Data Processing Agreement (DPA)
Last updated: 2026-10-09
Parties. druidori s.r.o., IČO 05164940, Kukučínova 799/10, Hulváky, 709 00 Ostrava, Czech Republic, registered in the Commercial Register kept by the Regional Court in Ostrava, Section C, Insert 66451 ("Processor") and the customer organization accepting the Terms of Service ("Controller").
This DPA forms part of the Terms of Service for customers who use Draftmill for their business.
1. Subject matter and duration
The Processor provides the Draftmill service (template-driven document creation, rendering and export). Processing lasts for the duration of the customer's account and the deletion periods below.
2. Nature and purpose of processing
Storage, rendering, transformation (PDF/DOCX export), transmission and backup of documents and template variables supplied by the Controller.
3. Categories of data and data subjects
Determined by the Controller. Typically: identification and contact data of the Controller's own customers, employees or contractors embedded in document content and variables. The Controller warrants it has a legal basis for the data it submits.
4. Obligations of the Processor (Art. 28(3) GDPR)
The Processor shall:
- process personal data only on documented instructions from the Controller (the functionality of the service constitutes the instruction), including with regard to third-country transfers;
- ensure persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in Annex 1;
- respect the sub-processor conditions in §5;
- taking into account the nature of processing, assist the Controller in responding to data-subject requests (access, erasure, portability — largely self-service in the application);
- assist the Controller with Art. 32–36 obligations (security, breach notification, DPIA) to the extent reasonable;
- at the Controller's choice, delete or return all personal data after the end of services (account deletion is self-service; exports auto-delete after 30 days; backups are deleted after 14 days);
- make available information necessary to demonstrate compliance and allow audits, at most once per year, on 30 days' notice, at the Controller's cost.
5. Sub-processors
General authorisation is granted for the sub-processors listed below. The Processor will announce intended changes at least 14 days in advance; the Controller may object on reasonable data-protection grounds, in which case the Controller may terminate the service.
Where the Processor engages a sub-processor, it imposes on that sub-processor, by contract, the same data-protection obligations as set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of the GDPR (Art. 28(4) GDPR). The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.
| Sub-processor | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Hosting, storage, backups | n/a (EU) |
| Stripe Payments Europe, Ltd. | Ireland (EU) | Subscription management via Stripe Managed Payments (controller-side billing data only) | n/a (EU) |
| Resend (Plus Five Five, Inc.) | USA | Transactional email (e.g. invitations) | EU-U.S. Data Privacy Framework or Standard Contractual Clauses |
6. Transfers outside the EEA
Personal data is transferred outside the European Economic Area only to the sub-processors marked above, and only on the basis of an adequacy decision (the EU-U.S. Data Privacy Framework, where the recipient is certified under it) or of the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914).
7. Breach notification
The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, providing the information required by Art. 33(3) GDPR as it becomes available.
8. Liability and governing law
Liability follows the Terms of Service. This DPA is governed by Czech law.
Annex 1 — Technical and organisational measures (TOMs)
- TLS 1.2+ encryption in transit; HSTS.
- Application-layer tenant isolation on every query (workspace → organization → membership scoping).
- Passwords hashed with bcrypt (cost 12); session revocation on password change.
- Least-privilege object-storage credentials scoped to a single bucket; databases and object storage bound to an internal network, unreachable from the internet; default-deny firewall.
- Sandboxed template evaluation (no code execution from user content); size caps and SSRF filtering on embedded content.
- Automated nightly backups of the database and stored files, retained for 14 days; access restricted to the operator.
- Rate limiting of sign-in and other sensitive operations; web-server access logs kept for 14 days.
- Administrative access to production servers restricted to the operator and protected against brute-force attempts.
Annex 2 — Instructions
The documented instruction is: process the data as necessary to provide the Draftmill functionality invoked by the Controller's users (store, render, export, back up, delete).