Data Processing Addendum

Last updated: September 9, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Crevoca ("Processor" or "we") and you ("Controller" or "Customer") and reflects the parties' agreement with respect to the processing of personal data under applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR").

1. Roles and Scope

The Controller determines the purposes and means of processing personal data. The Processor processes personal data on behalf of the Controller in accordance with the Controller's instructions through the provision of the Service. This DPA applies to personal data that the Controller submits to or makes available through the Service.

2. Processing of Personal Data

The Processor shall:

  • Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required by applicable law.
  • Ensure that persons authorized to process personal data are subject to confidentiality obligations.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption in transit and at rest, access controls, and regular security assessments.
  • Notify the Controller without undue delay after becoming aware of a personal data breach, providing all reasonably necessary information to allow the Controller to meet its own notification obligations.

3. Sub-processors

The Controller grants general authorization for the Processor to engage sub-processors to support the provision of the Service. The Processor shall remain liable for the performance of its sub-processors to the same extent it is liable under this DPA. Current sub-processors include:

  • Stripe: Payment processing services.
  • Cloud hosting providers: Infrastructure and data storage.
  • Analytics providers: Usage analytics and reporting.

The Processor shall give the Controller prior notice of intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes.

4. Data Subject Rights

Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligations to respond to requests from data subjects exercising their rights under the GDPR, including:

  • Right of access to personal data.
  • Right to rectification of inaccurate data.
  • Right to erasure ("right to be forgotten").
  • Right to data portability.
  • Right to object to processing.
  • Right to restriction of processing.

5. International Data Transfers

Where personal data is transferred outside the European Economic Area ("EEA"), the Processor shall ensure appropriate safeguards are in place, which may include Standard Contractual Clauses ("SCCs") approved by the European Commission, the EU-US Data Privacy Framework, or other lawful transfer mechanisms.

6. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations under this DPA and shall contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.

7. Deletion of Data

Upon termination of the Service, the Processor shall, at the choice of the Controller, delete or return all personal data to the Controller, and delete existing copies, unless applicable law requires storage of the personal data. Data retained for legal compliance shall be stored securely and not processed for any other purpose.

8. Contact

For any questions regarding this DPA or to exercise data subject rights, please contact us.