdom; remote administrative and support access from the UK relies on the European Commission’s adequacy decision for the United Kingdom. Where a sub-processor is located outside the EU/EEA, transfers are covered by the EU Standard Contractual Clauses or another mechanism permitted under Chapter V GDPR, as stated on the sub-processor list. Should an adequacy decision relied upon lapse, Servano will implement Standard Contractual Clauses without interruption to the Service.

8. Data subject requests

Servano does not respond directly to data subjects regarding Customer Data. If Servano receives such a request, it will forward it to the Customer without undue delay and, taking into account the nature of the processing, assist the Customer in fulfilling it — primarily through the Customer’s own access to its applications and databases on the Service.

9. Personal data breach

Servano will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available.

10. Deletion and return

On termination of the account, or on the Customer’s deletion of a project, Servano will delete the corresponding Customer Data within 30 days; copies in backups are overwritten within 35 days on the standard rotation. Until deletion, the Customer may export its data through the Service. Servano may retain data where EU, Member State or UK law requires it, and will inform the Customer of any such requirement. Written confirmation of deletion is available on request.

11. Audits

Servano will make available the information necessary to demonstrate compliance with this DPA, including this document, the sub-processor list and a description of the security measures. Where this is insufficient to meet a legal requirement, the Customer may conduct an audit — once per 12 months, on 30 days’ written notice, during business hours, by the Customer or an independent auditor bound by confidentiality, without unreasonable disruption to the Service and at the Customer’s cost.

12. Liability and precedence

The limitations of liability in the Terms of Service apply to this DPA, except where they conflict with mandatory data-protection law. In case of conflict between this DPA and the Terms, this DPA prevails with regard to the processing of Customer Data.

13. Term

This DPA takes effect when the Customer accepts the Terms and remains in force for as long as Servano processes Customer Data, including the deletion period in section 10.

14. Contact

Ptolemy Technologies Ltd, [REGISTERED OFFICE ADDRESS], London, United Kingdom
Data-protection matters: privacy@servano.io
EU representative (Art. 27 GDPR): [EU REPRESENTATIVE NAME AND CONTACT]