Data Processing Agreement

Skip to main content

Data Processing Agreement

This Data Processing Agreement records how Vallic processes personal data on your behalf when you use Vallic Cloud. It is required by Article 28 of the GDPR and it forms part of our Terms and Conditions.

You do not need to sign anything for it to apply — it applies automatically to every account. If your compliance team needs a countersigned copy, ask us and we will send one.

Vallic, established in the Republic of Croatia, is the processor. You are the controller.

1. What this covers, and what it does not

Two quite different sets of data pass through this platform, and this agreement is only about one of them.

DataWho is controllerGoverned by
Customer Personal Data — everything inside your environments: your database, your uploads, your application logs, your visitorsYouThis agreement
Account data — your name, email, billing address, the people you inviteVallicThe Privacy Policy
Operational data — resource samples, heartbeats, deployment records, audit logsVallicThe Privacy Policy

We are your processor for the first row only. For the other two we are a controller in our own right, on our own legal bases, and Article 28 does not apply.

The distinction is worth understanding rather than skipping: it decides who answers a data subject who writes in, and the answer is usually you.

2. Your instructions

We process Customer Personal Data only on your documented instructions. Your instructions are: this agreement, the Terms, and the actions you take through the console, the API and the CLI.

Configuring a backup schedule is an instruction. Choosing a datacentre is an instruction. Asking support to look at a failing query is an instruction, and a narrow one.

We will tell you if we believe an instruction breaches the GDPR or Croatian data protection law, and we may decline it. We do not process your data for our own purposes, and we do not use it to train models.

What you are responsible for. That there is a lawful basis for the data you put here, that the people it describes have been told what they need to be told, and that you have the right to instruct us to process it.

3. Confidentiality

Everyone at Vallic who can reach Customer Personal Data is bound by a written confidentiality obligation that survives their leaving, and is trained on handling it.

Access is on a need-to-know basis, granted for a task and removed afterwards. Every access to a customer environment is logged and you can ask for the log.

4. Security

We implement the technical and organisational measures set out in Annex II, which are appropriate to the risk under Article 32.

They may change as technology does. They will not get materially worse without telling you.

5. Sub-processors

You give us general authorisation to engage the sub-processors listed in Annex III, and others from time to time.

Before we add one that touches Customer Personal Data, we give you 30 days' notice by email to account owners. You may object on reasonable data protection grounds within 14 days. If we cannot resolve the objection, you may terminate the affected part of the service and we refund the unused remainder — you are never left choosing between a sub-processor you object to and losing money.

Thirty days rather than the fifteen that is common, because a change of sub-processor can mean a change of jurisdiction, and a fortnight is not long enough for a compliance function to assess one.

Each sub-processor is bound by data protection terms no weaker than these. We remain fully liable to you for their performance.

Two things you may connect are not our sub-processors. Storage of your own that you add for backups, and a destination you ship logs to, are your instruction and your relationship with that provider. We send the data where you told us to; what happens to it there is under your terms with them.

A note specific to this platform. The machines your sites run on are rented from Hetzner, UpCloud or Gcore, and you choose which at the point of purchase. Choosing a datacentre is choosing a sub-processor and a jurisdiction, and it is the one sub-processor decision that is yours rather than ours.

6. Helping you answer data subjects

If a data subject contacts us about data inside your environments, we do not answer them. We tell them to contact you and we tell you they wrote.

Most of what you would need to answer them — export, correction, deletion — you can do yourself from the console, which is faster than asking us. Where you cannot, we help you with appropriate technical and organisational measures, at no charge for a reasonable volume of requests.

7. Personal data breaches

We notify you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data.

The notice tells you what we know: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken or proposed. Where we do not yet have all of it, we send what we have and follow up rather than waiting until the picture is complete.

We assist you with your own notification obligations under Articles 33 and 34. Notifying the supervisory authority about your data is your obligation, not ours, and the clock on it starts when we tell you.

8. Assessments and prior consultation

We assist you with data protection impact assessments and prior consultation under Articles 35 and 36, taking into account the nature of the processing and the information available to us.

In practice that means answering a questionnaire, providing Annex II in a form your assessor can use, and explaining how a particular part of the platform works. It does not mean writing your DPIA for you.

9. Deletion and return

You can export everything at any time, yourself, in standard formats, without asking us and without a fee. That is the mechanism we expect you to use and it is available throughout the life of the account.

