Last updated: July 9, 2026
Effective date: July 9, 2026
This DPA is incorporated into the Terms of Service and becomes effective when a customer accepts the Terms of Service, creates an account, or uses Dalmatius subscription software. It applies between Dalmatius.com, operated from Europe, and the customer only to personal data processed by Dalmatius as processor on behalf of the customer.
If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA controls for that data-protection matter. The Terms of Service continue to apply to all other matters.
For customer-controlled data entered into the software, the customer is the controller and Dalmatius is the processor. For Dalmatius account, billing, website, security, support, and product-improvement data, Dalmatius may act as controller as described in the Privacy Policy.
The customer is responsible for having a lawful basis for the personal data it submits to Dalmatius, providing legally required notices, handling its own controller obligations, and ensuring its instructions are lawful.
Dalmatius processes customer personal data only on documented customer instructions, including the Terms of Service, this DPA, product configuration, support requests, and other written instructions consistent with the subscription software. If Dalmatius believes an instruction violates applicable data protection law, it will notify the customer where legally permitted.
Customer personal data may include names, emails, roles, customer records, order records, analytics metadata, operational records, support messages, identifiers, and technical logs relating to the customer's users, staff, customers, or business contacts.
Dalmatius ensures that persons authorized to process customer personal data are bound by confidentiality obligations or are under an appropriate statutory duty of confidentiality.
Dalmatius implements appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure, taking into account the nature, scope, context, and purposes of processing and the risks to individuals. Measures may include access controls, least-privilege access, backups, logging, encryption or provider security controls where appropriate, and operational security practices.
The customer gives Dalmatius general authorization to use subprocessors for hosting, databases, storage, email delivery, analytics, billing, tax calculation, fraud prevention, monitoring, security, and support. Dalmatius remains responsible for subprocessors used to process customer personal data and requires them to protect data under written terms that are no less protective than this DPA in substance.
Dalmatius may add or replace subprocessors as the software evolves. Where required by GDPR, Dalmatius will provide notice of new subprocessors through the website, product, email, or another reasonable method. Customers may object on reasonable data-protection grounds within 14 days after notice. If the objection cannot be resolved, the customer may stop using the affected feature or terminate the affected subscription as its exclusive remedy.
Customer personal data may be processed in countries outside the customer's country. Where GDPR transfer rules apply, Dalmatius will use appropriate safeguards such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism where required.
Taking into account the nature of the processing and information available to Dalmatius, Dalmatius will provide reasonable assistance with data-subject requests, security obligations, personal-data breach notifications, data protection impact assessments, prior consultations, and regulator inquiries where required by applicable data protection law.
Dalmatius will notify affected customers without undue delay after becoming aware of a personal-data breach affecting customer personal data, where required by law, and will provide reasonable information available to help customers meet their own obligations.
At the end of the subscription, and where technically available, the customer may export customer personal data from the software before access ends. After termination, Dalmatius may retain customer personal data for a limited period for export, backup, billing, security, legal compliance, and dispute handling. After that period, Dalmatius will delete or anonymize customer personal data unless law requires retention. If the customer has a legally required deletion or return instruction, it may contact legal@dalmatius.com.
Dalmatius will make information reasonably necessary to demonstrate compliance with this DPA available to customers on request. Audits are handled document-first through security summaries, policy information, subprocessors information, and written responses. On-site audits are only available where legally required, no more than once per year unless required after a material incident, during normal business hours, with reasonable notice, subject to confidentiality, and limited to systems relevant to the customer's personal data.
Data protection questions can be sent to legal@dalmatius.com.