Data Processing Agreement
Version 1.0 · Effective: 27 April 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Displaydev OÜ ("Processor", "we", "us") and the customer entity that has accepted those terms ("Controller", "you"). It applies where the Controller uses display.dev to process personal data of its own users, employees, or other data subjects.
This DPA reflects the parties' agreement on the processing of personal data in accordance with the requirements of the EU General Data Protection Regulation (2016/679) ("GDPR") and, where applicable, other applicable data protection laws.
1. Definitions
| Term | Meaning |
|---|---|
| Controller | The customer entity that determines the purposes and means of processing personal data through the Service |
| Processor | Displaydev OÜ, which processes personal data on behalf of the Controller |
| Data Subject | The natural person to whom the personal data relates |
| Personal Data | Any information relating to an identified or identifiable natural person, as defined in GDPR Art. 4(1) |
| Processing | Any operation performed on personal data, as defined in GDPR Art. 4(2) |
| Sub-processor | Any third party engaged by the Processor to process personal data under this DPA |
| Service | The display.dev platform and associated services as described in the Terms of Service |
| Standard Contractual Clauses (SCCs) | The clauses adopted by the European Commission Decision 2021/914 for international data transfers |
2. Subject Matter and Duration
Subject matter: The Processor will process personal data submitted to the Service by or on behalf of the Controller in connection with the Controller's use of the Service.
Duration: This DPA is effective for the duration of the Controller's subscription to the Service and terminates automatically upon termination or expiry of the Terms of Service, subject to the post-termination obligations in Section 11.
3. Nature and Purpose of Processing
The Processor processes personal data solely to provide the Service to the Controller. The processing activities include:
- Hosting and serving artifacts (HTML, Markdown) uploaded by the Controller
- Authenticating authorised viewers via one-time codes sent to email addresses provided by the Controller
- Logging viewer access events associated with the Controller's artifacts
- Providing the Controller with aggregate usage analytics for their artifacts
- Maintaining audit logs of administrative actions within the Controller's organisation
The Processor does not process personal data for its own commercial purposes (including advertising or profiling) beyond what is necessary to provide the Service.
4. Types of Personal Data and Categories of Data Subjects
4.1 Types of personal data processed
| Category | Examples |
|---|---|
| Viewer identity data | Email addresses of individuals invited to view private artifacts |
| Viewer access events | Timestamp, artifact identifier, and authentication method for each viewer access |
| Aggregate view analytics | View counts per artifact per day (no individual identity retained) |
The Controller determines what personal data is submitted to the Service. The Processor does not control or validate the types of personal data the Controller chooses to include in artifacts or guest viewer lists.
4.2 Categories of data subjects
- Employees, contractors, and other personnel of the Controller
- Customers, clients, or end users of the Controller who are granted viewer access to artifacts
- Any other natural persons whose personal data the Controller submits to the Service
5. Processor Obligations
5.1 Documented instructions
The Processor will process personal data only on the documented instructions of the Controller, as set out in this DPA and the Terms of Service. If the Processor is required by applicable law to process personal data beyond those instructions, it will inform the Controller before such processing unless prohibited by law.
If the Processor believes an instruction violates GDPR or other applicable data protection law, it will promptly notify the Controller.
5.2 Confidentiality
The Processor will ensure that all personnel authorised to process personal data under this DPA are subject to an obligation of confidentiality, whether by contract or statutory duty.
5.3 Security
The Processor will implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with GDPR Art. 32. The measures currently in place are described in Schedule C.
5.4 Sub-processors
Authorisation: The Controller grants the Processor general authorisation to engage sub-processors. The current list of sub-processors is set out in Schedule B.
Change notification: The Processor will notify the Controller at least 14 days before adding or replacing a sub-processor by updating Schedule B and sending a notification to the email address associated with the Controller's account (or via a notice in the Service).
Objection: The Controller may object to a new sub-processor on reasonable grounds relating to data protection within 10 days of notification. If the parties cannot resolve the objection, either party may terminate the affected part of the Service on written notice without penalty.
Sub-processor contracts: The Processor will impose data protection obligations on each sub-processor that are equivalent to those in this DPA and will remain fully liable to the Controller for any failure by a sub-processor to fulfil its obligations.
5.5 Data subject rights
The Processor will provide the Controller with reasonable assistance to fulfil the Controller's obligations to respond to requests from data subjects exercising their rights under GDPR (Articles 15–22). Where a data subject contacts the Processor directly, the Processor will redirect the request to the Controller without undue delay.
5.6 Assistance with compliance obligations
The Processor will provide reasonable assistance to the Controller in ensuring compliance with the Controller's obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to the Processor.
