Effective Date: 22.08.2026
Version: 2.0
Pursuant to Art. 28 GDPR.
This Data Processing Agreement ("DPA") is entered into between you (the "Controller") and Sliplane, Lukas Mauser, Freienwalder Str. 3, 13359 Berlin (the "Processor"). It governs the processing of personal data the Controller entrusts to the Processor in connection with the Controller's use of the Sliplane services.
The subject of this DPA is the commissioning of the Processor by the Controller and the issuing of instructions regarding the processing of personal data. The processing carried out by the Processor is strictly limited to the activities required to fulfill the underlying main contract. It covers all Sliplane services the Controller uses, including compute servers, managed object storage (buckets), managed PostgreSQL databases, and the backups of these resources.
The term of this DPA corresponds to that of the main contract.
The categories of personal data processed are:
The collected and processed personal data relates to:
(1) Depending on the region the Controller selects for its servers, databases and storage buckets, personal data may be processed inside the EU/EEA (Germany, Finland) or outside it (United States, Singapore). The Controller chooses the region and is responsible for selecting one appropriate to its own compliance requirements.
(2) Where a sub-processor processes personal data outside the EU/EEA, the Processor ensures that an appropriate safeguard under Chapter V GDPR, in particular EU Standard Contractual Clauses or an adequacy decision, is in place before any such transfer. The Processor ensures that the transfer is carried out securely and with appropriate safeguards according to the current state of the art.
(3) The Processor will not move personal data to a region outside the EU/EEA that the Controller did not select, except where required to provide a service the Controller has ordered in that region.
(1) Before the conclusion of this DPA, the Processor undertakes to implement all required technical and organizational security measures and to provide the Controller with a document describing these measures in detail (Annex 1), with specific reference to this agreement.
(2) The Processor guarantees that it has implemented all security measures required by Art. 28(3)(c) and Art. 32 GDPR, especially in connection with Art. 5(1) and (2) GDPR. These measures must ensure data security and an appropriate level of protection regarding confidentiality, integrity, availability, and resilience of systems. According to Art. 32(1) GDPR, the adequacy of the security measures must take into account: compliance with current state of the art, implementation costs, the nature, scope, and purpose of processing, as well as the likelihood and severity of risks to the rights and freedoms of natural persons.
(3) Technical and organizational measures are subject to technological progress and development. The Processor may adopt alternative suitable measures that meet current standards, provided that the security level is not reduced. Significant changes must be documented.
(1) The Processor agrees to cooperate fully, to the extent reasonably possible, to support the Controller in responding to requests from data subjects exercising their rights.
(2) In particular, the Processor undertakes to:
(i) immediately forward to the Controller any request from a data subject to exercise their rights, and
(ii) where possible and appropriate, enable the Controller to design and implement technical and organizational measures necessary to comply with such requests.
(3) While the Controller remains responsible for responding to requests, the Processor may be tasked with handling specific requests, provided these do not impose an unreasonable burden and the Controller issues detailed written instructions.
In addition to compliance with this DPA, the Processor agrees to meet all legal requirements set out in Articles 28–33 GDPR. In particular, the Processor guarantees compliance with:
The Processor's contact point for data protection matters is: Lukas Mauser, Freienwalder Str. 3, 13359 Berlin, support@sliplane.io.
The Processor will promptly inform the Controller of any change to this contact.
Processing under this DPA may only be carried out by persons (e.g., employees, agents, staff) who have been informed about proper data handling and contractually committed to confidentiality under Art. 28(3)(b) and Art. 32 GDPR. The Processor and any person acting under its authority who has access to personal data may only process such data on instructions from the Controller, unless legally required otherwise.
The Processor shall implement and comply with all appropriate measures under Art. 32 GDPR. It will regularly monitor internal processes and security measures to ensure compliance with data protection law and protection of data subjects' rights. The Controller shall be given the ability to verify these measures within the Controller's audit rights under Section 7.
The Controller and Processor shall cooperate with supervisory authorities upon request. The Controller shall be promptly informed of any inspections or measures taken by a supervisory authority in relation to this DPA. If investigations are initiated against the Processor, the Processor will make all efforts to support the Controller.
(1) The Controller authorizes the Processor to subcontract parts of the processing to sub-processors. Such sub-processors must be contractually bound by the same obligations as set out in this DPA in accordance with Art. 28(4) GDPR.
