Legal
Data Processing Agreement
Version 1.0 · Last updated 15 September 2026
Data processing terms for customers and partners.
1. What this agreement is
This Data Processing Agreement (“DPA”) governs the personal data that Firelent processes on your behalfwhen people use the projects you build and publish — visitors, form submitters, customers of your shop, users of your app, subjects of your project’s analytics (“Project Data”). For that data you are the controller and Firelent UG (haftungsbeschränkt) is your processor within the meaning of Art. 28 GDPR.
The DPA forms part of your contract with us automatically — it applies to every account whose projects process personal data, without a signature ceremony. It does not cover the data Firelent processes as controller (your account, billing, prompts, usage), which the privacy policy governs.
2. Subject matter, duration, nature and purpose
- Subject matter: hosting, storage, transmission, display and technical processing of Project Data through the Firelent platform — publishing, databases and storage for your project, form and order handling, bookings, project analytics, and end-user accounts of your applications.
- Duration: the life of your contract with us, plus the deletion periods in section 9.
- Purpose: providing the Service to you — nothing else. We do not use Project Data for our own purposes, do not sell it, and do not use it to train AI models.
3. Categories of data and data subjects
- Data subjects: visitors and end users of your projects, your customers, and the people whose data you or they enter into your project.
- Data categories:whatever your project collects — contact and account details, order, booking and payment-status records, form submissions, content, and technical usage data (IP-derived approximate location, device type, pages viewed) for your project’s analytics. You control which of these your project actually collects, and you must not build projects that collect special-category data (Art. 9 GDPR) without ensuring a lawful basis yourself.
4. Your instructions
We process Project Data only on your documented instructions. These terms, this DPA, and the actions you take in the product — publishing, configuring forms, enabling a shop, requesting an export or deletion — are your instructions. If we believe an instruction violates data protection law, we tell you and may pause it. If the law of the EU or a member state obliges us to process differently, we inform you before processing, unless that law forbids it.
5. Confidentiality and personnel
Only personnel who need Project Data to provide the Service can access it, and every one of them is bound to confidentiality by contract before touching anything. Access is role-based, logged and reviewed.
6. Security (Art. 32 GDPR)
We implement and maintain the technical and organizational measures described in section 13 of the privacy policy: encryption in transit and at rest, isolation between customer projects, role-based access with multi-factor authentication, secret management for connected integrations, monitoring, logging and vetted providers. We update the measures as the state of the art moves — changes never reduce the overall level of protection.
7. Sub-processors
You authorize the sub-processors we use to run the Service — the infrastructure providers named in section 6 of the privacy policy (hosting, storage and delivery, build and preview infrastructure, payments where your project sells, email delivery). Each is bound by a contract imposing data protection obligations equivalent to this DPA. We give at least 30 days’ notice before adding or replacing a sub-processor that touches Project Data; if you have a substantiated data-protection objection and we cannot offer a workaround, you may terminate the affected part of the Service.
8. Assistance
- Data subject requests: if someone exercises GDPR rights about your project directly with us, we forward the request to you without undue delay and, given the nature of the processing, assist you with appropriate technical means — export, deletion and correction tooling — to answer it.
- Compliance assistance: taking into account the nature of the processing and the information available to us, we assist you with your obligations under Art. 32–36 GDPR — security, breach notification, and data protection impact assessments where our processing is relevant to them.
9. Personal data breaches
If we become aware of a personal data breach affecting Project Data, we notify you without undue delay, with what we know: the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures taken or proposed. We do not notify your end users or authorities on your behalf — that judgment and duty are the controller’s — but we support you with the facts you need to make it.
10. Deletion and return
You can export Project Data throughout the contract using the product’s export tools (including code and data export and GitHub sync). On termination, the export window and deletion timelines of the general terms and privacy policy apply: export for 30 days, then deletion or irreversible anonymization within 30 days, backups purged within a further 90 — unless EU or member state law requires longer retention of specific records.
11. Audits
We make available the information reasonably necessary to demonstrate compliance with Art. 28 GDPR — this DPA, our security documentation, and summaries of relevant third-party attestations of our infrastructure providers. Where that is genuinely insufficient, you (or a mandated auditor who is not our competitor) may audit, at most once per year, on 30 days’ notice, during business hours, under confidentiality, at your cost, and without access to other customers’ data. Audits required by a supervisory authority follow that authority’s terms.
12. International transfers
Project Data is processed primarily in the EU; where a sub-processor processes it outside the EEA, the transfer safeguards in section 11 of the privacy policy apply — adequacy decisions including the EU–US Data Privacy Framework where certified, otherwise Standard Contractual Clauses with supplementary measures. We enter these safeguards with the sub-processors on your behalf where the GDPR permits.
13. Liability, precedence, term
- Liability follows the general terms; Art. 82 GDPR remains unaffected.
- Within its scope — the processing of Project Data — this DPA prevails over conflicting clauses of the general terms.
- The DPA runs as long as we process Project Data for you and ends when deletion under section 10 completes.