5.7 Security incidents
The Processor will notify the Controller without undue delay — and in any event within 72 hours of becoming aware — of any personal data breach affecting the Controller's data. The notification will include:
- A description of the nature of the breach
- The categories and approximate number of data subjects affected
- The categories and approximate number of personal data records affected
- The likely consequences of the breach
- Measures taken or proposed to address the breach
5.8 Data protection impact assessments
At the Controller's request, the Processor will provide reasonable information to assist the Controller in conducting a data protection impact assessment (DPIA) under GDPR Art. 35, to the extent such information relates to the Processor's processing activities.
5.9 Deletion and return of data
Upon termination or expiry of the Terms of Service, the Processor will, at the Controller's election:
- Delete all personal data processed under this DPA within 30 days of termination, except where retention is required by applicable law; or
- Return a machine-readable export of the Controller's data within 30 days of a written request made before termination.
The Processor will certify deletion in writing upon request.
5.10 Audit and information rights
The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and GDPR Art. 28. The Controller may:
- Request a summary of the Processor's relevant security documentation once per calendar year; and
- Conduct an audit of the Processor's processing activities at the Controller's expense, on at least 14 days' written notice, during normal business hours, and subject to reasonable confidentiality obligations. Audits must not unreasonably disrupt the Processor's operations.
6. Controller Obligations
The Controller represents and warrants that:
- It has a lawful basis for processing the personal data submitted to the Service
- It has provided all required notices to, and obtained all required consents from, data subjects whose personal data is processed under this DPA
- Its instructions to the Processor comply with applicable data protection laws
- It is responsible for the accuracy, quality, and legality of personal data submitted to the Service
7. International Data Transfers
Where the Processor transfers personal data to sub-processors in countries outside the EU/EEA that do not benefit from an adequacy decision, the Processor will ensure such transfers are governed by the EU Standard Contractual Clauses (SCCs) (Commission Decision 2021/914) or another valid transfer mechanism. Details of transfer mechanisms per sub-processor are set out in Schedule B.
Where required, the Controller authorises the Processor to enter into SCCs with sub-processors on the Controller's behalf as an alternative or additional transfer mechanism.
8. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability where such limitation is not permitted by applicable law (including liability for fraud or wilful misconduct).
9. Order of Precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA takes precedence with respect to the subject matter of data protection.
10. Governing Law and Jurisdiction
This DPA is governed by the laws of Estonia. The parties submit to the exclusive jurisdiction of the Estonian courts, except where applicable data protection law requires otherwise.
11. Termination
This DPA terminates automatically on termination of the Terms of Service. Sections 5.9 (deletion/return), 8 (liability), and 10 (governing law) survive termination.
Schedule A — Details of Processing
| Field | Details |
|---|---|
| Subject matter | Provision of the display.dev artifact publishing and viewer authentication service |
| Duration | For the term of the Controller's subscription |
| Nature of processing | Storage, retrieval, transmission, and deletion of artifacts; viewer authentication; analytics |
| Purpose | Enabling the Controller to publish and gate access to HTML/Markdown artifacts |
| Types of personal data | Viewer email addresses; viewer access events; aggregate view counts |
| Categories of data subjects | Controller's authorised viewers; Controller's organisation members |
| Special categories | None — the Processor does not knowingly process special categories of personal data |
Schedule B — Approved Sub-processors
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Neon (Neon Inc.) | Primary database — user accounts, org data, viewer access events, billing records, audit logs | United States | Standard Contractual Clauses |
| PostHog (PostHog Inc.) | Product analytics and usage events | EU (eu.posthog.com) | No third-country transfer |
| Stripe (Stripe, Inc.) | Payment processing | United States | Standard Contractual Clauses |
| Cloudflare (Cloudflare, Inc.) | CDN, artifact delivery, DDoS protection | Global (EU primary where available) | Standard Contractual Clauses |
| Fly.io (Superfly, Inc.) | Application hosting and infrastructure | United States (Ashburn, VA) | Standard Contractual Clauses |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery — sign-in OTPs, guest invites, account notifications | United States | Standard Contractual Clauses |
The Processor will update this schedule when sub-processors are added or replaced and will provide 14 days' prior notice as described in Section 5.4.
Schedule C — Technical and Organisational Security Measures
| Measure | Description |
|---|---|
| Encryption in transit | All data transmitted over TLS 1.2 or higher |
| Encryption at rest | Data stored on Fly.io infrastructure is encrypted at rest |
| Access controls | Production system access restricted to authorised personnel, protected by multi-factor authentication |
| Audit logging | Administrative actions within organisations are logged for the lifetime of the account |
| Incident response | Security incident response process with internal escalation and 72-hour breach notification obligation |
| Vendor security | Sub-processors are assessed for security practices and bound by DPAs prior to engagement |
Schedule D — Acceptance and Versioning
This DPA may be accepted electronically as part of the Terms of Service sign-up flow. The Controller's continued use of the Service after the effective date of a revised DPA constitutes acceptance of the updated terms, subject to the 14-day change notification obligation for sub-processor changes.
| Version | Effective date | Summary of changes |
|---|---|---|
| 1.0 | 22 April 2026 | Initial version |