Data Processing Agreement
Version 2026-06-19
This Data Processing Agreement ("DPA") is part of, and incorporated into, the Terms of Service between you ("Controller") and VProcess Marcin Żyła, NIP PL6312711151, ul. Derkacza 2/52, 44-122 Gliwice, Poland ("skube", "Processor", "we"). It applies where, in using the Service, you process personal data of others ("Customer Personal Data") on your cluster and we process that data on your behalf. It reflects Article 28 of the EU General Data Protection Regulation (GDPR). Where this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails.
1. Roles and scope
You are the controller (or a processor acting for another controller) of Customer Personal Data; we are your processor. For your own account, billing, and consent data we act as an independent controller under our Privacy Policy, and that processing is not governed by this DPA.
2. Subject matter, nature, and duration
- Subject matter and purpose: providing the Service, namely provisioning, operating, supporting, and decommissioning your single-tenant Kubernetes cluster.
- Nature of processing: hosting and storage on infrastructure we manage, plus any administrative access needed to deliver the Service, as described in Section 4.
- Duration: for as long as we provide the Service to you, until the cluster is decommissioned and data deleted under Section 8.
- Categories of data and data subjects: determined by you, since you control what you place on your cluster. We do not require, and do not in the ordinary course inspect, the contents of your workloads.
3. Your instructions
We process Customer Personal Data only on your documented instructions, including as to international transfers, unless required to act by EU or member-state law (in which case we will inform you, unless that law prohibits it). Your instructions are this DPA, the Terms, and your configuration and use of the Service. We will inform you if, in our opinion, an instruction infringes the GDPR or other data-protection law.
4. Confidentiality and access
Your clusters are single-tenant. We do not access the contents of your workloads in the ordinary course, but may need administrative access to provision, maintain, support, or decommission a cluster, or to comply with law. We ensure that persons authorized to process Customer Personal Data are bound by confidentiality and process it only on our instructions.
5. Security
We implement appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art and the risk. These include encrypted transport, single-tenant isolation of clusters, restricted and logged administrative access, and hardened host provisioning. You are responsible for the security measures within your cluster and workloads, including access controls, encryption of data you store, and backups. A current summary of our measures is available on request.
6. Sub-processors
You give general authorization for us to engage sub-processors to deliver the Service. Our current sub-processors, and the role each performs, are the infrastructure, hosting, authentication, email, and DNS providers listed in Section 3 of our Privacy Policy. We impose data-protection obligations on each sub-processor no less protective than this DPA, and we remain responsible for their performance. We will give you prior notice of any new or replacement sub-processor (by email or in the Service), and you have 30 days from that notice to object on reasonable data-protection grounds. If you do not object within that period, you are deemed to accept the change. If you raise a justified objection we cannot resolve, you may terminate the affected Service, and we will refund any fees you have prepaid for the period after termination.
7. Assistance
Taking into account the nature of the processing, we will assist you, by appropriate technical and organizational measures and as far as possible, to respond to requests from data subjects exercising their rights, and to meet your obligations on security, breach notification, data-protection impact assessments, and prior consultation (Articles 32 to 36 GDPR). We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information you reasonably need to meet your own notification duties.
8. Return and deletion
On termination of the Service, or earlier at your instruction, we delete Customer Personal Data by decommissioning the cluster, which permanently destroys its data, unless EU or member-state law requires continued storage. Throughout the Service you keep cluster-admin access and can export or return Customer Personal Data yourself at any time before termination; that self-service export is how we make return available to you for the purposes of Article 28(3)(g) GDPR. Decommissioning is irreversible, so export anything you need first.
9. Audits
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To protect the security and single-tenancy of other customers, audits are on reasonable prior notice, no more than once a year except where required by a supervisory authority or after a breach, and may be satisfied by our providing documentation of our measures.
10. International transfers
Where processing Customer Personal Data involves a transfer outside the European Economic Area, we rely on appropriate safeguards under the GDPR, such as the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses, which are incorporated by reference; a copy is available on request.
11. Contact
For any matter under this DPA, contact VProcess Marcin Żyła at support@skube.dev.