Skip to content
Databasezy

Data processing agreement

Draft v0.1, last updated 2026-09-27. This draft is published for review while the service is in preview; it is not yet the executed version. To sign a countersigned copy, or to attach your own DPA, email [email protected]. Related documents: Terms of service, Privacy policy, Sub-processors, Business Associate Agreement.

1. Parties and scope

This Data Processing Agreement (DPA) forms part of the Databasezy Terms of Service between Databasezy, Inc. (the Processor) and the customer identified in the account (the Controller). It applies to all personal data that Databasezy processes on the Controller's behalf when providing the managed database service, the customer portal, the API and support.

Where the Controller acts as a processor for its own customers, Databasezy acts as a sub-processor and the same terms apply.

2. Definitions

"Data Protection Law" means the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any applicable US state privacy law. "Personal Data", "Controller", "Processor", "Processing", "Data Subject" and "Personal Data Breach" have the meanings given in the GDPR. "Customer Data" means all data stored in the Controller's database instances, backups and exports.

3. Details of processing

Subject matter: hosting, backing up and making available database instances operated by the Controller. Duration: the term of the account plus the retention window of the Controller's plan after deletion (shown before every deletion; the full-erasure option purges immediately). Nature and purpose: storage and transmission of Customer Data; Databasezy does not read, analyse or profile Customer Data, and metering sees bytes and sizes only.

  • Types of personal data: whatever the Controller stores in its databases (unknown to Databasezy by design), plus account data of the Controller's users: name, email, IP address, audit-log entries.
  • Categories of data subjects: the Controller's end users, employees and contractors; the Controller's own customers where it acts as a processor.
  • Special categories: only where the Controller has enabled secure hosting and signed the Business Associate Agreement for protected health information; otherwise the Controller undertakes not to store special-category data.

4. Processor obligations

Databasezy processes Personal Data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of the portal, CLI, API and MCP server. Databasezy informs the Controller if an instruction, in its opinion, infringes Data Protection Law.

  • Confidentiality: staff are bound by confidentiality obligations and, by design, cannot read Customer Data without a customer-issued support access grant (time-boxed, logged, revocable).
  • Security (Art. 32): per-instance isolation, TLS 1.3 at the edge and re-encryption inside the cell, encryption at rest with per-tier keys (per-org customer-managed keys on secure hosting), per-database credentials, IP allow-lists, immutable backups where the plan provides them, a tamper-evident audit log and annual external penetration testing. The current description of measures is on the security page.
  • Assistance: Databasezy assists with data-subject requests by providing export and deletion of Customer Data through the portal and API, and with data protection impact assessments and consultations with supervisory authorities on request.
  • Personal Data Breach: Databasezy notifies the Controller's security contact without undue delay and no later than 48 hours after becoming aware of a breach affecting the Controller's Personal Data, with the information required by Art. 33(3) as it becomes available.
  • Deletion and return: on termination the Controller can export Customer Data in engine-native formats; Databasezy deletes Customer Data, backups and secrets at the end of the plan's retention window, or immediately on request, and writes an erasure certificate to the audit log.
  • Audits: Databasezy makes available the information necessary to demonstrate compliance, including third-party audit reports as they become available (SOC 2 Type I is scheduled for the HIPAA launch phase), and allows audits by the Controller or an independent auditor once per year on 30 days' notice, subject to confidentiality and without access to other customers' data.

5. Sub-processors

The Controller gives general authorisation for the sub-processors listed on the sub-processors page. Databasezy gives at least 30 days' notice of any addition or replacement by updating that page and emailing the account's security contact; the Controller may object on reasonable data-protection grounds within that period, in which case the parties work in good faith on a solution and the Controller may terminate the affected service without penalty. Databasezy imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains liable for their performance.

6. International transfers

Customer Data is stored in the region the Controller selects for each instance and is not moved between regions except by the Controller's own action (cross-region backup copies are a per-plan option). Where Personal Data is transferred from the EEA, the UK or Switzerland to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (Module 2, controller to processor, or Module 3 where the Controller is a processor), the UK International Data Transfer Addendum and the Swiss amendments, which are incorporated by reference and completed with the details in this DPA.

7. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict, this DPA prevails over the Terms for the processing of Personal Data, and the Standard Contractual Clauses prevail over this DPA. This DPA is governed by the law that governs the Terms.

8. Term and changes

This DPA takes effect when the Controller accepts the Terms and lasts as long as Databasezy processes Personal Data for the Controller. Databasezy may update this DPA to reflect changes in law; material changes are announced 30 days ahead through the changelog and email to the security contact.

Annex: technical and organisational measures

The measures are described on the security page (tenant isolation, encryption, credential handling, staff access, backups, audit logging, vulnerability management) and, for secure hosting, in the secure hosting documentation. They are updated as the platform evolves; the versions in force at signing are attached to the executed copy.