When the service ends, we delete Customer Personal Data after 30 days, including from backups as they rotate. On written request within that window we return it or confirm the deletion in writing.

The 30-day window is deliberate. Deleting on the day of termination is simpler for us and is what several platforms do; it is the wrong answer for anybody whose card expired while they were away. We retain nothing after it except where EU or Croatian law requires — invoices and the records behind them, which contain billing data rather than Customer Personal Data.

10. Audits and evidence

We make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits.

In the first instance that means our documentation, Annex II, and written answers to your questions — which for most customers answers everything.

Where it genuinely does not, you may audit us on 30 days' notice, no more than once a year, during business hours, under confidentiality, without access to other customers' data, and at your cost. That frequency limit does not apply after a personal data breach affecting you, or where a supervisory authority requires it — in which case we cooperate without conditions and at our own cost.

11. International transfers

Where Customer Personal Data leaves the EEA, the transfer relies on the European Commission's Standard Contractual Clauses, which are incorporated into this agreement by reference — Module Two where you are a controller and we process for you, Module Three where you are yourself a processor and we are your sub-processor.

For the purposes of the Clauses: you are the data exporter, Vallic is the data importer, Annex I of this agreement supplies the description of the transfer, Annex II supplies the security measures, and the governing law and forum are Croatian.

Not every transfer needs the Clauses. Two of the sub-processors in Annex III rely on something stronger and simpler. Mail to our own addresses sits with Proton in Switzerland, which holds a European Commission adequacy decision — a transfer there needs no additional safeguard at all. Platform email leaves through MailerSend in the United States under the EU-U.S. Data Privacy Framework, with the Clauses as a fallback should that framework be invalidated, as its two predecessors were.

Where your data actually sits is your choice. Every datacentre the configurator offers states its country before you buy. An environment in Frankfurt, Helsinki or Luxembourg does not leave the EEA at all, and the simplest way to avoid a transfer question is to choose a region inside it — which is why the choice is offered in front of the purchase rather than buried in settings.

Backups are a second question and a separate answer: the destination is chosen per project and the bucket sits on the continent chosen. The European destination adds a jurisdictional restriction on top of that placement; Annex III says what each one guarantees.

12. Liability, precedence and changes

Liability under this agreement is subject to the limitations in the Terms and Conditions, except where the GDPR does not permit them to apply.

Where this agreement conflicts with the Terms, this agreement wins on anything concerning the processing of personal data. Where it conflicts with the Standard Contractual Clauses, the Clauses win.

This agreement lasts as long as we process Customer Personal Data for you. We give 30 days' notice of a material change, and you may terminate before it takes effect.

Annex I — The processing

Controller / data exporter: you, the account holder, with the contact details held on the account.

Processor / data importer: Vallic, Republic of Croatia. Data protection contact: via our contact page.

Subject matter: providing managed hosting for the customer's web applications.

Duration: the term of the Agreement, plus the 30-day deletion window in clause 9.

Nature and purpose: hosting, storing, backing up, transmitting and restoring the customer's application and its data; serving it to the internet; and supporting the customer in operating it.

Categories of data subject: whoever the customer's application holds data about — typically its own registered users, its customers, its employees, and visitors to its sites.

Types of personal data: whatever the customer chooses to put on the platform. Vallic does not determine it and does not inspect it. In practice it commonly includes names, email addresses, postal addresses, telephone numbers, hashed credentials, order and transaction records, uploaded files, and the IP addresses and request metadata of site visitors.

Special category data: not expected, and the platform is not designed or certified for it. If you intend to process health data, biometric data, or any other Article 9 category, tell us first — see also the high-risk exclusions in the Acceptable Use Policy.

Frequency: continuous, for as long as the service runs.

Annex II — Technical and organisational measures

Encryption. Data in transit is encrypted with TLS. Data at rest is encrypted on the provider's volumes. Backups are encrypted before they leave the machine, and every destination is a separate repository with its own key — one key opens one copy. Those keys are stored encrypted like the secrets below. Credentials, API tokens and environment secrets are encrypted in our own database with keys held outside it, so a database copy on its own decrypts nothing.

Access control. Access to production requires a second factor. Staff access to a customer environment happens on request, for a task, and is logged with who, when and which environment. Audit logs are retained for one year.

Tenant isolation. Each environment runs in its own container with its own credentials and its own filesystem. A machine in the shared pool carries several tenants and isolates them; a dedicated machine carries one team only. Private networking between a team's machines does not cross to another team's.

