Ownware Cloud: Data Processing Agreement
Part of the Ownware Cloud Terms of Service · version 1.0 · published 27 September 2026 · in force from that date
Parties
- The Customer — the person or organisation named on the Cloud Account ("the Controller").
- NaTutti s. r. o., a company registered in the Slovak Republic (EU) ("the Processor"). Privacy contact: support@ownware.io.
This DPA forms part of the Ownware Cloud Terms of Service and applies whenever the Processor processes personal data on the Controller's behalf under a Plan. It is concluded in writing, including in electronic form (Article 28(9) GDPR), when the Customer accepts the Terms of Service at sign-up.
1. Definitions
1.1 "GDPR" means Regulation (EU) 2016/679 and, where it applies, the UK GDPR and the Data Protection Act 2018.
1.2 "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Article 4 GDPR.
1.3 "Customer Data", "Instance", "Plan" and "Account" have the meanings given in the Terms of Service.
1.4 "Sub-processor" means another processor engaged by the Processor to carry out specific processing activities on the Controller's behalf.
2. Subject matter, duration, nature and purpose
2.1 Subject matter. Hosting and operating the Controller's Instance of the Ownware app(s) named on the Account, including storage, backup, updating, export and deletion of Customer Data.
2.2 Duration. From the start of the first Plan until all Customer Data has been deleted or returned under clause 11.
2.3 Nature. Storage, hosting, backup and restore, software updates, production of exports, deletion, and access by Processor personnel only where needed under clause 6.
2.4 Purpose. Only to provide the Plan to the Controller as described in the Terms of Service, and for no purpose of the Processor's own.
2.5 Details are set out in Annex I.
3. Rights and obligations of the Controller
3.1 The Controller decides the purposes and means of processing of Customer Data, including what data is entered into the Instance, who may access it and for how long it is kept inside the Instance.
3.2 The Controller is responsible for having a lawful basis for the processing and for the information given to data subjects.
3.3 The Controller may give documented instructions under clause 4, object to Sub-processors under clause 8, receive information and carry out audits under clause 12, and choose between return and deletion under clause 11.
4. Instructions — Art. 28(3)(a)
4.1 The Processor processes Customer Data only on the Controller's documented instructions, including with regard to transfers of personal data to a third country or an international organisation, unless required to do otherwise by Union or Member State law to which the Processor is subject. In that case the Processor will inform the Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.
4.2 The Controller's instructions at the date of this DPA are: the Terms of Service, this DPA, and the Controller's own use and configuration of the Instance and the Account (including exports, deletions and integrations the Controller sets up). Further instructions may be given in writing, including by email to support@ownware.io, and the Processor will keep a record of them.
4.3 The Processor will inform the Controller immediately if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions (Art. 28(3), final subparagraph). Where the Controller maintains such an instruction, the Processor may suspend the affected processing and either party may terminate the affected Plan (compare SCC Clause 10(c)).
4.4 If the Processor determines purposes and means of processing in breach of this DPA, it is treated as a controller for that processing (Art. 28(10)).
5. Confidentiality — Art. 28(3)(b)
5.1 The Processor grants access to Customer Data only to members of its personnel for whom it is strictly necessary to provide, manage and monitor the Plan (SCC Clause 7.4(b)).
5.2 Every person authorised to process Customer Data has committed to confidentiality in writing or is under an appropriate statutory obligation of confidentiality. This covers employees, contractors, temporary and agency workers. Today the Processor's only person with access is its operator, who is bound by this DPA; anyone given access later will first commit to confidentiality in writing.
6. Security — Art. 28(3)(c) and Art. 32
6.1 The Processor implements at least the technical and organisational measures in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks to data subjects (Art. 32(1)).
6.2 The Processor reviews Annex II at least every 12 months and whenever the processing changes. It will not make changes that reduce the overall level of security without the Controller's prior approval (EDPB Guidelines 07/2020, para. 126).
