Data Processing Agreement (DPA)
Version: July 2026
Related documents: use of the services is governed by our Terms of Service; the processing of account data is described in the Privacy Policy.
1. Parties and scope
This data processing agreement pursuant to Art. 28 GDPR ("DPA") is concluded between:
- the customer as controller within the meaning of Art. 4(7) GDPR, and
- Lanisce, razvoj programske opreme, d.o.o. (hereinafter the "Provider") as processor within the meaning of Art. 4(8) GDPR.
This DPA applies to the extent the customer uses hosted control planes and personal data contained in cluster or control-plane data on the Provider's infrastructure is processed in the course of doing so.
Scoping:
- For self-hosted monitoring, the Provider processes only account and heartbeat metadata as a controller in its own right, as described in the Privacy Policy; this DPA does not apply in that respect.
- Worker nodes in the customer's own Hetzner account are outside the scope of this DPA; in that respect the customer has its own direct contractual relationship with Hetzner (see the Terms, Section 3).
2. Subject matter, duration, nature and purpose of processing
| Item | Description |
|---|---|
| Subject matter | Operation of managed Kubernetes control planes (etcd, apiserver, scheduler, controller-manager), including storage and backup of control-plane data |
| Duration | Term of the service contract (Terms of Service); this DPA ends upon its termination |
| Nature and purpose | Hosting, storage, backup, and technical operation of control-plane data for the provision of the service |
| Categories of data | Any personal data the customer stores in control-plane data (in particular etcd, e.g. in Kubernetes objects, ConfigMaps, Secrets); the content is determined solely by the customer |
| Categories of data subjects | Determined solely by the customer (e.g. the customer's employees, customers, or users) |
3. Instructions
- The Provider processes personal data only on documented instructions from the customer (Art. 28(3)(a) GDPR). The customer's configuration of the service (e.g. creating, modifying, and deleting clusters and their contents) constitutes such an instruction.
- Further instructions must be given in text form.
- If the Provider considers that an instruction infringes the GDPR or other data protection provisions, it shall inform the customer without undue delay.
4. Confidentiality
The Provider ensures that persons authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
5. Security of processing
The Provider implements all technical and organizational measures required pursuant to Art. 32 GDPR. The current measures are described in the annex "Technical and organizational measures" at the end of this document; they may be further developed, provided the level of protection is not reduced.
6. Sub-processors
- The customer grants a general authorization for the engagement of sub-processors (Art. 28(2) GDPR). The Provider will inform the customer in advance of intended changes (addition or replacement); the customer may object on justified data protection grounds.
- The Provider imposes on sub-processors, by contract, the same data protection obligations as set out in this DPA (Art. 28(4) GDPR).
Sub-processors currently engaged:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH, Germany | Infrastructure hosting (data centers FSN1/NBG1) | Germany (EU) |
No data is transferred outside the EU/EEA. Worker nodes in the customer's own Hetzner account do not constitute sub-processing by the Provider (see Section 1).
7. Assistance to the customer
Taking into account the nature of the processing and the information available to it, the Provider assists the customer:
- with appropriate technical and organizational measures in fulfilling data-subject rights (Art. 12-23 GDPR) (Art. 28(3)(e) GDPR),
- in complying with the obligations under Art. 32-36 GDPR (security of processing, breach notification, data protection impact assessment, prior consultation) (Art. 28(3)(f) GDPR).
8. Notification of personal data breaches
The Provider notifies the customer of personal data breaches affecting data processed on the customer's behalf without undue delay after becoming aware of them, and provides the information required for the notification to the supervisory authority (Art. 33 GDPR) to the extent available to it.
9. Deletion and return
- Upon termination of the service contract, the Provider deletes all personal data processed on the customer's behalf, unless statutory retention obligations require otherwise (Art. 28(3)(g) GDPR).
- Complete deletion takes place within 30 days after termination of the contract, in accordance with the Terms.
- The customer may export its data before termination using the features provided by the service.
10. Evidence and audits
- The Provider makes available to the customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR (Art. 28(3)(h) GDPR).
- Audits are conducted primarily through written information and the provision of suitable documentation. On-site audits are permitted only where mandatorily required by law, upon reasonable advance notice, during normal business hours, and without disproportionate disruption of operations; the customer bears the costs.
11. Liability and precedence
- Liability is governed by the liability section of the Terms of Service (Section 12); statutory liability under Art. 82 GDPR remains unaffected.
- In case of conflict between this DPA and the Terms, this DPA prevails in matters concerning the processing of personal data.
Annex: Technical and organizational measures (TOMs)
- EU infrastructure: Exclusively infrastructure in the EU (Hetzner, Germany — FSN1/NBG1); no data transfers outside the EU/EEA
- Encryption in transit: TLS for all service endpoints; the in-cluster network (CNI) of user clusters is WireGuard-encrypted
- Encryption at rest: Kubernetes Secrets in the etcd of hosted clusters are stored encrypted at the application layer (secretbox encryption with per-cluster key material); the bulk-data tier of the platform storage cluster additionally resides on block-level encrypted disks (LUKS)
- Tenant isolation: Dedicated control planes per customer, per-tenant OIDC organizations, network policies between tenant workloads
- Access control: Role-based access control; multi-factor authentication and step-up verification for sensitive operations
- Backup and recovery: Regular backups with tested, documented restore procedures; backups remain exclusively within the EU; the off-site backup copy is stored encrypted (authenticated encryption) with regular automated integrity checks; secret and key material is stored encrypted
- Logging: Logging and audit trails for administrative access
- Personnel: Personnel access is limited to what is operationally necessary
The Provider currently holds no certifications (e.g. ISO 27001) and claims none.
This is an English translation provided for convenience. The German version of this data processing agreement is authoritative. For questions, contact privacy@kubehz.io.