Data Processing Agreement (DPA)
Version: August 2026
English translation: the German version is the legally authoritative one. Full notice at the foot of this page.
Related documents: use of the services is governed by our Terms of Service; the processing of account data is described in the Privacy Policy.
1. Parties and scope
This data processing agreement pursuant to Art. 28 GDPR (“DPA”) is concluded between:
- the customer as controller within the meaning of Art. 4(7) GDPR, and
- Lanisce, razvoj programske opreme, d.o.o. (hereinafter the “Provider”) as processor within the meaning of Art. 4(8) GDPR.
This DPA applies to the extent the customer uses hosted control planes or Spaces (shared control planes) and personal data contained in cluster or control-plane data on the Provider’s infrastructure is processed in the course of doing so.
Scoping:
- For self-hosted monitoring, the Provider processes only account and heartbeat metadata (the fields listed under Heartbeats) as a controller in its own right, as described in the Privacy Policy; this DPA does not apply in that respect.
- Worker nodes in the customer’s own Hetzner account are outside the scope of this DPA; in that respect the customer has its own direct contractual relationship with Hetzner (see the Terms, Section 3).
2. Subject matter, duration, nature and purpose of processing
| Item | Description |
|---|---|
| Subject matter | Operation of managed Kubernetes control planes (etcd, apiserver, scheduler, controller-manager), including storage and backup of control-plane data |
| Duration | Term of the service contract (Terms of Service); this DPA ends upon its termination |
| Nature and purpose | Hosting, storage, backup, and technical operation of control-plane data for the provision of the service |
| Categories of data | Any personal data the customer stores in control-plane data (in particular etcd, e.g. in Kubernetes objects, ConfigMaps, Secrets); the content is determined solely by the customer |
| Categories of data subjects | Determined solely by the customer (e.g. the customer’s employees, customers, or users) |
3. Instructions
- The Provider processes personal data only on documented instructions from the customer (Art. 28(3)(a) GDPR). The customer’s configuration of the service (e.g. creating, modifying, and deleting clusters and their contents) constitutes such an instruction.
- Further instructions must be given in text form.
- If the Provider considers that an instruction infringes the GDPR or other data protection provisions, it shall inform the customer without undue delay.
4. Confidentiality
The Provider ensures that persons authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
5. Security of processing
The Provider implements all technical and organizational measures required pursuant to Art. 32 GDPR. The current measures are described in the annex “Technical and organizational measures” at the end of this document; they may be further developed, provided the level of protection is not reduced.
6. Sub-processors
- The customer grants a general authorization for the engagement of sub-processors (Art. 28(2) GDPR).
- Notice. The Provider announces any new or replacement sub-processor at least 30 days before it begins processing, on the sub-processor list and by e-mail to every tenant owner.
- Objection. The customer may object on justified data protection grounds within those 30 days. If the Provider proceeds regardless, the customer may terminate the affected services without penalty and without notice period, and is refunded any prepaid fees for the unused period.
- The Provider imposes on sub-processors, by contract, the same data protection obligations as set out in this DPA (Art. 28(4) GDPR).
Sub-processors currently engaged:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH, Germany | Infrastructure hosting (data centers FSN1/NBG1) | Germany (EU) |
| MINDBAZ SAS (“Sweego”), France | Outbound e-mail (account mail and service notifications) | France (EU) |
No sub-processor listed above transfers data outside the EU/EEA. Worker nodes in the customer’s own Hetzner account do not constitute sub-processing by the Provider (see Section 1).
Card payments are handled by Revolut Bank UAB (Lithuania, EU). For the payment itself it acts as an independent controller rather than as a sub-processor of the Provider, so it is listed as a recipient in the Privacy Policy instead of here.
7. Assistance to the customer
Taking into account the nature of the processing and the information available to it, the Provider assists the customer:
- with appropriate technical and organizational measures in fulfilling data-subject rights (Art. 12-23 GDPR) (Art. 28(3)(e) GDPR),
- in complying with the obligations under Art. 32-36 GDPR (security of processing, breach notification, data protection impact assessment, prior consultation) (Art. 28(3)(f) GDPR).
8. Notification of personal data breaches
The Provider notifies the customer of personal data breaches affecting data processed on the customer’s behalf without undue delay after becoming aware of them, and provides the information required for the notification to the supervisory authority (Art. 33 GDPR) to the extent available to it.
9. Deletion and return
- Upon termination of the service contract, the Provider deletes all personal data processed on the customer’s behalf, unless statutory retention obligations require otherwise (Art. 28(3)(g) GDPR).
- Complete deletion takes place within a planned 14 days after termination of the contract, and in any event within 30 days at the latest, in accordance with the Terms.
- The customer may export its data before termination using the features provided by the service.
- Backups: the Provider keeps encrypted internal backups of the platform databases. Data already deleted from the live systems can remain in these backups for at most 90 days, after which the retention policy destroys it. These backups exist solely for disaster recovery: they are never read, searched, analysed or exported for any other purpose, and access is limited to the operators carrying out a restore. Where a restore would reinstate data that has already been deleted, the deletion is re-applied as a documented step of the restore procedure.
10. Evidence and audits
- The Provider makes available to the customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR (Art. 28(3)(h) GDPR).
- Audits are conducted primarily through written information and the provision of suitable documentation. On-site audits are permitted only where mandatorily required by law, upon reasonable advance notice, during normal business hours, and without disproportionate disruption of operations; the customer bears the costs.
11. Liability and precedence
- Liability is governed by the liability section of the Terms of Service (Section 12); statutory liability under Art. 82 GDPR remains unaffected.
- In case of conflict between this DPA and the Terms, this DPA prevails in matters concerning the processing of personal data.
Annex: Technical and organizational measures (TOMs)
- EU infrastructure: Exclusively infrastructure in the EU (Hetzner, Germany — FSN1/NBG1; outbound e-mail via Sweego, France); no data transfers outside the EU/EEA
- Encryption in transit: TLS for all service endpoints; the in-cluster network (CNI) of user clusters is WireGuard-encrypted
- Encryption at rest: Kubernetes Secrets in the etcd of hosted clusters are stored encrypted at the application layer (secretbox encryption with per-cluster key material); the bulk-data tier of the platform storage cluster additionally resides on block-level encrypted disks (LUKS)
- Tenant isolation: Dedicated control planes per customer, per-tenant OIDC organizations, network policies between tenant workloads
- Access control: Role-based access control; multi-factor authentication and step-up verification for sensitive operations
- Backup and recovery: Regular backups with tested, documented restore procedures; backups remain exclusively within the EU; the off-site backup copy is stored encrypted (authenticated encryption) with regular automated integrity checks; secret and key material is stored encrypted
- Logging: Logging and audit trails for administrative access
- Personnel: Personnel access is limited to what is operationally necessary
The Provider currently holds no certifications (e.g. ISO 27001) and claims none.
This is an English translation provided for convenience. The German version of this data processing agreement is authoritative. For questions, contact privacy@kubehz.io.