6.3 Special categories of data. Some apps may be used to record data that falls under Article 9 or 10 GDPR (for example health information in waivers or incident records) if the Controller chooses to enter it. The Processor applies the measures in Annex II to all Customer Data alike; the Controller decides whether an app is suitable for such data and what it records there.
7. Personal data breaches — Art. 28(3)(f) and Art. 33(2)
7.1 The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and in any event within 48 hours, by email to the Account address.
7.2 The notification contains at least: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; a contact point for more information; and the likely consequences and the measures taken or proposed (SCC Clause 9.2). Where not all of this is available at once, the Processor provides it in phases without undue delay.
7.3 The Processor assists the Controller with notifying the supervisory authority and, where required, the data subjects (Art. 33 and 34), taking into account the nature of processing and the information available to the Processor.
8. Sub-processors — Art. 28(2), 28(3)(d) and 28(4)
8.1 General written authorisation. The Controller gives the Processor general written authorisation to engage the Sub-processors listed in Annex III (03-subprocessors.md).
8.2 Changes. The Processor will inform the Controller in writing, by email to the Account address, of any intended addition or replacement of a Sub-processor at least 30 days before the change, with the information the Controller needs to decide whether to object (name, location, what it will do, and the transfer mechanism if any). Publishing the change on the website alone is not enough (EDPB Guidelines 07/2020, para. 110).
8.3 Objection. The Controller may object in writing within 14 days of the notice, on reasonable data-protection grounds. The parties will then discuss the objection in good faith for 14 days. If they cannot resolve it, the Controller may terminate the affected Plan without penalty before the new Sub-processor is engaged, and the Processor refunds any prepaid fees for the unused period (EDPB Guidelines 07/2020, para. 158).
8.4 Flow-down. The Processor engages each Sub-processor under a written contract that imposes on it, in substance, the same data protection obligations as this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures (Art. 28(4)). At the Controller's request the Processor provides a copy of that contract, redacted where needed to protect business secrets (SCC Clause 7.7(c)), or, where a Sub-processor's terms do not allow copies, points to that Sub-processor's published data processing terms.
8.5 Liability. The Processor remains fully liable to the Controller for the performance of each Sub-processor's obligations (Art. 28(4)), and will notify the Controller of any failure by a Sub-processor to meet its contractual obligations.
9. Data subjects' rights — Art. 28(3)(e)
9.1 The Processor promptly passes to the Controller any request it receives from a data subject about Customer Data and does not answer it unless the Controller authorises it (SCC Clause 8(a)).
9.2 The Processor assists the Controller, by appropriate technical and organisational measures and insofar as possible, to respond to requests to exercise rights under Chapter III GDPR. The Instance itself provides the main measures: the Controller can view, correct, export and delete records in the Instance, and take a full export from the Account. Where the Controller cannot do something itself through the Instance, the Processor helps within 5 working days of a written request, free of charge.
10. Assistance with Articles 32 to 36 — Art. 28(3)(f)
10.1 Taking into account the nature of processing and the information available to it, the Processor assists the Controller with:
- (a) security of processing (Art. 32), by maintaining Annex II;
- (b) personal data breach notifications (Art. 33 and 34), under clause 7;
- (c) data protection impact assessments (Art. 35), by providing a description of the processing and of Annex II on request;
- (d) prior consultation with the supervisory authority (Art. 36), by providing information it holds that the Controller reasonably needs.
10.2 The Processor informs the Controller without delay if it becomes aware that Customer Data it processes is inaccurate or out of date (SCC Clause 8(c)(3)).
11. End of processing: return or deletion — Art. 28(3)(g)
11.1 At the end of the provision of the services, the Controller chooses whether the Processor deletes all Customer Data or returns it. The Controller may state or change this choice at any time before the end, by email to support@ownware.io (EDPB Guidelines 07/2020, para. 140).
11.2 Return. The Controller can take a full export through the Account at any time while a Plan is active and during the 30 days set out in "Your data when a Plan ends". On request the Processor provides the same export (a .tar file holding the SQLite database, the Instance's files, the application source and a README) within 5 working days.
