Data Processing Agreement
Last updated: September 2, 2026 (Version 2026-09-02)
Introduction
This Data Processing Agreement ("DPA") forms part of the Platform Terms between Aicode Studio, registered with the Dutch Chamber of Commerce under number 89302230, registered office Kortgenestraat 93, 3086 JH Rotterdam, The Netherlands ("we," "us," "the Processor"), and the business licensing a hosted instance of Aicode App ("you," "the Customer," "the Controller").
It is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR"), which requires a written contract between a controller and a processor. It applies from the moment your Instance first processes personal data.
Roles. For personal data processed within your Instance, you are the controller and we are the processor. For your own administrative account with us, and for billing you, we act as a controller in our own right; that processing is described in our Privacy Policy and is outside the scope of this DPA.
What is not in scope. Your Instance connects to services you hold accounts with, including Stripe, your SMTP provider, Discord, video hosting, and any automation or AI provider used by your Apps. Those are your own processors, engaged by you under your own agreements, not our sub-processors. This DPA covers the processing we carry out in hosting and operating your Instance.
1. Subject Matter, Duration, Nature and Purpose
- Subject matter: the hosting and operation of your Instance
- Duration: the term of the Platform Terms, plus the retention period in clause 9
- Nature and purpose: storage, retrieval, transmission, backup, and display of personal data so that you can operate your business and deliver products to your End Users, together with the technical support necessary to keep the Instance running
- Type of processing: collection, recording, organisation, structuring, storage, retrieval, transmission, backup, restoration, erasure, and destruction
2. Categories of Data Subjects
- Visitors to your storefront, browsing public pages without an account
- Leads, being people who submit a contact form, request a demo, join a waitlist, or provide their details to receive a free download
- Registered users of your storefront
- Customers, being registered users who have purchased or subscribed
- Your administrators and staff who use the Instance
- Discord-connected users, where you operate a community product
- Participants in service projects, where you deliver a service with status updates, messages, and file exchange
3. Categories of Personal Data
- Identity: first name, last name, email address, profile avatar
- Account: password stored only as a secure hash, role, access history, and interface preferences such as language, theme, and onboarding progress
- Purchase: order summaries comprising product, amount, currency, date, and status; subscription status, billing interval, and period end; and the Stripe customer, subscription, and payment intent identifiers. Payment card numbers are not stored, and are handled by Stripe under your own account
- Billing and invoicing: name or company name, email, phone number, billing address, VAT number, company registration number, and a stored snapshot of each invoice
- Usage: lesson completion records, downloads granted, and App input and results
- Licensing and device data: license tokens, machine identifiers used for device binding, and last check-in time
- Discord: Discord user ID, username, avatar URL, and server membership status
- Communications: name, email, subject, and message content from contact forms, demo requests, waitlists, and support
- Service projects: project details, status updates, messages, and exchanged files
- Technical: IP address, held transiently in server memory for rate limiting, and browser user agent
- User-uploaded files: resource files and project files
4. Special Categories of Data
Neither party intends special categories of personal data within the meaning of Article 9 GDPR, nor personal data relating to criminal convictions and offences within the meaning of Article 10, to be processed under this DPA.
You must not use the Instance to process such data without our prior written agreement, so that appropriate additional safeguards can be put in place first.
We note that the Instance allows you and your End Users to enter free-text content, App inputs, and file uploads that we do not inspect. This clause is an obligation on you, not a technical control by us.
5. Our Obligations as Processor
We will:
- Process personal data only on your documented instructions, including as to international transfers, unless required to do otherwise by law, in which case we will inform you before processing unless the law prohibits it. Your use of the Instance, together with the Platform Terms, the Order Form, and this DPA, constitutes your documented instructions
- Inform you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law
- Ensure that personnel authorised to process personal data are bound by an appropriate obligation of confidentiality
- Implement and maintain the technical and organisational measures set out in Annex A
- Assist you, taking into account the nature of the processing and the information available to us, in responding to requests from data subjects exercising their rights under Chapter III GDPR
- Assist you in complying with your obligations under Articles 32 to 36 GDPR, including security, breach notification, and data protection impact assessments
- Make available the information necessary to demonstrate compliance with Article 28, as set out in clause 10
Support access. We access personal data within your Instance where necessary to provide support, to investigate faults, and to maintain the service. Such access is limited to what is necessary for the task, and the personnel concerned are bound by confidentiality.
6. Sub-processors
You give general written authorisation for us to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex B.
We will impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
Updating Annex B. We will give at least 30 days' written notice to your admin contact before adding or replacing a sub-processor. Annex B may be updated by that notice, and such an update does not require an amendment of this DPA. You may object on reasonable data protection grounds within the notice period. If we cannot resolve your objection, you may terminate the Platform Terms in respect of the affected processing, and we will refund fees prepaid for the unused remainder of the current period.
7. International Transfers
Your deployment region is agreed with you and stated on the Order Form. The default region is Europe.
Where your Instance is deployed within the European Economic Area, the personal data we process under this DPA is stored in the EEA and no transfer to a third country takes place in the course of our hosting and operating it.
