Data Processing Agreement

Version 1.0 · Effective: 27 April 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Displaydev OÜ ("Processor", "we", "us") and the customer entity that has accepted those terms ("Controller", "you"). It applies where the Controller uses display.dev to process personal data of its own users, employees, or other data subjects.

This DPA reflects the parties' agreement on the processing of personal data in accordance with the requirements of the EU General Data Protection Regulation (2016/679) ("GDPR") and, where applicable, other applicable data protection laws.


1. Definitions

TermMeaning
ControllerThe customer entity that determines the purposes and means of processing personal data through the Service
ProcessorDisplaydev OÜ, which processes personal data on behalf of the Controller
Data SubjectThe natural person to whom the personal data relates
Personal DataAny information relating to an identified or identifiable natural person, as defined in GDPR Art. 4(1)
ProcessingAny operation performed on personal data, as defined in GDPR Art. 4(2)
Sub-processorAny third party engaged by the Processor to process personal data under this DPA
ServiceThe display.dev platform and associated services as described in the Terms of Service
Standard Contractual Clauses (SCCs)The clauses adopted by the European Commission Decision 2021/914 for international data transfers

2. Subject Matter and Duration

Subject matter: The Processor will process personal data submitted to the Service by or on behalf of the Controller in connection with the Controller's use of the Service.

Duration: This DPA is effective for the duration of the Controller's subscription to the Service and terminates automatically upon termination or expiry of the Terms of Service, subject to the post-termination obligations in Section 11.


3. Nature and Purpose of Processing

The Processor processes personal data solely to provide the Service to the Controller. The processing activities include:

  • Hosting and serving artifacts (HTML, Markdown) uploaded by the Controller
  • Authenticating authorised viewers via one-time codes sent to email addresses provided by the Controller
  • Logging viewer access events associated with the Controller's artifacts
  • Providing the Controller with aggregate usage analytics for their artifacts
  • Maintaining audit logs of administrative actions within the Controller's organisation

The Processor does not process personal data for its own commercial purposes (including advertising or profiling) beyond what is necessary to provide the Service.


4. Types of Personal Data and Categories of Data Subjects

4.1 Types of personal data processed

CategoryExamples
Viewer identity dataEmail addresses of individuals invited to view private artifacts
Viewer access eventsTimestamp, artifact identifier, and authentication method for each viewer access
Aggregate view analyticsView counts per artifact per day (no individual identity retained)

The Controller determines what personal data is submitted to the Service. The Processor does not control or validate the types of personal data the Controller chooses to include in artifacts or guest viewer lists.

4.2 Categories of data subjects

  • Employees, contractors, and other personnel of the Controller
  • Customers, clients, or end users of the Controller who are granted viewer access to artifacts
  • Any other natural persons whose personal data the Controller submits to the Service

5. Processor Obligations

5.1 Documented instructions

The Processor will process personal data only on the documented instructions of the Controller, as set out in this DPA and the Terms of Service. If the Processor is required by applicable law to process personal data beyond those instructions, it will inform the Controller before such processing unless prohibited by law.

If the Processor believes an instruction violates GDPR or other applicable data protection law, it will promptly notify the Controller.

5.2 Confidentiality

The Processor will ensure that all personnel authorised to process personal data under this DPA are subject to an obligation of confidentiality, whether by contract or statutory duty.

5.3 Security

The Processor will implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with GDPR Art. 32. The measures currently in place are described in Schedule C.

5.4 Sub-processors

Authorisation: The Controller grants the Processor general authorisation to engage sub-processors. The current list of sub-processors is set out in Schedule B.

Change notification: The Processor will notify the Controller at least 14 days before adding or replacing a sub-processor by updating Schedule B and sending a notification to the email address associated with the Controller's account (or via a notice in the Service).

Objection: The Controller may object to a new sub-processor on reasonable grounds relating to data protection within 10 days of notification. If the parties cannot resolve the objection, either party may terminate the affected part of the Service on written notice without penalty.

Sub-processor contracts: The Processor will impose data protection obligations on each sub-processor that are equivalent to those in this DPA and will remain fully liable to the Controller for any failure by a sub-processor to fulfil its obligations.

5.5 Data subject rights

The Processor will provide the Controller with reasonable assistance to fulfil the Controller's obligations to respond to requests from data subjects exercising their rights under GDPR (Articles 15–22). Where a data subject contacts the Processor directly, the Processor will redirect the request to the Controller without undue delay.

5.6 Assistance with compliance obligations

The Processor will provide reasonable assistance to the Controller in ensuring compliance with the Controller's obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to the Processor.

