Legal
Data Processing Agreement
Last updated 9 September 2026
This DPA applies automatically where we process personal data on your behalf as a hosting provider.
1. Parties and roles
You are the controller of personal data you store on your server. We are the processor for that data, and a separate controller for your own account and billing data.
Marlena GórzyńskaSole proprietorship registered in the Polish CEIDG
ul. Mariana Seredyńskiego 7/7, 80-753 Gdańsk, Poland
NIP 5833543655 · VAT PL5833543655 · REGON 542305286
order@skycloud-droid.site
2. Subject matter and duration
Subject matter: provision of virtual servers, storage, networking, backups and support. Duration: for as long as your service is active, plus the deletion periods below.
3. Nature, purpose and data
Processing consists of hosting, storage, transmission, backup and deletion, carried out only on your documented instructions. The categories of data subjects and personal data are determined entirely by you as controller.
4. Sub-processors
We use datacentre operators in Frankfurt, Amsterdam and Madrid, Cloudflare for network protection, Supabase for the customer database, Brevo for email and Whop for payments. We give at least 30 days' notice of a new sub-processor and you may terminate without penalty if you reasonably object.
5. Security measures
Encryption in transit and at rest, hardened hypervisors, network segmentation, multi-factor administrative access, least-privilege access control, logging and monitoring, tested restore procedures, and datacentres with 24/7 physical security and ISO 27001 certification.
6. Assistance and breach notification
We assist you with data subject requests, impact assessments and prior consultations to the extent reasonably possible. We notify you of a personal data breach affecting your data without undue delay and in any case within 48 hours of becoming aware.
7. Confidentiality
Every person authorised to process your data is bound by confidentiality obligations that survive the end of the engagement.
8. Audits
On reasonable notice, and at most once a year unless required by an authority, we provide the information needed to demonstrate compliance and allow an audit that does not compromise other customers' security.
9. Deletion and return
On termination, your data is returned or deleted at your choice. Server volumes are destroyed seven days after termination and backups cycle out within 30 days.
10. Transfers
Processing takes place in the EEA. Any transfer outside it relies on the European Commission's Standard Contractual Clauses, incorporated into this DPA by reference.