Data Processing Agreement
Data Processing Agreement
Effective Date: August 19, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Goodrepublic UG (haftungsbeschraenkt), Karl-Kunger-Strasse, 12435 Berlin, Germany ("Processor," "Opsily," "we") and the customer ("Controller," "you"), and applies whenever we process personal data on your behalf in connection with the Service. It is incorporated into the Terms of Service automatically - no separate signature is required.
1. Definitions
"Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Sub-processor" have the meanings given in Regulation (EU) 2016/679 (GDPR).
2. Roles of the Parties
You are the Controller of any personal data processed through the Service. We are the Processor. We process personal data only as necessary to provide the Service and only on your documented instructions, as set out in the Terms of Service and this DPA.
3. Scope
- Subject matter: provision of hosting infrastructure and related services.
- Duration: for as long as the Terms of Service remain in effect.
- Nature and purpose: hosting server infrastructure on which your chosen applications run; we access application-level personal data only if you explicitly request our assistance (e.g. support).
- Categories of data subjects: your end users, employees, or contacts, as determined by your use of the Service.
- Categories of personal data: determined by you, based on what you input into your hosted application.
4. Processor Obligations
We will:
- Process personal data only on your documented instructions, unless required to do otherwise by EU or member state law;
- Ensure persons authorized to process personal data are bound by confidentiality;
- Implement appropriate technical and organizational security measures (Section 7);
- Assist you, to the extent reasonably possible, in responding to data subject rights requests and in meeting your obligations under Art. 32-36 GDPR;
- Delete or return all personal data at the end of the provision of services, per Section 8;
- Make available information reasonably necessary to demonstrate compliance with this DPA (Section 9).
5. Sub-processors
You provide general authorization for us to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server infrastructure hosting | Germany (EU), or another Hetzner EU region if you select one |
| Amazon Web Services (S3) | Encrypted backup storage | Frankfurt, Germany (EU) |
| Amazon Web Services (SES) | Transactional email delivery | EU |
| Stripe, Inc. | Payment processing | EU / per Stripe's own data processing terms |
We will give you at least 14 days' notice before engaging a new sub-processor, by updating this page or notifying you by email. If you object to a new sub-processor and we are unable to resolve your objection, your sole remedy is to terminate the affected Service.
6. Data Location & International Transfers
Personal data processed through the Service is stored in the EU (Germany) by default. If you choose to deploy your server in a non-EU Hetzner region, your data will be located there instead - this is your choice, not ours. We do not otherwise transfer personal data outside the EU/EEA. Where any sub-processor does involve a transfer outside the EU/EEA, it is conducted on the basis of appropriate safeguards (such as Standard Contractual Clauses).
7. Security Measures (Art. 32 GDPR)
We maintain the following technical and organizational measures:
- TLS 1.3 encryption in transit for all customer traffic;
- Encrypted backup storage at rest (AWS S3, Frankfurt);
- Per-server, unique SSH-key-based access control (no shared credentials);
- Firewall (UFW) and intrusion-prevention (fail2ban) on all servers;
- Administrative access to our management systems restricted to an isolated network (WireGuard).
We do not currently hold ISO 27001, SOC 2, or equivalent third-party security certifications.
8. Deletion of Data
Upon termination of the Service, your server, hosted application, and associated data are deleted immediately, except free-trial usage of "Ship," which is retained for 30 days after trial expiry before deletion. Account metadata (e.g. name, email) is retained for up to 12 months after account closure and then deleted or anonymized, except where we are legally required to retain records for longer (e.g. invoicing records, retained for 10 years under German tax law, Section 147 AO).
9. Audit & Compliance
On written request, we will provide you with reasonably requested documentation to demonstrate compliance with this DPA, no more than once every 12 months. We do not offer on-site or third-party audit rights.
10. Data Breach Notification
We will notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting your data, to enable you to meet your own regulatory notification obligations.
11. Liability
Liability under this DPA is subject to the limitation of liability set out in our Terms of Service.
12. Governing Law
This DPA is governed by the laws of Germany, consistent with the Terms of Service.
Contact
Data protection queries: security@opsily.com
Goodrepublic UG (haftungsbeschraenkt) - Karl-Kunger-Strasse, 12435 Berlin, Germany - HRB 243161 B (Amtsgericht Charlottenburg) - VAT DE353813913