5.7 Security incidents

The Processor will notify the Controller without undue delay — and in any event within 72 hours of becoming aware — of any personal data breach affecting the Controller's data. The notification will include:

  • A description of the nature of the breach
  • The categories and approximate number of data subjects affected
  • The categories and approximate number of personal data records affected
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach

5.8 Data protection impact assessments

At the Controller's request, the Processor will provide reasonable information to assist the Controller in conducting a data protection impact assessment (DPIA) under GDPR Art. 35, to the extent such information relates to the Processor's processing activities.

5.9 Deletion and return of data

Upon termination or expiry of the Terms of Service, the Processor will, at the Controller's election:

  • Delete all personal data processed under this DPA within 30 days of termination, except where retention is required by applicable law; or
  • Return a machine-readable export of the Controller's data within 30 days of a written request made before termination.

The Processor will certify deletion in writing upon request.

5.10 Audit and information rights

The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and GDPR Art. 28. The Controller may:

  • Request a summary of the Processor's relevant security documentation once per calendar year; and
  • Conduct an audit of the Processor's processing activities at the Controller's expense, on at least 14 days' written notice, during normal business hours, and subject to reasonable confidentiality obligations. Audits must not unreasonably disrupt the Processor's operations.

6. Controller Obligations

The Controller represents and warrants that:

  • It has a lawful basis for processing the personal data submitted to the Service
  • It has provided all required notices to, and obtained all required consents from, data subjects whose personal data is processed under this DPA
  • Its instructions to the Processor comply with applicable data protection laws
  • It is responsible for the accuracy, quality, and legality of personal data submitted to the Service

7. International Data Transfers

Where the Processor transfers personal data to sub-processors in countries outside the EU/EEA that do not benefit from an adequacy decision, the Processor will ensure such transfers are governed by the EU Standard Contractual Clauses (SCCs) (Commission Decision 2021/914) or another valid transfer mechanism. Details of transfer mechanisms per sub-processor are set out in Schedule B.

Where required, the Controller authorises the Processor to enter into SCCs with sub-processors on the Controller's behalf as an alternative or additional transfer mechanism.


8. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability where such limitation is not permitted by applicable law (including liability for fraud or wilful misconduct).


9. Order of Precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA takes precedence with respect to the subject matter of data protection.


10. Governing Law and Jurisdiction

This DPA is governed by the laws of Estonia. The parties submit to the exclusive jurisdiction of the Estonian courts, except where applicable data protection law requires otherwise.


11. Termination

This DPA terminates automatically on termination of the Terms of Service. Sections 5.9 (deletion/return), 8 (liability), and 10 (governing law) survive termination.


Schedule A — Details of Processing

FieldDetails
Subject matterProvision of the display.dev artifact publishing and viewer authentication service
DurationFor the term of the Controller's subscription
Nature of processingStorage, retrieval, transmission, and deletion of artifacts; viewer authentication; analytics
PurposeEnabling the Controller to publish and gate access to HTML/Markdown artifacts
Types of personal dataViewer email addresses; viewer access events; aggregate view counts
Categories of data subjectsController's authorised viewers; Controller's organisation members
Special categoriesNone — the Processor does not knowingly process special categories of personal data

Schedule B — Approved Sub-processors

Sub-processorPurposeLocationTransfer mechanism
Neon (Neon Inc.)Primary database — user accounts, org data, viewer access events, billing records, audit logsUnited StatesStandard Contractual Clauses
PostHog (PostHog Inc.)Product analytics and usage eventsEU (eu.posthog.com)No third-country transfer
Stripe (Stripe, Inc.)Payment processingUnited StatesStandard Contractual Clauses
Cloudflare (Cloudflare, Inc.)CDN, artifact delivery, DDoS protectionGlobal (EU primary where available)Standard Contractual Clauses
Fly.io (Superfly, Inc.)Application hosting and infrastructureUnited States (Ashburn, VA)Standard Contractual Clauses
Postmark (ActiveCampaign, LLC)Transactional email delivery — sign-in OTPs, guest invites, account notificationsUnited StatesStandard Contractual Clauses

The Processor will update this schedule when sub-processors are added or replaced and will provide 14 days' prior notice as described in Section 5.4.


Schedule C — Technical and Organisational Security Measures

MeasureDescription
Encryption in transitAll data transmitted over TLS 1.2 or higher
Encryption at restData stored on Fly.io infrastructure is encrypted at rest
Access controlsProduction system access restricted to authorised personnel, protected by multi-factor authentication
Audit loggingAdministrative actions within organisations are logged for the lifetime of the account
Incident responseSecurity incident response process with internal escalation and 72-hour breach notification obligation
Vendor securitySub-processors are assessed for security practices and bound by DPAs prior to engagement

Schedule D — Acceptance and Versioning

This DPA may be accepted electronically as part of the Terms of Service sign-up flow. The Controller's continued use of the Service after the effective date of a revised DPA constitutes acceptance of the updated terms, subject to the 14-day change notification obligation for sub-processor changes.

VersionEffective dateSummary of changes
1.022 April 2026Initial version