Data Processing Agreement (DPA) — Aderlo Cloud
Annex to the Terms of Service for Aderlo Cloud Hosting Services
In force from 1 Aug 2026.
Effective from 1 August 2026
§ 1. Parties and Definitions
-
This Data Processing Agreement (hereinafter: "DPA") forms an integral annex to the Terms of Service for Aderlo Cloud hosting services and takes effect upon conclusion of the hosting service agreement.
-
Parties: a) Data Controller — the Client using Aderlo Cloud hosting services who, in the course of their activity, processes personal data of third parties (e.g. customers of their online store, newsletter subscribers) on the Service Provider's infrastructure. b) Data Processor — ADERLO PROSTA SPÓŁKA AKCYJNA, ul. Nowogrodzka 50/54 lok. 515, 00-695 Warsaw, Poland, KRS: 0000955282, NIP: 5492466214.
-
In the event of any discrepancy between language versions, the Polish version shall prevail.
§ 2. Subject Matter and Duration
-
The Controller entrusts the Processor with the processing of personal data under the terms of this DPA, solely to the extent and for the purpose necessary for the performance of the hosting service agreement.
-
Processing includes: storage on servers, backup creation, data transmission over the network, making data available via web servers.
-
Processing lasts for the entire duration of the hosting service agreement. After termination, § 9 applies.
§ 3. Nature and Purpose of Processing
-
Nature: The Processor provides shared hosting services, storing and serving the Controller's data on physical servers located within the European Union.
-
Purpose: Enabling the Controller to operate websites, online stores, web applications and e-mail services in which the Controller processes personal data of their customers/users.
-
The Processor processes data solely on documented instructions from the Controller (Article 28(3)(a) GDPR). Documented instructions include: conclusion of the hosting agreement, service configuration in the admin panel, and support requests.
§ 4. Categories of Data Subjects and Types of Data
-
Categories of data subjects (examples — dependent on the Controller's activity):
- customers of the Controller's online stores,
- newsletter subscribers,
- website users,
- the Controller's contractors and employees (if their data is stored on the hosting).
-
Types of personal data (examples):
- identification data (name, surname),
- contact data (e-mail, phone, address),
- transaction data (orders, payments),
- technical data (IP addresses, access logs),
- any other personal data the Controller chooses to store within the Hosting Service.
-
The Processor does not access the content of personal data stored by the Controller, except where access is necessary for technical support at the Controller's express request.
§ 5. Processor's Obligations
The Processor undertakes to:
-
Process data solely on the Controller's instructions — not for its own purposes, except where required by EU or Member State law (in which case the Processor informs the Controller before processing, unless prohibited by law).
-
Ensure confidentiality — persons authorised to process personal data have committed themselves to confidentiality or are under appropriate statutory obligation.
-
Implement technical and organisational measures (Article 32 GDPR), including: SSL/TLS encryption, CloudLinux CageFS account isolation, Imunify360 protection, regular backups, server access controls, security monitoring, ECC RAM, NVMe drives with PLP in RAID1.
-
Assist the Controller with: data subject rights requests (Articles 15–22 GDPR), security of processing (Article 32), data breach notification (Articles 33–34), and data protection impact assessments (Articles 35–36).
-
Breach notification — notify the Controller of a personal data breach without undue delay, no later than 48 hours after becoming aware, providing: description, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
§ 6. Sub-processing
-
The Controller grants the Processor general authorisation to engage sub-processors to the extent necessary for the hosting service.
-
Current list of sub-processors:
Sub-processor Scope Location Hetzner Online GmbH Physical server (hosting), backup Falkenstein, Germany (EU) Supabase Inc. Client panel database Ireland (EU) -
The Processor informs the Controller of any intended addition or replacement of a sub-processor at least 14 days in advance.
-
The Controller may raise a reasoned objection within 14 days. If no resolution is reached, the Controller may terminate the hosting agreement with 30 days' notice, with a right to a proportional refund.
-
The Processor ensures that sub-processor agreements contain data protection obligations at least equivalent to those in this DPA.
-
The Processor is fully liable for the acts and omissions of its sub-processors (Article 28(4) GDPR).
§ 7. Audit
-
The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allows audits, including inspections, conducted by the Controller or an authorised auditor.
-
The Controller must provide at least 30 days' notice of a planned audit and conduct it without unreasonable disruption.
-
Audit costs are borne by the Controller, unless the audit reveals a material breach by the Processor.
-
The Processor may offer independent audit reports or security certifications as an alternative to individual audits.
§ 8. Transfers Outside the EEA
-
The Processor stores entrusted data on servers within the European Union (Hetzner, Germany).
-
Where data transfer outside the EEA is necessary (e.g. via sub-processors), the Processor applies safeguards under Chapter V GDPR, including Standard Contractual Clauses (SCC) and adequacy decisions (EU-US Data Privacy Framework).
§ 9. Data Deletion and Return After Termination
-
After termination of the hosting agreement, the Processor, at the Controller's choice: a) returns all personal data — the Client may download a backup via the admin panel before service termination, or b) deletes all personal data and existing copies, unless EU or Member State law requires continued storage.
-
If the Controller does not retrieve data within 30 days of termination, the Processor permanently deletes personal data from the production server. Backups expire naturally according to Plan retention (7–30 days).
-
Upon written request, the Processor confirms deletion of data after the retention periods have elapsed.
Final Provisions
-
Matters not regulated by this DPA shall be governed by the GDPR and applicable Polish law.
-
This DPA takes effect upon conclusion of the Aderlo Cloud hosting service agreement and remains in force for its duration and the period necessary for data deletion under § 9.
-
Amendments to this DPA require written or documentary form (e-mail).
-
This DPA is effective from 1 August 2026.
ADERLO PROSTA SPÓŁKA AKCYJNA ul. Nowogrodzka 50/54 lok. 515, 00-695 Warsaw, Poland KRS: 0000955282 · NIP: 5492466214 · REGON: 521268860