Data Processing Agreement
Last updated: January 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Webbbyy ("Processor") and you ("Controller").
1. Definitions
Personal Data: Any information relating to an identified or identifiable natural person.
Processing: Any operation performed on Personal Data.
Data Subject: The individual to whom Personal Data relates.
2. Processing of Personal Data
Processor shall:
- Process Personal Data only on documented instructions from Controller
- Ensure persons authorized to process Personal Data have committed to confidentiality
- Implement appropriate technical and organizational measures
- Assist Controller in responding to Data Subject requests
3. Security Measures
We implement industry-standard security measures including:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Incident response procedures
4. Sub-processors
Current sub-processors:
- Stripe: Payment processing
- Brevo: Email communications
We will notify you of any intended changes to sub-processors.
5. International Transfers
Personal Data may be transferred to countries outside the EEA. Such transfers are protected by Standard Contractual Clauses or adequacy decisions.
6. Data Subject Rights
We will assist you in fulfilling obligations to respond to Data Subject requests for:
- Access to their Personal Data
- Rectification or erasure
- Restriction of processing
- Data portability
7. Breach Notification
We will notify you without undue delay after becoming aware of a Personal Data breach.
8. Audit Rights
Controller has the right to audit Processor's compliance with this DPA, subject to reasonable notice and confidentiality obligations.
9. Return and Deletion
Upon termination, we will delete or return all Personal Data at your choice, unless retention is required by law.
10. Liability
Each party's liability arising from this DPA shall be subject to the limitations in the Terms of Service.
Contact
Data Protection Officer: [email protected]