Where you use Athmane to collect or store your own end users' personal data, we process it on your behalf as your processor under Article 28 GDPR. This DPA is part of the Terms of Service; it governs only that Customer Personal Data.
You are the controller and we are the processor of Customer Personal Data. We process it only to provide the Service and only on your documented instructions (your use of the Service, the Terms, and this DPA). We tell you if an instruction appears to infringe applicable law.
Personnel authorized to process Customer Personal Data are bound by confidentiality. We maintain technical and organizational measures appropriate to the risk (Art. 32): encryption of sensitive fields at rest and data in transit (TLS), per-app isolation of Customer Personal Data enforced server-side on every read and write, least-privilege access controls, audit logging of privileged actions, and regular encrypted backups with tested restore.
You authorize us to engage the sub-processors listed at athmane.com/subprocessors. We remain responsible for their performance, and we update that list before adding or replacing one that handles personal data, giving you a way to object where required.
Customer Personal Data is hosted in the EU (Hetzner, Germany/Finland). Where a transfer involves a country outside the EEA without an adequacy decision, the safeguard we rely on is the one recorded for that vendor at athmane.com/subprocessors. Rows marked being confirmed there are vendors whose transfer basis we have not finished verifying — we publish it once it is settled rather than a value we have not checked. If a specific vendor's basis matters for your own compliance, ask us at [email protected] before you rely on it.
Taking into account the nature of processing, we assist you with data-subject requests (the Service provides self-service export and delete) and with your obligations under Arts. 32–36. We notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with the information you need to meet your own notification obligations.
On termination, or on your request, we delete or return Customer Personal Data and delete existing copies, except where retention is legally required. Active data is deleted immediately; our encrypted infrastructure backups roll off within three days, so the maximum residual is three days.
We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, subject to reasonable confidentiality and frequency limits. Liability under this DPA is subject to the limitations in the Terms; if this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls.