Standard Data Processing Terms (DPA)
"Völundr" Platform — https://volundr.dev
Version 1.0 · Effective date: 27 July 2026 · Draft pending legal review
These Standard Data Processing Terms ("DPA Terms") implement Article 28 of Regulation (EU) 2016/679 ("GDPR"). Capitalised terms not defined here have the meaning given to them in the Platform Terms of Service (the "Regulamin") available at https://volundr.dev/terms.
§ 1. Parties and scope
- These DPA Terms are concluded between: a) the Platform User who activates the Hosting Service and, through a hosted Application, processes personal data of that Application's end users — acting as the Controller; and b) the Service Provider (Usługodawca) as identified in § 1 of the Regulamin — acting as the Processor.
- In accordance with § 16 of the Regulamin, activation of the Hosting Service by a Controller who processes end users' personal data through a hosted Application is equivalent to concluding these DPA Terms. If the Controller does not process any personal data of end users through the hosted Application, these DPA Terms do not apply.
- These DPA Terms govern the processing by the Processor of personal data for which the Controller is responsible, carried out solely in connection with the provision of the Hosting Service.
§ 2. Subject matter, nature and purpose of processing
- Subject matter: hosting, storage and technical operation of the Controller's Application and its database on the Processor's infrastructure.
- Nature and purpose: storing and making available the Application and its data so that the Application functions; performing backups; technical maintenance strictly necessary to keep the Application running. The Processor does not use the entrusted data for its own purposes.
- Duration: for the duration of the active Hosting Service, and thereafter for the period set out in § 8 for return or deletion.
§ 3. Categories of data and data subjects
- Categories of data subjects: the end users of the Controller's Application, and any other natural persons whose personal data the Application collects or stores.
- Categories of personal data: determined solely by the Controller through the design and use of its Application. The Processor does not decide what data the Application collects. The categories may include, by way of example, identification and contact data, account credentials, and any content the end users submit to the Application.
- The Controller must not use the Application to process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR) unless it has separately confirmed in writing with the Processor that the Hosting Service is suitable for such processing.
§ 4. Obligations of the Processor
The Processor:
- processes the entrusted personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law; the Controller's instructions are set out in these DPA Terms, in the Regulamin, and in the configuration of the Hosting Service, and may be supplemented in a documented form;
- ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- implements the technical and organisational security measures required under Article 32 GDPR, described in § 6;
- respects the conditions for engaging sub-processors set out in § 5;
- taking into account the nature of the processing, assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR;
- assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment and prior consultation), taking into account the nature of the processing and the information available to the Processor;
- at the choice of the Controller, deletes or returns all the personal data after the end of the provision of the Hosting Service, as set out in § 8;
- makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allows for and contributes to audits, including inspections, on the terms set out in § 7;
- immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
§ 5. Sub-processors
- The Controller grants the Processor general written authorisation to engage sub-processors for the provision of the Hosting Service.
- At the date of these DPA Terms, the Processor uses the following sub-processors for the infrastructure on which Applications are hosted: a) Hetzner Online GmbH (Germany) — provision of the server infrastructure (data centres located within the EU/EEA); b) Cloudflare, Inc. — network, DNS and security services (traffic routing and TLS). An up-to-date list of sub-processors is available from the Processor on request at rodo@volundr.dev.
- The Processor imposes on each sub-processor, by contract, data-protection obligations equivalent to those set out in these DPA Terms, in particular sufficient guarantees to implement appropriate technical and organisational measures.
- The Processor informs the Controller of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Controller the opportunity to object to such changes. The Processor will provide such information via the Platform or by e-mail with reasonable notice.
- The Processor remains fully liable to the Controller for the performance of a sub-processor's obligations.
§ 6. Security of processing
- Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, the Processor implements appropriate technical and organisational measures, including as appropriate: a) access control to the infrastructure and administrative interfaces, restricted to authorised personnel; b) encryption of sensitive configuration data (e.g. credentials) at rest, and encryption in transit (TLS) for data reaching the Application over the public network; c) network isolation of hosted Applications and their databases; d) regular backups of the hosted database, with defined retention; e) logging of administrative access to the infrastructure; f) measures to restore the availability of and access to personal data in a timely manner in the event of an incident.
- The Processor regularly reviews the effectiveness of these measures and may update them, provided the level of protection is not reduced.
- The Controller acknowledges that the Hosting Service is provided on a single-server infrastructure without redundancy, as described in the Regulamin, and is itself responsible for assessing whether this level of availability is adequate for the data it processes.
§ 7. Audits
- The Processor makes available to the Controller, on request, the information necessary to demonstrate compliance with Article 28 GDPR.
- The Controller may carry out an audit no more than once per calendar year (and additionally after a personal data breach affecting the Controller's data), on reasonable prior notice of at least 14 days, during the Processor's business hours, in a manner that does not disproportionately disrupt the Processor's operations or compromise the security or confidentiality of other customers' data.
- Where an audit requires on-site inspection or significant effort, the Processor may charge the reasonable costs incurred.
§ 8. Return and deletion of data
- Upon termination of the Hosting Service for any reason, the Processor, at the Controller's choice expressed within 14 days, either returns the personal data (by making an export available) or deletes it.
- In the absence of the Controller's choice within that period, the Processor deletes the personal data and existing copies after the expiry of the grace period applicable to the Hosting Service under the Regulamin, unless Union or Member State law requires further storage.
- Backups are deleted in accordance with the ordinary backup-rotation cycle.
§ 9. Personal data breach
- The Processor notifies the Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Controller's data.
- The notification contains at least the information reasonably available to the Processor that enables the Controller to comply with its obligations under Articles 33 and 34 GDPR.
- Notifying the Controller of a breach is not an acknowledgement by the Processor of any fault or liability.
§ 10. International transfers
The Processor processes and stores the entrusted personal data within the European Economic Area. The Processor will not transfer the data to a third country without a valid legal transfer mechanism under Chapter V GDPR and, where required, the Controller's documented instruction.
§ 11. Liability and final provisions
- The liability of each party under these DPA Terms is subject to the limitations of liability set out in the Regulamin, to the extent permitted by law. Nothing in these DPA Terms limits either party's statutory liability towards data subjects or supervisory authorities.
- In the event of any conflict between these DPA Terms and the Regulamin on matters of personal data protection, these DPA Terms prevail.
- These DPA Terms are governed by Polish law. The Polish-language version is the binding version; the English version is provided for convenience.
- Matters not regulated here are governed by the GDPR, the Polish Personal Data Protection Act, and the Regulamin.