Where you select a region outside the EEA, the storage of personal data in that region is a transfer to a third country, made on your documented instruction. Where that country is not the subject of an adequacy decision under Article 45 GDPR, the transfer takes place on the basis of the Standard Contractual Clauses adopted by the European Commission, which are incorporated into this DPA by reference, together with any supplementary measures identified by a transfer impact assessment. Selecting a non-EEA region may create additional obligations for you as controller, including in your own privacy notice and records of processing.
Where we later engage a sub-processor established outside the EEA, the same basis applies, and clause 6 governs the notice and your objection right.
Transfers arising from services you connect yourself, including Stripe, Discord, video hosting, your SMTP provider, and any automation or AI provider, are made under your own agreements with those providers and are not governed by this DPA.
8. Personal Data Breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, as Article 33(2) GDPR requires.
Notification is sent to the admin contact stated on your Order Form. Notices to us under this clause should be sent to security@app.aicode.studio.
The notification will describe, so far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. We will provide further information as it becomes available.
Notifying a supervisory authority or the affected data subjects is your responsibility as controller. We will provide reasonable assistance.
9. Return and Deletion
On termination of the Platform Terms:
- Your Instance becomes read-only for 30 days, as set out in clause 15.6 of the Platform Terms. Within that window you may request an export of the personal data processed under this DPA. We will provide it in a structured, commonly used, machine-readable format, comprising a database export and your uploaded files
- We will delete the personal data, including from backups in the ordinary course of their rotation, within 30 days of the end of the export window
We may retain personal data where required to do so by law, in particular accounting and invoicing records, which Dutch law requires us to keep for seven years. Retained data remains subject to this DPA for as long as we hold it.
10. Audit
We will make available to you the information necessary to demonstrate compliance with Article 28 GDPR, in the form of our documentation, the description of technical and organisational measures in Annex A, and written answers to reasonable questions. Where we hold a relevant third-party report or certification, providing it satisfies this obligation.
Where that is not sufficient, you may carry out an on-site audit, subject to the following: it is at your cost, on at least 30 days' written notice, no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, conducted during normal business hours, not conducted during an ongoing security incident, and subject to the auditor accepting confidentiality obligations and not being a competitor of ours.
11. Liability
Liability under this DPA is subject to the limitations and exclusions in clause 13 of the Platform Terms.
12. Order of Precedence
Where this DPA conflicts with the Platform Terms in relation to the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, those clauses prevail.
Annex A: Technical and Organisational Measures
Measures implemented pursuant to Article 32 GDPR. This annex describes what is in place at the version date of this DPA.
Encryption
- All connections are served over HTTPS. Personal data is encrypted in transit using TLS, and plain HTTP connections are not accepted
- Personal data is encrypted at rest at the database storage layer
- Passwords are stored only as secure hashes, never in readable form
- Sensitive configuration values, including App signing secrets, webhook secrets, and license API keys, are stored encrypted with AES-256 and are never held in readable form
Access control
- Access to production systems is restricted to personnel who require it, on a need-to-know basis
- Authentication supports passwordless sign-in by emailed single-use magic link, in addition to password sign-in. Multi-factor authentication is not currently offered as a separate factor
- Access within the application is enforced at the database layer through row-level security, in addition to application-level checks
- Identity, license, and single sign-on tokens are cryptographically signed, short-lived, and revocable
Isolation
- Each customer is deployed to a dedicated, isolated Instance with its own database. Personal data is not shared between instances, and no instance can read another's data
Application security
- Server-side App handlers run in an isolated sandbox with no network access, no file system access, and a strict execution time limit
- Payment card data is never received or stored by us; card processing is carried out by Stripe under the customer's own account
Resilience
- Automated backups are taken daily and stored separately from the server running the Instance
- Backup retention is 30 days for Starter and Pro plans, and one year for the Scale plan
- Restoration is on a reasonable-efforts basis, with no recovery point or recovery time objective
Operational security
- Security patches are applied to the platform and its dependencies on an ongoing basis
- Application and access events are logged
- Incidents are triaged, contained, and recorded, and notified in accordance with clause 8
Organisational
- Personnel with access to personal data are bound by confidentiality obligations
- Sub-processors are bound by written terms no less protective than this DPA
Annex B: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server infrastructure hosting the Instance | The region stated on your Order Form. Default: Europe (Germany) |
No other sub-processor is engaged.
Specifically:
- Supabase is not a sub-processor. The platform uses Supabase's open-source software, self-hosted on our own infrastructure. No personal data is transmitted to Supabase Inc. or to Supabase's hosted service
- Stripe, your SMTP provider, Discord, video hosting providers, and any automation or AI provider used by your Apps are engaged by you under your own accounts and agreements. They are your processors, not ours
- No freelancers or subcontractors have access to production data. Should that change, they will be engaged as sub-processors under written confidentiality and data protection obligations, and Annex B will be updated in accordance with clause 6
Annex B may be updated by notice under clause 6, without amendment of this DPA.
Contact
Questions and notices under this DPA, including breach notifications, should be sent to security@app.aicode.studio. General privacy enquiries may be sent to privacy@app.aicode.studio.
Aicode Studio
Kortgenestraat 93, 3086 JH Rotterdam, The Netherlands
Dutch Chamber of Commerce number 89302230
VAT NL004713458B58
Effective Date: September 2, 2026
Last Updated: September 2, 2026
Version: 2026-09-02