Legal

Data Processing Addendum.

The contract that sits alongside our Terms of Service for customers who need formal data processing terms. Pre-signed DPAs available on request.

Effective 1 May 2026Version 2.0Pre-signed Available

Scope

This Data Processing Addendum ("DPA") forms part of the agreement between rendrOS and the Customer. It applies whenever rendrOS processes personal data on behalf of the Customer in connection with the rendrOS service, and supplements our Terms of Service.

Roles & responsibilities

PartyRoleExamples
CustomerControllerDecides what data goes into rendrOS and why
rendrOSProcessorStores, processes and transmits the data per Customer's instructions
Sub-processorsSub-processorHosting, payments, email delivery (see below)

Authorised sub-processors

Sub-processorServiceRegion
Amazon Web ServicesHosting, storage, backupsUK (eu-west-2), UAE (me-central-1)
Stripe PaymentsCard processing, billingUK / EU / UAE
PostmarkTransactional emailEU
Plausible AnalyticsCookie-less site analyticsEU
SentryError monitoringEU
CloudflareCDN, DDoS protectionGlobal edge

We will give the Customer 30 days' notice before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds.

Technical & organisational measures

International data transfers

Personal data is stored in the Customer's chosen region. Where transfer to another region is operationally necessary (e.g. EU sub-processors), it is covered by EU Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and supplementary measures as required.

Breach response

rendrOS will notify the Customer of a confirmed personal data breach affecting their data without undue delay, and in any event within 48 hours of confirmation. Notification will include nature, scope, likely consequences, and remediation taken.

Audit rights

The Customer may, at most once per year and on 30 days' written notice, audit our compliance with this DPA. We may satisfy audit requests through current SOC 2 reports, ISO 27001 certificates, or other recognised attestations once available.

Return or deletion of data

On termination, the Customer may export their data via the in-app export tool for up to 90 days. After 90 days, all Customer personal data is permanently deleted from production systems and from backups within the next backup rotation cycle (max 35 days), unless retention is required by law.

Request a signed DPA

Need a counter-signed DPA on company letterhead?

hello@getrendros.com