This Data Processing Agreement ("DPA") forms part of our Terms of Service and applies when you use Poof to run an application that processes personal data of other people — for example the visitors your analytics app records, or the users of your password manager. For that data, you are the controller and we are your processor, as those terms are defined in the EU General Data Protection Regulation (GDPR).
1. What we process and why
We host and operate the application you choose, together with its database and files, for as long as your subscription is active and during the retention period described in §4 of the Terms of Service. We process the personal data stored in your application only to provide that hosting: to run, update, monitor, stop and restore it, and to delete it at the end. The kinds of data and the people they concern are determined by you and by the application you run.
2. Your instructions
We process this data only on your documented instructions — the Terms of Service, this DPA, and the actions you take in your account — unless the law requires otherwise, in which case we will tell you first where the law allows it. We do not use it for any purpose of our own, and we do not sell it.
3. Confidentiality and security
Only the people who operate the Service can access it, and they are bound to confidentiality. We keep applications isolated from each other, serve them only over HTTPS, store secrets you give us (such as application passwords) encrypted, and record operator actions in an audit log. We do not currently make backups of your application's data; see §4 of the Terms of Service.
4. Sub-processors
You authorise us to use the sub-processors listed on our Sub-processors page. We will update that page before adding a new one; if you object to the change, you may cancel your subscription. We impose data protection obligations on each sub-processor equivalent to those in this DPA.
5. Location and transfers
Your application and its data are hosted in the EU. Where a sub-processor processes data outside the EU or the European Economic Area, it does so under appropriate safeguards required by the GDPR, such as the European Commission's Standard Contractual Clauses.
6. Assistance
Taking into account the nature of the Service, we will help you respond to requests from the people whose data you process and meet your obligations on security, breach notification and impact assessments. Much of this you can do directly in your application.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your application's data, with the information we have at that time, and keep you updated as we learn more.
8. Deletion
When your subscription ends, your application and its data are kept for the retention period in §4 of the Terms of Service and then permanently deleted. Before that, you can export your data using your application's own export features, where it offers them.
9. Information and audits
On request we will provide the information reasonably necessary to demonstrate compliance with this DPA. Requests: legal@poof.run.
10. Precedence
If this DPA and the Terms of Service conflict on the processing of personal data on your behalf, this DPA prevails.