Data Processing Agreement
Last updated: August 6, 2026
When you save a lead, you are the controller of that data and we are your processor. This agreement is what Art. 28 GDPR requires us to put in writing: what we may do with it, who else touches it, how we secure it, and what happens when you leave. It applies automatically — you do not need to sign anything.
1. Parties and scope
This agreement is between you, the account holder ("Controller"), and Dodera Software S.R.L., Str. Banat nr. 1, ap. 2, 440043 Satu Mare, jud. Satu Mare, Romania, Trade Register J30/958/2023, tax identification code 49004234 ("Processor", "we"). It forms part of the Terms of Service and takes effect when you create an account. No signature is needed; if you require a countersigned copy, write to office@doderasoft.com.
It covers only the personal data we process on your behalf — the business and contact data you search for, save, enrich, annotate and act on inside your workspace. The data we hold about you as our customer is processed under our own responsibility as controller, and is covered by the Privacy Policy, not this agreement. Where this agreement and the Terms conflict on data protection, this agreement wins.
Terms used here — controller, processor, personal data, processing, personal data breach, supervisory authority — have the meaning given to them in Regulation (EU) 2016/679 ("GDPR").
2. Details of the processing
As required by Art. 28(3) GDPR:
| Detail | |
|---|---|
| Subject matter | Provision of the PawByTech service: business search, enrichment, scoring, pipeline tracking, notes, and AI generation of mock sites and outreach drafts. |
| Duration | For as long as you hold an account, plus the deletion periods in clause 9. |
| Nature and purpose | Collection, retrieval, structuring, storage, enrichment, analysis and deletion, carried out to let you identify and manage prospective business customers. |
| Types of personal data | Business name and address; phone numbers; website addresses; email addresses published on business websites; social media profiles; opening hours, ratings and photographs; and any notes, stages, assignees, follow-up dates and outreach drafts you add. |
| Categories of data subjects | Owners, representatives and staff of the businesses you search for — in particular sole traders and other individuals whose contact details are published by the business. |
| Special category data | None. The service is not designed for it and you must not enter it. |
3. Your obligations as controller
You warrant that:
- you have a lawful basis under Art. 6 GDPR for every business and contact record you collect through the service, and for contacting the people behind it;
- you provide the information Art. 14 GDPR requires when you first contact a person whose details you did not get from them, including naming the source;
- you comply with the marketing rules that apply to the recipient, including art. 12 of Law 506/2004 in Romania;
- your instructions to us — the actions you take in the app — do not require us to break data protection law;
- you do not enter special category data or criminal offence data into the service.
4. Our obligations as processor
We will:
- Process only on your documented instructions, including for transfers outside the EEA. Your use of the features in the app constitutes those instructions; any other instruction must be sent in writing and we may charge for work outside the normal service. If the law obliges us to process for another reason, we will tell you first unless that law forbids it (Art. 28(3)(a)).
- Tell you if an instruction appears to infringe the GDPR or other Union or Member State data protection law, and may suspend that instruction until it is resolved (Art. 28(3), final paragraph).
- Bind everyone with access to confidentiality, and grant access only to people who need it to run or support the service (Art. 28(3)(b)).
- Keep the security measures in clause 10, appropriate to the risk (Art. 28(3)(c) and Art. 32).
- Engage sub-processors only under clause 7 (Art. 28(3)(d) and Art. 28(2)).
- Help you answer data subjects. The app already lets you find, edit, export and delete any record yourself; where that is not enough, we will assist by appropriate technical and organisational measures (Art. 28(3)(e)).
- Help you meet Arts. 32 to 36 — security, breach notification, impact assessments and prior consultation — taking into account what we know and what is available to us (Art. 28(3)(f)).
- Delete or return the data at the end, as clause 9 sets out (Art. 28(3)(g)).
- Make available the information needed to show compliance, and allow audits under clause 8 (Art. 28(3)(h)).
- Never use your workspace data for our own purposes — not to build a product, not to sell, not to train an AI model.
5. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and in any case within 48 hours. The notice will describe what happened, the categories and approximate number of records involved, the likely consequences, and the measures taken or proposed. Notifying your supervisory authority under Art. 33, and the data subjects under Art. 34, remains your responsibility as controller.
6. International transfers
The service runs in Germany. Data leaves the EEA only through the sub-processors in clause 7, and only under a valid Chapter V transfer mechanism — the Standard Contractual Clauses in Implementing Decision (EU) 2021/914, or an adequacy decision where one covers the provider. You instruct and authorise those transfers by using the corresponding features. We will make a copy of the safeguards available on request.
7. Sub-processors
You give general written authorisation for the sub-processors below. We impose data protection obligations on each of them that are no less protective than those in this agreement, and we remain fully liable to you for their performance.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Application server, Postgres database and object storage | Germany (EEA) | No transfer — data stays in the EEA |
| Anthropic PBC | AI generation of mock sites and outreach drafts | United States | EU Standard Contractual Clauses (Decision 2021/914), Module 3 |
| Stripe Payments Europe, Ltd. | Payments, subscriptions and invoices | Ireland (EEA), with onward transfer to Stripe, Inc. | EU Standard Contractual Clauses and EU-US Data Privacy Framework |
| Google Ireland Ltd. | Business search (Places API), performance audits (PageSpeed), Google sign-in | Ireland (EEA), with onward transfer to Google LLC | EU Standard Contractual Clauses and EU-US Data Privacy Framework |
| Zoho Corporation B.V. | Delivery of account emails (verification, sign-in links, invitations) | Netherlands (EEA), data centres in Amsterdam and Dublin | No transfer — the EU service keeps data in the EEA |
Before adding or replacing a sub-processor we will give you at least 30 days' notice by email or in the app. If you have a reasonable data protection objection, tell us within that period and we will work with you to find an alternative. If we cannot, you may terminate the affected part of the service and receive a refund of the unused portion of what you have paid.
8. Audits
On reasonable written notice, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will provide the information needed to demonstrate compliance with Art. 28. Where a documented answer is not enough, we will allow an audit or inspection by you or an independent auditor you mandate, during business hours, subject to confidentiality and to not disturbing other customers' data or the security of the service. You bear the cost of an audit unless it uncovers a material breach on our side.
9. Return and deletion
- You can export your board and delete any record at any time, while your account is active.
- When a workspace is deleted, its data is deleted from the database immediately. Deleting your own account does not by itself delete a workspace — its owner deletes it, or you can ask us to erase it.
- Generated mock sites are deleted automatically 60 days after creation, regardless.
- We keep nothing afterwards except what Union or Member State law requires us to keep — in practice accounting records, which contain no workspace data.
10. Security measures
The technical and organisational measures we maintain under Art. 32 GDPR. We may change them, but not in a way that materially weakens security.
| Area | Measure |
|---|---|
| Encryption in transit | All traffic served over TLS; outbound calls to providers over HTTPS. |
| Access control | Every request is authenticated and scoped to the workspace it belongs to. Roles separate owners, admins and members. Private notes are visible only to their author. |
| Authentication | Passwords stored hashed. Session cookies are HTTP-only and secure. Email verification on sign-up. Rate limits on sign-in, sign-up and password reset. |
| Application hardening | Content security policy blocking third-party scripts, framing and object embedding; per-route rate limiting on the API; input validated against schemas at every endpoint. |
| Segregation | Data is partitioned by workspace at the database level, with cascade deletion when a workspace is removed. |
| Hosting | Servers, database and object storage located in Germany (EEA). |
| Deletion | Generated sites and their public links are purged automatically 60 days after creation. Account deletion cascades to workspace content. |
11. Liability and duration
This agreement lasts as long as we process personal data on your behalf. The liability limits in the Terms of Service apply to it, except where Art. 82 GDPR provides otherwise — neither of us can contract out of our liability to a data subject.
12. Contact
Data protection matters under this agreement: office@doderasoft.com.
