Legal · Data Processing Agreement

Data Processing Agreement

Where you are the controller and we are the processor. Accepted automatically — no need to chase us for a signature.

Version 1.0 Effective 6 August 2026 Hola Money S.L.

01Scope and roles

This Data Processing Agreement (DPA) is entered into between you (the Controller) and Hola Money S.L. (the Processor) and forms part of the Terms of Service. It applies where we process personal data on your behalf under Article 28 of the GDPR.

It is accepted automatically when you accept the Terms. If your organisation needs a signed copy on paper, email legal@cleverotter.eu and we will provide one at no charge.

02Subject matter of the processing

Subject matterHosting and serving of static websites
DurationFor as long as your account is active
NatureStorage, transmission, caching, backup
PurposeDelivering your Sites to Visitors

Categories of data subject: Visitors to your Sites, and any individuals whose personal data you choose to include in the content you upload.

Categories of personal data: IP addresses and request metadata of Visitors; any personal data contained in files you upload. We do not require, and ask you not to upload, special category data.

03Our obligations

We will:

  • process personal data only on your documented instructions, which are given by your use of the Service and by these agreements, unless required otherwise by EU or Member State law — in which case we will tell you first, unless the law forbids it;
  • ensure everyone authorised to process the data is bound by confidentiality;
  • implement the technical and organisational measures in clause 05;
  • assist you in responding to data subject requests, and with your obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to us;
  • delete or return the data at the end of the relationship, as set out in clause 08;
  • make available the information needed to demonstrate compliance with Article 28.

If we consider an instruction to infringe data protection law, we will tell you immediately.

04Your obligations

You confirm that you have a lawful basis for the personal data you place on the Service, that you have provided any required privacy notices to your Visitors, and that your instructions to us comply with data protection law. You are responsible for the content you upload and for any personal data within it.

05Security measures

We maintain the following, and will not reduce them during the term:

  • Encryption in transit — TLS on all public endpoints; SSH for deployment.
  • Encryption at rest — server-side encryption in object storage; encrypted backups.
  • Access control — key-based administrative access only, no shared accounts, least privilege, separate credentials per environment.
  • Isolation — content is namespaced per customer; serving infrastructure holds read-only credentials and cannot alter a release.
  • Integrity — releases are content-addressed and immutable; a partial upload can never be published.
  • Resilience — multiple independent serving nodes; automated backups tested by restore.
  • Logging — administrative and deployment actions are logged; no secret or uploaded content is ever written to a log.

06Sub-processors

You give general authorisation for us to engage the sub-processors below.

Hetzner Online GmbH · DECompute, object storage
Scaleway SAS · FREncrypted offsite backups
Payment providerCONFIRM
Email providerCONFIRM

We will give at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within that period; if we cannot offer an alternative, you may terminate the affected part of the Service and receive a pro-rata refund. Each sub-processor is bound by obligations no less protective than this DPA.

07Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken.

Notifying your supervisory authority and your data subjects remains your responsibility as controller; we will give you the information you need to do it.

08Deletion and return

On termination, you may retrieve your content at any time during the 30-day period described in the Terms. After that we delete it from live systems, and it ages out of backups within a further 35 days. We will confirm deletion in writing on request.

09Audits

We will make available the information necessary to demonstrate compliance with Article 28. You may audit no more than once in any 12 months, on 30 days' notice, at your own cost, subject to confidentiality and without disrupting the Service or accessing other customers' data. Where a recognised third-party certification or report is available, we may provide that instead. CONFIRM: whether you intend to obtain ISO 27001 or SOC 2

10International transfers

All processing takes place within the EEA. We will not transfer personal data outside the EEA without either an adequacy decision or Standard Contractual Clauses in place, and we will update the sub-processor list before doing so.

11Precedence

Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, those clauses prevail.

Questions about this document

Ask a person, not a form.

We would rather answer a question before you sign up than argue about a clause afterwards.