Data Processing Agreement

Version: September 13, 2026.

1. Parties, scope and order of precedence

This Data Processing Agreement (DPA), including its annexes, forms part of the service agreement between the customer identified in that agreement or its accepted order (Customer) and amerged B.V., Netherlands (Processor), when that agreement incorporates this DPA. It applies to personal data processed by Processor on Customer's behalf to provide ohmyho.st. Electronic acceptance of the incorporating agreement identifies the parties; publication of this document alone does not represent a separately signed agreement with every website visitor.

Customer acts as controller, or as a processor authorised by its controller to appoint Processor as a subprocessor. Each party fulfils the obligations applicable to its role. This DPA prevails over conflicting service terms on the processing it covers; applicable Standard Contractual Clauses prevail over conflicting terms of either document.

Account administration, billing, service security and correspondence for which amerged B.V. determines its own purposes are covered by the Privacy notice rather than treated automatically as processing on Customer's instructions.

2. Documented instructions

Processor processes Customer Personal Data only to provide the agreed services and on documented instructions, including the service agreement, this DPA, the selected configuration and actions submitted by Customer's authorised users or agents. Customer is responsible for its agents' authority and for the lawfulness of its instructions, notices and collection of data. A configuration or agent instruction does not waive this DPA or applicable data protection law.

Processor does not sell Customer Personal Data, use it for its own advertising, or use customer application content to train a general-purpose AI model. If Union or Member State law to which Processor is subject requires processing outside Customer's instructions, Processor informs Customer before processing unless that law prohibits notification. Processor promptly informs Customer if, in its opinion, an instruction infringes applicable data protection law and may suspend the affected instruction while the issue is resolved.

3. Confidentiality and security

Access is limited to authorised persons with a need to access the data and an appropriate confidentiality obligation. Processor applies technical and organisational measures appropriate to the risk, taking account of the nature, scope, context and purposes of processing. The current baseline is set out in Annex II — Technical and organisational measures.

Processor may update measures to respond to technical change and risk without materially reducing the overall protection of Customer Personal Data. Customer remains responsible for the security and lawful design of its application, its users and agents, the credentials it controls and the choices it makes between shared and isolated environments.

4. Subprocessors

Customer gives general written authorisation to engage the workload subprocessors identified in Annex III — Provider register. Processor imposes written obligations on each subprocessor providing at least the protection required by Article 28 GDPR for its processing and remains responsible to Customer for the subprocessor's performance of those obligations.

Processor gives at least 30 days' prior notice of a new or replacement workload subprocessor through the registered customer contact, together with the relevant service and processing location. Customer may object on reasonable data-protection grounds within that period. The parties work in good faith on an alternative; if no reasonable solution is available, Customer may end the affected service before the change takes effect. An urgent security or legal replacement is communicated as soon as practicable with the reason and available alternatives. This does not remove mandatory rights under applicable SCCs.

5. Assistance and individual rights

Taking account of the processing and information available, Processor assists Customer with requests for access, correction, deletion, restriction and portability, and with obligations under Articles 32–36 GDPR, including security assessments, breach notifications, impact assessments and consultation with supervisory authorities.

If Processor receives a request concerning data it processes for Customer, it forwards the request to Customer without undue delay and does not respond on Customer's behalf unless instructed or legally required. Requests concerning Processor’s independent-controller activities follow the Privacy notice. The contact form is the public channel for submitting requests and obtaining the appropriate secure follow-up.

6. Personal data breaches

Processor notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification includes, as information becomes available, the nature of the breach; affected data and persons; likely consequences; containment and remediation; and a contact route for follow-up. Information may be provided in phases where it cannot reasonably be supplied at once.

Processor takes reasonable steps to contain, investigate and mitigate the breach, preserves relevant evidence and cooperates with Customer. Customer decides on notifications to individuals and authorities in its controller role, without prejudice to Processor's own legal obligations.

7. International transfers

Processor makes restricted international transfers only on documented instructions and with a valid Chapter V GDPR mechanism. Selected US infrastructure and access from outside the EEA are addressed in Annex IV — International transfers. Where SCCs are required, the applicable unmodified Commission clauses, module and completed annexes govern that particular transfer. A customer-to-amerged transfer within the EEA does not become a restricted transfer merely because an onward subprocessor is in the US.

8. Information and audits

Processor makes available information reasonably needed to demonstrate compliance with this DPA and allows and contributes to audits, including inspections, by Customer or an independent auditor bound by confidentiality. The parties agree a proportionate scope, timing and safeguards for other customers' data and system security. Existing documentation may be used where it adequately answers the issue, but does not eliminate an audit required by law or justified by a breach or substantiated compliance concern. Reasonable notice applies except where the circumstances require urgency. These arrangements do not restrict a supervisory authority's powers.

9. Return and deletion

At the end of the affected services, or on Customer's documented instruction, Processor returns or deletes Customer Personal Data, at Customer's choice, and deletes remaining copies unless applicable law requires their retention. Return is through the supported export mechanisms or an agreed secure handover; the SQL ZIP export is not represented as an export of every file or category of service data.

Customer chooses and retains its SQL-export password. Downloads made by Customer are under Customer's control. Active-resource deletion and expiry of backup copies are distinct. Restricted backup copies remain protected, are not used for another purpose, and expire under the applicable retention lifecycle; deletion instructions must be reapplied if such a copy is restored. Processor supplies confirmation of the completed deletion process on request. Data retained by law is isolated from ordinary use and retained only for the required purpose and period.

10. Duration and responsibility

This DPA continues while Processor holds Customer Personal Data under the agreement, including protected retention copies. Mandatory data-subject rights, regulatory powers and applicable SCC rights are unaffected by the agreement's allocation of responsibility. Customer can request a copy of the operative documents or submit an instruction through the contact form and a secure channel agreed with Customer.

Annex I — Description of processing

Item Description
Subject matter Provision of the hosting capabilities ordered and configured by Customer
Nature and operations Receipt, transmission, organisation, storage, retrieval, execution of application requests, authorised access, export and deletion; build/deployment, database, file, runtime and enabled transactional-mail processing as applicable
Purpose Host and operate Customer's application and perform its authorised service instructions
Duration and frequency Continuous or request-driven during the service, followed by the documented return/deletion and protected-retention lifecycle
Data subjects Customer's authorised personnel, application users, visitors, contacts and other persons whose data Customer lawfully submits
Data categories Application-defined identifiers, contact details, account/content records, uploaded files, transaction or communication records, network/request metadata and diagnostic data, only to the extent present in the selected workload
Sensitive data Special-category data under Article 9 and criminal-offence data under Article 10 require a separate written arrangement establishing appropriate safeguards before being intentionally submitted
Customer details and instructions The customer identity and authorised contact recorded in the service agreement/account, together with its selected projects, environments and configuration
Processor contact amerged B.V., Netherlands; public requests through the contact form, followed by an appropriate secure channel

Annex II: TOMs · Annex III: Providers · Annex IV: Transfers

Get beta access

Register your interest in ohmyho.st.