Customer-instructed processing
Data Processing Addendum
Draft Article 28 terms for the limited cases in which the hosted provider processes customer personal data on documented instructions.
Pre-publication draft: this document is not an approved public-beta contract. Publication and open registration remain disabled.
Document: dpa
Version: 2026-08-29-public-beta-draft-1
Effective date: 2026-08-29
Canonical localized-content SHA-256: 0c4a3f6da35faae8b8b4d7e115503eec6f79dafe77cba082ca6168068edb758a
Approved multilingual document SHA-256: 8289456c2f7890be46d829e568a94ba3b60e4e5f65d8f68225236484a3dee05e
Privacy: privacy@gutmask.xyz
Parties, scope, and roles
This Addendum applies only when a customer is controller, or processor for another controller, and Will be added later processes customer personal data solely to provide the contracted hosted function.
Account, contract, licence, abuse, security, billing-free beta administration, and legal-compliance records processed for the provider's own purposes remain subject to the Privacy Notice and are not customer-instructed data merely because the same person uses the service.
- Customer: the holder identified in the accepted service record.
- Processor: Will be added later at Will be added later.
- Privacy contact: privacy@gutmask.xyz
- If the customer is itself a processor, its lawful controller instructions and authorization must cover these subprocessors.
Documented instructions and confidentiality
The processor handles customer personal data only on the documented instructions in the agreement, product configuration, and authorized support request, including transfers, unless applicable law requires otherwise. The processor informs the customer before legally required processing unless law prohibits that notice.
If an instruction appears to violate applicable data-protection law, the processor informs the customer and may suspend that instruction while the issue is resolved.
- Authorized people are bound to confidentiality and receive least-privilege access.
- The customer is responsible for lawful instructions, notices, legal bases, data accuracy, and configured retention.
- Raw credentials, private keys, and unrelated personal data must not be sent through support.
- No sale, advertising use, or independent profiling of customer-instructed data is permitted.
Security measures
The processor maintains measures appropriate to risk, including identity and access control, MFA for privileged access, encryption where appropriate, audit, environment separation, vulnerability and release controls, backup and recovery, incident handling, and personnel/process restrictions.
The exact technical and organizational measures for the deployed release are attached or content-addressed as the Security annex and may improve without materially reducing protection.
- No certification, penetration-test scope, availability level, or absolute security is implied unless exact current evidence is attached.
- The customer applies shipped hardening, access, backup, and update guidance within its control.
- Security changes that materially reduce protection require advance notice where practicable and a lawful remedy.
Subprocessors
The customer gives general authorization for the subprocessors listed in the current Subprocessors document for the exact hosted contour. Each subprocessor is bound to data-protection duties no less protective for its assigned processing.
- The processor gives advance notice of a material new or replacement subprocessor using the agreed channel and notice period.
- The customer may object on reasonable data-protection grounds during that period.
- If no reasonable alternative is available, either party may end the affected service without a future charge; mandatory remedies remain available.
- The processor remains responsible for its subprocessor duties as required by applicable law.
Assistance and incidents
Taking account of the processing, the processor assists the customer with data-subject requests, security, breach assessment and notice, impact assessments, prior consultation, and information needed to demonstrate compliance.
The processor notifies the customer without undue delay after becoming aware of a personal-data breach affecting customer-instructed data and provides available facts in stages without delaying the first notice.
- The customer remains responsible for deciding whether and how to notify its authority and affected people unless law assigns that duty otherwise.
- Assistance is proportionate to the service and does not require disclosure that would weaken another customer's security or violate law.
- Incident records contain only the minimum necessary evidence.
International transfers
Customer-instructed data is processed only in the countries and access locations listed in the approved annex and Subprocessors document. A transfer outside the European Economic Area requires the recorded legal mechanism and required supplementary safeguards.
Routine technical access from Russia is not authorized for European customer personal data until the exact controller-to-processor arrangement, applicable standard contractual clauses, transfer assessment, security measures, and public disclosure are completed.
- A provider's global infrastructure is not described as EU-only unless current contractual and technical evidence proves it.
- The customer is told the applicable transfer mechanism before affected processing begins.
- A legally binding government request is assessed, narrowed, challenged where reasonable, and disclosed where law permits.
Return, deletion, and audit information
At the end of the affected service, the processor returns or deletes customer-instructed data at the customer's choice, unless law requires retention. Isolated backups expire through the documented rotation and are not restored for ordinary use after deletion.
The processor provides information reasonably necessary to demonstrate compliance and supports a proportionate audit arrangement that protects security, confidentiality, and other customers.
- Existing current reports and independent evidence are used before intrusive inspection where sufficient.
- Audit timing, scope, confidentiality, and reasonable cost allocation are agreed in good faith; a material suspected breach is not hidden behind an unreasonable fee.
- Deletion and export evidence is bound to the exact account or customer request.
- Duties that must survive termination remain in force for retained data.
Required annex facts
Before approval, the annex must identify subject matter, duration, nature and purpose, data subjects, data categories, special-category restrictions, customer instructions, security measures, subprocessors, processing and access countries, transfer mechanisms, retention, backup deletion, and return or exit procedure.
- Unknown deployment, provider, location, access, or transfer facts remain blockers and are not inferred from code or marketing.
- The Addendum becomes effective only with the exact accepted service documents and verified party details.
- Governing-law basis: Will be added later
- Privacy questions: privacy@gutmask.xyz