Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement applies where Dalmatius processes personal data on behalf of a customer as part of the subscription software.

Last updated: July 9, 2026

Effective date: July 9, 2026

Incorporation and scope

This DPA is incorporated into the Terms of Service and becomes effective when a customer accepts the Terms of Service, creates an account, or uses Dalmatius subscription software. It applies between Dalmatius.com, operated from Europe, and the customer only to personal data processed by Dalmatius as processor on behalf of the customer.

Order of precedence

If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA controls for that data-protection matter. The Terms of Service continue to apply to all other matters.

Roles

For customer-controlled data entered into the software, the customer is the controller and Dalmatius is the processor. For Dalmatius account, billing, website, security, support, and product-improvement data, Dalmatius may act as controller as described in the Privacy Policy.

Customer responsibilities

The customer is responsible for having a lawful basis for the personal data it submits to Dalmatius, providing legally required notices, handling its own controller obligations, and ensuring its instructions are lawful.

Documented instructions

Dalmatius processes customer personal data only on documented customer instructions, including the Terms of Service, this DPA, product configuration, support requests, and other written instructions consistent with the subscription software. If Dalmatius believes an instruction violates applicable data protection law, it will notify the customer where legally permitted.

Data subjects and data types

Customer personal data may include names, emails, roles, customer records, order records, analytics metadata, operational records, support messages, identifiers, and technical logs relating to the customer's users, staff, customers, or business contacts.

Confidentiality

Dalmatius ensures that persons authorized to process customer personal data are bound by confidentiality obligations or are under an appropriate statutory duty of confidentiality.

Security measures

Dalmatius implements appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure, taking into account the nature, scope, context, and purposes of processing and the risks to individuals. Measures may include access controls, least-privilege access, backups, logging, encryption or provider security controls where appropriate, and operational security practices.

Subprocessor authorization

The customer gives Dalmatius general authorization to use subprocessors for hosting, databases, storage, email delivery, analytics, billing, tax calculation, fraud prevention, monitoring, security, and support. Dalmatius remains responsible for subprocessors used to process customer personal data and requires them to protect data under written terms that are no less protective than this DPA in substance.

Subprocessor changes

Dalmatius may add or replace subprocessors as the software evolves. Where required by GDPR, Dalmatius will provide notice of new subprocessors through the website, product, email, or another reasonable method. Customers may object on reasonable data-protection grounds within 14 days after notice. If the objection cannot be resolved, the customer may stop using the affected feature or terminate the affected subscription as its exclusive remedy.

International transfers

Customer personal data may be processed in countries outside the customer's country. Where GDPR transfer rules apply, Dalmatius will use appropriate safeguards such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism where required.

Assistance

Taking into account the nature of the processing and information available to Dalmatius, Dalmatius will provide reasonable assistance with data-subject requests, security obligations, personal-data breach notifications, data protection impact assessments, prior consultations, and regulator inquiries where required by applicable data protection law.

Security incidents

Dalmatius will notify affected customers without undue delay after becoming aware of a personal-data breach affecting customer personal data, where required by law, and will provide reasonable information available to help customers meet their own obligations.

Deletion and return

At the end of the subscription, and where technically available, the customer may export customer personal data from the software before access ends. After termination, Dalmatius may retain customer personal data for a limited period for export, backup, billing, security, legal compliance, and dispute handling. After that period, Dalmatius will delete or anonymize customer personal data unless law requires retention. If the customer has a legally required deletion or return instruction, it may contact legal@dalmatius.com.

Audit and information

Dalmatius will make information reasonably necessary to demonstrate compliance with this DPA available to customers on request. Audits are handled document-first through security summaries, policy information, subprocessors information, and written responses. On-site audits are only available where legally required, no more than once per year unless required after a material incident, during normal business hours, with reasonable notice, subject to confidentiality, and limited to systems relevant to the customer's personal data.

Contact

Data protection questions can be sent to legal@dalmatius.com.