Data Processing Agreement (DPA)

Last updated: 2026-10-09

Parties. druidori s.r.o., IČO 05164940, Kukučínova 799/10, Hulváky, 709 00 Ostrava, Czech Republic, registered in the Commercial Register kept by the Regional Court in Ostrava, Section C, Insert 66451 ("Processor") and the customer organization accepting the Terms of Service ("Controller").

This DPA forms part of the Terms of Service for customers who use Draftmill for their business.

1. Subject matter and duration

The Processor provides the Draftmill service (template-driven document creation, rendering and export). Processing lasts for the duration of the customer's account and the deletion periods below.

2. Nature and purpose of processing

Storage, rendering, transformation (PDF/DOCX export), transmission and backup of documents and template variables supplied by the Controller.

3. Categories of data and data subjects

Determined by the Controller. Typically: identification and contact data of the Controller's own customers, employees or contractors embedded in document content and variables. The Controller warrants it has a legal basis for the data it submits.

4. Obligations of the Processor (Art. 28(3) GDPR)

The Processor shall:

  1. process personal data only on documented instructions from the Controller (the functionality of the service constitutes the instruction), including with regard to third-country transfers;
  2. ensure persons authorised to process the data are bound by confidentiality;
  3. implement the technical and organisational measures in Annex 1;
  4. respect the sub-processor conditions in §5;
  5. taking into account the nature of processing, assist the Controller in responding to data-subject requests (access, erasure, portability — largely self-service in the application);
  6. assist the Controller with Art. 32–36 obligations (security, breach notification, DPIA) to the extent reasonable;
  7. at the Controller's choice, delete or return all personal data after the end of services (account deletion is self-service; exports auto-delete after 30 days; backups are deleted after 14 days);
  8. make available information necessary to demonstrate compliance and allow audits, at most once per year, on 30 days' notice, at the Controller's cost.

5. Sub-processors

General authorisation is granted for the sub-processors listed below. The Processor will announce intended changes at least 14 days in advance; the Controller may object on reasonable data-protection grounds, in which case the Controller may terminate the service.

Where the Processor engages a sub-processor, it imposes on that sub-processor, by contract, the same data-protection obligations as set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of the GDPR (Art. 28(4) GDPR). The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.

Sub-processorLocationPurposeTransfer mechanism
Hetzner Online GmbHGermany (EU)Hosting, storage, backupsn/a (EU)
Stripe Payments Europe, Ltd.Ireland (EU)Subscription management via Stripe Managed Payments (controller-side billing data only)n/a (EU)
Resend (Plus Five Five, Inc.)USATransactional email (e.g. invitations)EU-U.S. Data Privacy Framework or Standard Contractual Clauses

6. Transfers outside the EEA

Personal data is transferred outside the European Economic Area only to the sub-processors marked above, and only on the basis of an adequacy decision (the EU-U.S. Data Privacy Framework, where the recipient is certified under it) or of the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914).

7. Breach notification

The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, providing the information required by Art. 33(3) GDPR as it becomes available.

8. Liability and governing law

Liability follows the Terms of Service. This DPA is governed by Czech law.

Annex 1 — Technical and organisational measures (TOMs)

Annex 2 — Instructions

The documented instruction is: process the data as necessary to provide the Draftmill functionality invoked by the Controller's users (store, render, export, back up, delete).

Terms of ServicePrivacy Policy
Data Processing Agreement · Draftmill