Network security. Every machine is created with a firewall already attached rather than attached afterwards, so there is no window in which it is unprotected. Inbound rules are explicit and default-deny; only the ports a site needs are open.

Resilience and backups. Backups run on the schedule the plan states, to two off-site copies with different providers — one on the environment's continent and a cold copy in the EU — with a retention the customer controls. Restores are exercised rather than assumed.

Patching. We patch the host operating system, the container runtime and the platform's own software. The customer patches their application and its dependencies.

Logging and monitoring. Machines report health continuously. The proxy's request log carries no visitor identifiers by default — no IP address, no user agent, no query string — only the fields needed to count and time requests. The full line is written only where the customer switches it on to ship logs to their own destination. The machine keeps its copy for 7 days; what reaches the platform is per-minute counts per environment, not lines.

Personnel. Written confidentiality obligations, need-to-know access, and removal on departure.

Deletion. Environments and their volumes are destroyed with the machine rather than left behind; backups age out on their schedule.

Annex III — Sub-processors

These process Customer Personal Data on our behalf. Which of the infrastructure providers applies to you depends on the datacentre you chose.

Sub-processorWhat they doWhere
Hetzner Online GmbHCompute and block storage; object storage for the previous cold backup copy, being retiredGermany, Finland, United States
UpCloud LtdCompute and block storageThe region you chose
GcoreCompute and block storageThe region you chose
CloudflareBackup object storage (R2)See the note below — EU for the European destination
Scaleway SASObject storage for the cold backup copyFrance (Paris), EU
Bunny.netCDN — serves cached assets, sees visitor IP addressesGlobal edge
MailerSend, Inc.Delivery of platform email — password resets, notifications, invoices. Sees the recipient address and the messageUnited States, under the EU-U.S. Data Privacy Framework
Proton AGOur own mailboxes. Sees whatever you send us and whatever we send you, including support correspondenceSwitzerland, under the EU adequacy decision
GitHubContainer registry. Serves our images to your machines; receives no data of yours. See the note belowGlobal
StripePayments. Billing data rather than Customer Personal Data; listed because customers askEU / US, under SCCs

Mail is worth a note. Platform email leaves through MailerSend and correspondence with us lands in Proton. Neither carries Customer Personal Data from inside your environments — but both carry the email address of whoever we are writing to, which is personal data belonging to the people you invited into your account.

Where backups actually sit. A project picks a backup destination and the bucket behind it is created on that continent, so backups for a European environment are stored in Europe rather than merely routed there. The platform picks the destination nearest an environment's machines by default.

The European destination goes further: it uses Cloudflare's EU jurisdiction endpoint, which is a contractual restriction to EU datacentres rather than a placement. The Americas and Asia Pacific destinations are placed on their continent without that additional jurisdictional undertaking. The cold copy is kept with Scaleway in Paris, France, across several availability zones, and is always in the EU whatever continent the environment is on. Until it holds a full retention history, the previous cold copy with Hetzner in Helsinki, Finland, is kept alongside it, and is retired after that.

For most purposes the placement is what matters. Where a regulator or a customer of yours wants the stronger form of the promise, choose the European destination and you have it in writing from Cloudflare as well as from us.

GitHub appears twice in this platform and neither is a sub-processor of your data. It is listed anyway, because anyone reviewing this will notice we deploy from it and ask.

  • As a registry. The service images your environments run — PHP, MariaDB, Redis, Solr and the rest — are published by us at ghcr.io/vallic/ and pulled by your machines on deploy. Data flows one way, from GitHub to the machine. GitHub sees which image a machine asked for and the address it asked from; it sees nothing of yours.
  • As a source of code. Where you connect a repository, you install our GitHub App on your own account and choose which repositories it may read. That is your relationship with GitHub under your own terms with them, not one we entered on your behalf — we receive code from it and send back commit and deployment statuses. If your repository contains personal data, it was there before it reached us.

Uptime monitoring is not a sub-processor either. Availability is checked from machines we rent from Scaleway (Europe), Linode (the Americas) and Vultr (Asia-Pacific). They send requests to your public sites and to the health endpoint on your machines, the same as any visitor, and receive nothing from inside your environments.

Signing in with GitHub is a third thing again: that identity is account data, where we are the controller and the Privacy Policy applies rather than this agreement.

This list is current as of 24 September 2026. Changes are notified under clause 5.