Data Processing Agreement
Effective date: 1 June 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Distortion Labs SAS ("Processor", "we") — a French SAS, registered office 66 avenue des Champs-Élysées, 75008 Paris, France, RCS Paris 921 758 694 — and the Customer ("Controller", "you"). It governs our processing of personal data on your behalf for the damn.dev managed-hosting service, and reflects Article 28 GDPR.
Scope — this DPA applies only to the managed-hosting plans (Indie and Team). It does not apply by default to Studio (bespoke) engagements, which are governed by their own agreement; equivalent data-processing terms can be agreed for a Studio engagement where its scope requires them. It does not apply to self-hosting, where you run the software on your own infrastructure and we process none of your workspace data.
Where this DPA conflicts with the Terms of Service on data protection, this DPA prevails.
1. Roles
- For the content of your hosted instance (workspaces, agents, messages, files), you are the Controller and we are the Processor.
- For your account and billing data, we are an independent Controller (see the Privacy Policy).
2. Subject matter, duration, nature & purpose
We process personal data only to provide, secure and maintain the managed-hosting service, for the duration of your subscription. We process it solely on your documented instructions (the Terms, this DPA, and your use of the service); we will tell you if an instruction appears to breach the GDPR.
3. Types of data & data subjects
- Categories of data: whatever you and your users place in your instance (e.g. messages, documents, agent configurations, and any personal data they contain).
- Data subjects: your team members, your customers, and any individuals whose data you process.
4. Our access to your data
- We do not read or use the contents of your instance.
- We do not log in to your instance to view its contents. Any support access to your instance is performed only with your explicit, time-limited consent, is logged, and is automatically revoked when the support window ends.
- We retain infrastructure-level access to the underlying server (e.g. security patching, backups where applicable, and disaster recovery). This access is used only as necessary to operate and secure the service and never to read your workspace data.
5. Security (Art. 32)
We implement appropriate technical and organisational measures, including: isolated, single-tenant instances per customer; encryption in transit (TLS); access controls and the principle of least privilege; no standing administrative SSH access to your instance by default; consent-gated, time-limited, logged break-glass support access; and audit logging of administrative actions.
6. Subprocessors
You authorise the following subprocessors. We will give prior notice of any intended change and you may object on reasonable data-protection grounds.
| Subprocessor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting (your instance) | Germany (EU) |
| Stripe | Payment processing | EU / US (SCCs) |
| Cloudflare | DNS, TLS, CDN | EU / US (SCCs) |
| Resend | Transactional email | EU / US (SCCs) |
7. International transfers
Where a subprocessor processes data outside the EEA, transfers are covered by the European Commission's Standard Contractual Clauses and appropriate supplementary measures.
8. Assistance to you
Taking into account the nature of processing, we will assist you, by appropriate measures, to: respond to data-subject requests (access, erasure, portability, etc.); meet your security, breach-notification and data-protection-impact-assessment obligations.
9. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification duties.
10. Deletion or return
On termination, and on your request, we will make your data available for export for a reasonable period, then delete it from your instance without undue delay, subject to any legally required retention.
11. Audits
We will make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to reasonable audits, including inspections, conducted by you or an auditor you mandate (subject to reasonable confidentiality and scheduling).
12. Liability & governing law
Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by French law.
Contact (data protection): [email protected] — Distortion Labs SAS, 66 avenue des Champs-Élysées, 75008 Paris, France.