Legal · Data Processing Agreement
Data Processing Agreement
Where you are the controller and we are the processor. Accepted automatically — no need to chase us for a signature.
01Scope and roles
This Data Processing Agreement (DPA) is entered into between you (the Controller) and Hola Money S.L. (the Processor) and forms part of the Terms of Service. It applies where we process personal data on your behalf under Article 28 of the GDPR.
It is accepted automatically when you accept the Terms. If your organisation needs a signed copy on paper, email legal@cleverotter.eu and we will provide one at no charge.
02Subject matter of the processing
Categories of data subject: Visitors to your Sites, and any individuals whose personal data you choose to include in the content you upload.
Categories of personal data: IP addresses and request metadata of Visitors; any personal data contained in files you upload. We do not require, and ask you not to upload, special category data.
03Our obligations
We will:
- process personal data only on your documented instructions, which are given by your use of the Service and by these agreements, unless required otherwise by EU or Member State law — in which case we will tell you first, unless the law forbids it;
- ensure everyone authorised to process the data is bound by confidentiality;
- implement the technical and organisational measures in clause 05;
- assist you in responding to data subject requests, and with your obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to us;
- delete or return the data at the end of the relationship, as set out in clause 08;
- make available the information needed to demonstrate compliance with Article 28.
If we consider an instruction to infringe data protection law, we will tell you immediately.
04Your obligations
You confirm that you have a lawful basis for the personal data you place on the Service, that you have provided any required privacy notices to your Visitors, and that your instructions to us comply with data protection law. You are responsible for the content you upload and for any personal data within it.
05Security measures
We maintain the following, and will not reduce them during the term:
- Encryption in transit — TLS on all public endpoints; SSH for deployment.
- Encryption at rest — server-side encryption in object storage; encrypted backups.
- Access control — key-based administrative access only, no shared accounts, least privilege, separate credentials per environment.
- Isolation — content is namespaced per customer; serving infrastructure holds read-only credentials and cannot alter a release.
- Integrity — releases are content-addressed and immutable; a partial upload can never be published.
- Resilience — multiple independent serving nodes; automated backups tested by restore.
- Logging — administrative and deployment actions are logged; no secret or uploaded content is ever written to a log.
06Sub-processors
You give general authorisation for us to engage the sub-processors below.
We will give at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within that period; if we cannot offer an alternative, you may terminate the affected part of the Service and receive a pro-rata refund. Each sub-processor is bound by obligations no less protective than this DPA.
07Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken.
Notifying your supervisory authority and your data subjects remains your responsibility as controller; we will give you the information you need to do it.
08Deletion and return
On termination, you may retrieve your content at any time during the 30-day period described in the Terms. After that we delete it from live systems, and it ages out of backups within a further 35 days. We will confirm deletion in writing on request.
09Audits
We will make available the information necessary to demonstrate compliance with Article 28. You may audit no more than once in any 12 months, on 30 days' notice, at your own cost, subject to confidentiality and without disrupting the Service or accessing other customers' data. Where a recognised third-party certification or report is available, we may provide that instead. CONFIRM: whether you intend to obtain ISO 27001 or SOC 2
10International transfers
All processing takes place within the EEA. We will not transfer personal data outside the EEA without either an adequacy decision or Standard Contractual Clauses in place, and we will update the sub-processor list before doing so.
11Precedence
Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, those clauses prevail.
Questions about this document
Ask a person, not a form.
We would rather answer a question before you sign up than argue about a clause afterwards.