11.3 Deletion. The Processor deletes the Instance database and files 30 days after the Instance closes, after a 7-day warning email, and deletes existing copies, unless Union or Member State law requires storage of the personal data. It will tell the Controller as soon as possible of any such legal requirement (EDPB Guidelines 07/2020, para. 142).
11.4 Backups. Copies in backups are put beyond use at the moment of deletion — they are not restored or accessed (each Instance's backups are separate files, so no other customer's restore ever needs them) — and are deleted on the normal backup rotation within 30 days (ICO, "End-of-contract provisions").
11.5 Confirmation. The Processor confirms deletion to the Controller in writing by email within 5 working days of completion (SCC Clause 10(d); EDPB Guidelines 07/2020, para. 141).
11.6 Until the data is deleted or returned, the Processor continues to apply this DPA.
12. Information and audits — Art. 28(3)(h)
12.1 The Processor makes available to the Controller all information necessary to demonstrate that it meets its obligations under Article 28 and this DPA, and deals promptly and adequately with the Controller's questions about the processing.
12.2 Audits. The Processor allows for and contributes to audits, including inspections, by the Controller or an independent auditor mandated by it, at reasonable intervals or where there are indications that this DPA is not being met (SCC Clause 7.6(c)–(d)).
- (a) The Controller gives at least 30 days' notice, except where a supervisory authority requires otherwise or following a personal data breach.
- (b) An auditor mandated by the Controller is bound by confidentiality.
- (c) The Processor may first answer by written information, documents or relevant certifications; this does not remove the Controller's right to an audit if that information is not sufficient.
- (d) Each party bears its own costs of an audit. Written answers under (c) are free of charge.
- (e) Inspections of Sub-processors' premises (for example data centres) take place through the Sub-processor's own audit reports and certifications where the Sub-processor's terms do not allow direct inspection.
12.3 The parties make this information, including audit results, available to the competent supervisory authority on request (SCC Clause 7.6(e)).
12.4 The Processor keeps a record of processing activities carried out on behalf of the Controller (Art. 30(2)).
13. International transfers — Art. 28(3)(a) and Chapter V
13.1 The Processor does not transfer Customer Data to a third country or an international organisation except on the Controller's documented instructions (including by approving a Sub-processor in Annex III that involves such a transfer), and only in line with Chapter V GDPR.
13.2 Annex III states, for each Sub-processor, where it processes Customer Data and the transfer mechanism relied on, if any.
13.3 Integrations that the Controller connects to its Instance (for example its own AI assistant through the MCP endpoint, or its own AI provider API key) are the Controller's choice and instruction; data sent to them on that instruction is not a transfer by the Processor.
14. Suspension and termination for non-compliance (SCC Clause 10)
14.1 If the Processor breaches this DPA, the Controller may instruct it to suspend processing until it complies or the contract ends. The Processor tells the Controller promptly if it cannot comply with this DPA for any reason.
14.2 The Controller may terminate the Plan insofar as it concerns processing of personal data if compliance is not restored within a reasonable time and in any case within one month of suspension; if the Processor is in substantial or persistent breach; or if it fails to comply with a binding decision of a competent court or supervisory authority.
15. Liability
15.1 Each party's liability under this DPA is governed by the liability clause of the Terms of Service. Nothing in this DPA limits either party's liability to data subjects under Article 82 GDPR, or any administrative fine imposed on a party.
16. Term, changes and law
16.1 This DPA lasts for as long as the Processor processes Customer Data.
16.2 Any change to this DPA is notified to the Controller directly and takes effect only after 30 days, during which the Controller can terminate the affected Plan.
