Skip to main content
Legal

Data Processing Agreement

How we process personal data on behalf of our clients.

Last updated: 28 June 2026

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions and of the Service Agreement between Tilizy Digital S.R.L. ("Processor", "we") and the business client ("Controller", "you") whenever we process personal data on your behalf in the course of providing development, support, maintenance, or managed-hosting services. It implements Article 28 of Regulation (EU) 2016/679 ("GDPR").

If a separate signed data-processing agreement exists between the parties, that signed agreement prevails over this DPA.

1. Roles

For personal data contained in the systems, applications, websites, mailboxes, or databases we operate or host for you, you act as controller (or processor on behalf of a third-party controller) and we act as processor. You are responsible for the lawfulness of the processing and for having a valid legal basis and the required information notices in place.

2. Subject-matter, duration, nature, and purpose

  • Subject-matter: processing of personal data necessary to provide the contracted services.
  • Duration: the term of the Service Agreement, plus any limited period needed for return or deletion.
  • Nature and purpose: hosting, storage, backup, transmission, maintenance, support, security operations, troubleshooting, and related technical operations performed on your instructions.

3. Categories of data subjects and personal data

Determined by the content you place in the hosted systems. Typically this includes:

  • Data subjects: your customers, users, employees, contacts, and website visitors.
  • Personal data: identification and contact data, account and authentication data, content of communications (including email content where we host mailboxes), usage and log data, and any other personal data you choose to store. You must not place special categories of data (Art. 9) in the systems unless agreed in writing and with appropriate safeguards.

4. Our obligations as processor

We will:

  • Process only on documented instructions from you, including for international transfers, unless required by EU or Romanian law (in which case we inform you first, unless the law prohibits it). Your instructions are this DPA, the Service Agreement, and your reasonable written instructions; your use of the service constitutes such instruction.
  • Confidentiality: ensure persons authorized to process the data are bound by confidentiality.
  • Security: implement appropriate technical and organizational measures under Article 32 (see Annex 2).
  • Sub-processors: engage sub-processors only under Section 5.
  • Assist you by appropriate technical and organizational measures, insofar as possible, in responding to data-subject requests (Art. 15-22).
  • Assist you in ensuring compliance with Articles 32-36 (security, breach notification, data-protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to us.
  • Personal-data breach: notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information available to help you meet your own notification duties.
  • Deletion or return: at your choice, delete or return all personal data after the end of the services and delete existing copies, unless EU or Romanian law requires storage. On request we provide an export in a commonly used, machine-readable format. Residual copies in routine backups are purged in the normal backup-rotation cycle, within 30 days of the end of the services.
  • Audits: make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and not unreasonably disrupting our operations or other clients.

5. Sub-processors

  • You provide general authorization for us to engage sub-processors to deliver the services. The current sub-processors are listed in our Sub-processor list.
  • We impose on each sub-processor data-protection obligations equivalent to those in this DPA, and we remain fully liable to you for their performance.
  • We will inform you of intended additions or replacements of sub-processors with reasonable prior notice, through the Sub-processor list and by email to your designated contact, giving you the opportunity to object on reasonable data-protection grounds.

6. Processing location and international transfers

By default we process and store your personal data within the European Economic Area (currently on infrastructure located in the EU). Where you require hosting in another region (for example for clients or audiences in North America or Asia), we will provision infrastructure in that region on your instruction, as recorded in the Service Agreement or Annex 1. For any transfer of personal data outside the EEA, the transfer relies on an adequacy decision or appropriate safeguards under Chapter V GDPR (for example Standard Contractual Clauses), and you remain responsible, as controller, for confirming that the chosen location and safeguards meet your compliance requirements.

7. Liability

Liability under this DPA is subject to the limitations of liability in the Terms and Conditions and the Service Agreement, to the extent permitted by the GDPR. Nothing limits liability that the GDPR does not allow to be limited.

8. Order of precedence

In case of conflict on data-protection matters, this DPA prevails over the rest of the Terms and the Service Agreement, except for a separately signed data-processing agreement, which prevails over this DPA.

Annex 1. Processing details

  • Services: as defined in the applicable Service Agreement.
  • Sub-processors: see Sub-processor list.
  • Processing locations: European Economic Area by default (Hetzner data centers in Germany/Finland). Other regions only where instructed by the controller for that engagement.

Annex 2. Technical and organizational measures (Article 32)

Summary of measures we maintain, appropriate to the risk:

  • Encryption: TLS for data in transit and encryption of administrative access (encrypted tunnels); encryption at rest applied where supported by the relevant infrastructure.
  • Access control: least-privilege administrative access, individual accounts, key-based authentication, and audit logging of administrative actions.
  • Network and application security: firewalling, web-application-firewall protection for protected sites, malware scanning for hosted mail, and isolation between client environments.
  • Resilience and backups: automated backups with defined retention, and restore procedures.
  • Patching and monitoring: regular updates, vulnerability and image scanning, uptime and security monitoring, and incident response.
  • Organizational: confidentiality undertakings, change-management and deployment controls, and need-to-know access.

This Annex summarizes the measures we maintain. The binding set of measures for a given engagement is the one stated in the signed Service Agreement or a separately signed data-processing agreement.