DPA
Processor terms for business customers that run personal data on Eurobase.
These processor terms form the Article 28 DPA when incorporated into accepted customer terms, checkout terms, an order form, or another written customer agreement.
Roles
For customer workload data, the customer is the controller and Eurobase is the processor. For Eurobase account, billing, security, and support data, Eurobase is the controller.
Processing
Eurobase processes customer workload personal data only on the customer's documented instructions, including the service contract, accepted product settings, support requests, and customer-authorized deployment actions. The subject matter is building, deploying, hosting, running, securing, logging, troubleshooting, metering, and supporting the customer's workloads. Processing lasts for the term of the customer's use of the service and any required retention period. If EU or Member State law requires different processing, Eurobase will inform the customer before processing unless that law forbids notice.
Data
- Repository, build, deployment, function, storage, request, log, and runtime data, including visitor IP addresses, derived location and request paths in project access logs.
- Customer environment metadata, quota, usage, health, audit, and incident data.
- Personal data categories depend on what the customer deploys or stores.
- Data subjects depend on the customer workload, such as account users, app users, employees, or end customers.
Security
Eurobase will maintain technical and organizational measures appropriate to the risk: access control, least privilege, confidentiality controls, secret handling, tenant isolation, provider security controls, logging, backup posture, vulnerability and incident handling, availability controls, and production change control. Personnel and contractors authorized to process customer personal data are bound by confidentiality duties.
Subprocessors
The customer gives general authorization for Eurobase to use the subprocessors listed at /legal/subprocessors. Eurobase will impose written data-protection obligations on each subprocessor that are materially equivalent to this DPA, remains responsible for subprocessor performance, and will use transfer safeguards for restricted transfers as described in the subprocessor notice.
Assistance
Taking into account the nature of processing and information available to Eurobase, Eurobase will assist the customer with data-subject requests, security obligations under Article 32, personal-data breach handling under Articles 33 and 34, DPIAs and prior consultation under Articles 35 and 36, audit information, and records needed to show Article 28 compliance. Audit or inspection requests must be reasonable, scoped to customer workload data, protective of other tenants and platform security, and sent to privacy@eurobase.dev.
End
At the customer's choice, Eurobase will delete or return customer personal data after processing services end and delete existing copies, unless EU or Member State law requires storage (GDPR Article 28(3)(g)). Send return or deletion instructions to privacy@eurobase.dev. Eurobase's separate controller records, such as required invoices, follow their own lawful retention; they do not create a general exception for customer workload data.
The retention table describes current log cleanup, aggregation, delivery-spool removal and account deletion limits. Project logs become eligible for cleanup thirty days after ingestion and can be removed sooner under the per-category volume limit. Unfinished aggregation and cleanup failures can delay removal. Aggregation does not automatically delete raw usage or delivery receipts. No fixed backup expiry or end-of-service deletion deadline is currently confirmed; Eurobase must address remaining copies and any legal storage exception when handling the customer's instructions.