16.3 This DPA is governed by the law of the Slovak Republic, and the courts of the Slovak Republic have jurisdiction.
---
Annex I — Details of processing
| Item | Details |
|---|---|
| Controller | The Customer named on the Account. Contact: the Account email. |
| Processor | NaTutti s. r. o., Slovak Republic (EU). Contact: support@ownware.io. No data protection officer is appointed; none is required for this processing. |
| Subject matter | Hosting and operating the Controller's Instance. |
| Nature of processing | Storage, hosting, backup and restore, software updates, export and deletion. The Instance's own emails to the Controller's clients go through the mail server the Controller sets in the Instance, not through the Processor. |
| Purpose | Providing the Plan to the Controller. |
| Duration | The term of the Plan(s), plus the 30 days and the backup rotation set out in "Your data when a Plan ends". |
| Categories of data subjects | Depends on the app and the Controller's use. Typically: the Controller's staff and other users of the Instance; its clients and customers; suppliers; visitors; tenants; members; people who submit reports, requests or complaints. |
| Types of personal data | Depends on the app. Typically: names, contact details, sign-in credentials (passwords stored only as salted hashes), business records linked to a person (invoices, bookings, shifts, leave, timesheets, training records, permits, complaints, waivers, signatures), uploaded documents and images, and IP addresses in logs. |
| Special categories (Art. 9/10) | Only if the Controller chooses to enter them. |
| Frequency | Continuous for the term of the Plan. |
| Retention inside the Instance | Set by the Controller. |
| Backups | Nightly; kept 14 days on the server, and encrypted backup copies kept up to 30 days, then deleted. See Annex II. |
| Sub-processors | See Annex III. |
Annex II — Technical and organisational measures
| Area | Measure |
|---|---|
| Isolation between customers | Each Instance has its own database file, its own writable copy of the app and its own files folder. A sign-in to one Instance is not accepted by any other. |
| Encryption in transit | Every request uses HTTPS: from the browser to Cloudflare, and from Cloudflare to the server over TLS with an origin certificate. |
| Encryption at rest | The server's disk and the live database files are not encrypted; they are protected by the access controls in this Annex. Backup copies kept beyond the server's own 14-day rotation are encrypted. |
| Pseudonymisation | The one-trial-per-email rule keeps only a SHA-256 hash of each normalised address that has started a trial, never the address itself. Customer Data is otherwise stored as entered. |
| Availability and resilience | One server in Hetzner's Falkenstein data centre. There is no standby server; recovery is from the backups below. Failed sign-ups and failed Instance builds raise an automatic alert to the operator. |
| Backups and restore | Every night (04:17 UTC) each Instance's database is integrity-checked and saved as a compressed snapshot, and its files as a compressed archive, kept 14 days on the server. Encrypted backup copies are kept for up to 30 days, then deleted. Restores are done by the operator, within two working days of a request. A restore is tested at least every six months. |
| Testing and evaluation | Every change to the platform runs its automated test suite before it is deployed, and this Annex is reviewed at least every 12 months. |
| User identification and authorisation | The Account is signed in with a single-use link sent to the Account email. Instance logins use the app's own accounts, with passwords stored only as salted hashes. API keys are created and revoked by the Controller inside the Instance. |
| Operator access | The server is reached only over SSH with keys; password sign-in is switched off. The operator console requires two-factor sign-in. The operator opens an Instance's data only when the Controller asks, or to fix a fault or a security incident. |
| Physical security | Provided by Hetzner's data centre controls. |
| Event logging | Web server logs of requests to the Cloud (IP address, time, address requested) are kept at most 30 days. A record of each Instance's lifecycle (created, paid, closed, deleted) is kept as set out in "Your data when a Plan ends". |
| Patching and configuration | The Processor applies updates to the apps and the platform. Changes go through the test suite first. |
| Data minimisation and retention | The platform keeps only what it needs to run and bill the Instance. Deletion follows clause 11 and "Your data when a Plan ends". |
| Portability and erasure | A full export from the Account at any time until deletion; deletion by the Controller from the Account once a Plan has ended, or 30 days after the Instance closes. |
| Incident response | The operator is alerted by the platform's own checks and by reports to support@ownware.io. Breaches affecting Customer Data are notified under clause 7, within 48 hours at the latest. |
| Assistance measures | In-app viewing, correction, export and deletion of records; help by email within 5 working days, free of charge. |
Annex III — Sub-processors
See "Sub-processors (Annex III to the DPA)".