(2) At the time of conclusion, the Processor engages the following sub-processors under such terms:
| # | Sub-Processor | Processing location(s) | Delegated activity | Transfer safeguard |
|---|---|---|---|---|
| 1 | Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Germany (Falkenstein, Nuremberg), Finland (Helsinki) | Hosting of customer servers, managed databases and control plane | Within EU/EEA |
| 2 | DataCamp Limited (DataPacket), 9 Coldbath Square, London, United Kingdom | United States (Seattle) | Hosting of customer servers (US-West region) | Outside EU/EEA, safeguarded under Chapter V (Section 2) |
| 3 | Latitude.sh, Rua Cubatão 929, São Paulo, Brazil | United States (Ashburn), Singapore | Hosting of customer servers (US-East and Singapore regions) | Outside EU/EEA, safeguarded under Chapter V (Section 2) |
| 4 | Impossible Cloud GmbH, Friesenweg 12, 22763 Hamburg, Germany | Germany (Frankfurt), United States (New York) | Managed object storage (buckets) and encrypted backup storage | Frankfurt within EU/EEA; New York safeguarded under Chapter V (Section 2) |
| 5 | Backblaze Inc., 500 Ben Franklin Ct, San Mateo, CA, United States | European Union (Amsterdam) | Encrypted volume and database backups | Storage within EU/EEA; safeguarded under Chapter V (Section 2) |
| 6 | IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany | Germany | Encrypted offsite backups | Within EU/EEA |
(3) Personal data may only be transferred to sub-processors once all requirements of (1) are met.
(4) The Processor shall maintain an up-to-date list of sub-processors and shall notify the Controller in advance of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object. If the Controller objects to a new sub-processor, the Controller may terminate the main contract and this DPA on 30 days' notice; the main contract otherwise continues on its existing terms.
(5) The Processor remains fully responsible and liable for sub-processors' activities.
(6) If a sub-processor operates outside the EU/EEA, the Processor must ensure compliance with the provisions on international transfers as per Section 2 of this DPA.
(1) The Controller has the right to conduct audits or appoint an auditor to do so, assessing compliance with this DPA based on sample checks, for which the Processor will be notified in advance.
(2) The Processor will provide the Controller with necessary information and proof of implementation of security measures.
(3) Proof may include:
(4) The Processor may charge the Controller a reasonable fee for audits.
(1) The Processor will assist the Controller with obligations under Articles 32–36 GDPR, including:
(2) The Processor may charge a reasonable fee for support services not included in the service description or not caused by its own errors.
(1) The Processor may only process data per the Controller's documented instructions, unless required by law.
(2) If the Controller requests changes that may cause GDPR violations, the Processor must inform the Controller immediately and may refrain from executing them.
(1) Each party shall indemnify the other for damages or expenses arising from its own culpable breach of this DPA, including breaches by legal representatives, subcontractors, employees, or agents. Each party also indemnifies the other against third-party claims arising from such breaches.
(2) Art. 82 GDPR remains unaffected.
(1) The Processor may not create copies of data without the Controller's knowledge and approval, except for necessary backups or where retention is legally required.
(2) Upon termination, the Processor shall, at the Controller's choice, delete or return all personal data to the Controller in compliance with GDPR, and delete existing copies, unless further storage is legally required.
(3) The Processor may retain information needed to demonstrate lawful processing beyond contract termination.
(4) Such documentation will be retained as per applicable laws. The Processor may hand over documentation to the Controller, releasing itself from retention obligations.
The parties agree that the competent court at the Processor's place of business in Berlin, Wedding, shall have jurisdiction.
(1) This DPA is concluded electronically. Acceptance by an authorized representative of the Controller through the Sliplane dashboard constitutes binding conclusion of this agreement by both parties, in electronic form within the meaning of Art. 28(9) GDPR.
(2) The Processor is bound as the offering party. The Controller's acceptance is recorded with the accepting user, the date and time, and the version of this document accepted; that record, together with this text, forms the executed agreement, and the Controller can download an executed copy from its team's compliance page at any time.
(1) The Processor may update this DPA from time to time, for example to reflect changes in applicable law, guidance from supervisory authorities, new or amended sub-processors, or new Sliplane services.
(2) The Processor will notify the Controller of any material change in advance and give the Controller the opportunity to object. If the Controller objects to a material change, the Controller may terminate the main contract and this DPA on 30 days' notice.
(3) Non-material changes (such as clarifications that do not reduce the level of protection) take effect upon publication of the updated version.