Data processing addendum (Art. 28)

Version 2026-09-13. This addendum applies when Dromix (processor, for install/support) processes personal data on behalf of a licensed customer (controller). The signed quote or contract prevails if it differs.

1. Roles

The customer is controller of personal data in its self-hosted Dromix. The vendor is processor only to the extent it accesses the customer server or credentials for installation, updates, or support. Day-to-day messaging is not a hosted SaaS tenant at HQ.

2. Subject matter and duration

Processing is limited to installing Dromix, applying application updates, and diagnosing faults the customer reports, for the licence term and a reasonable wind-down after it ends.

3. Nature and types of data

Server configuration, licence metadata, logs, and — only if the customer grants access — account directory fields and ciphertext. The processor does not decrypt end-to-end encrypted messages. Categories of data subjects: the customer’s staff, guests, and invitees.

4. Processor obligations (Art. 28(3))

The processor shall: process only on documented instructions; ensure persons authorised are bound by confidentiality; implement Art. 32 security measures; not engage a sub-processor without prior notice and the customer’s opportunity to object; assist with DSAR, DPIA, and consultations; delete or return personal data after the end of services unless Union or Member State law requires storage; and make available information necessary to demonstrate compliance and allow audits that do not compromise other customers or E2E keys.

5. Sub-processors

On the customer VPS the stack (PostgreSQL, MinIO, Redis, coturn, LiveKit) runs under the customer’s hoster contract — that hoster is the customer’s processor, not the vendor’s. HQ sales email, if used, is sent via the SMTP host configured by the vendor (see environment). The vendor will notify the customer of a change of vendor-side sub-processors used for the licensed service.

6. International transfers

If the processor must access the customer server from outside the EU/EEA, Chapter V safeguards (including SCCs where required) apply. The customer remains responsible for the location of its own VPS.

7. Breach assistance

The processor will notify the controller without undue delay after becoming aware of a personal data breach in processing it performs, with the information reasonably available to help the controller meet Arts. 33 and 34.

8. Assistance with data-subject rights

Because the customer holds the database, DSAR fulfilment is primarily the customer’s. The product provides export, rectification (profile), restriction, and erasure tools so the controller can meet Arts. 15–21. The vendor assists on request during support hours.

9. Deletion at end of service

When the licence ends, the vendor does not remotely wipe the customer VPS. The customer deletes or continues the machine. Any copies the vendor holds from a support session (logs, screenshots) are deleted when no longer needed for that ticket, unless law requires retention.

Sales: dromix.web@gmail.com