Data Processing Agreement
When you protect a website with AegiFlow, you are the controller and we are the processor. This sets out what we may do, who else is involved, and what happens at the end.
Draft, pending review by external counsel. It describes how the platform actually operates today and is published so you can read it now — but treat it as a working document until this notice is removed.
This agreement forms part of the Terms of Service and applies whenever AegiFlow processes personal data on your behalf. It is written to satisfy Article 28 of Regulation (EU) 2016/679.
Roles
You are the controller. AegiFlow is the processor. We process personal data only on your documented instructions — which are, in practice, your configuration of the platform and the actions you take in it. If we ever believe an instruction breaks data protection law, we will tell you rather than carry it out.
For our own account holders’ data we act as controller; that is covered by the Privacy Notice, not by this agreement.
Subject matter and duration
We process personal data for as long as you have an active workspace, plus the retention periods below. The subject matter is the operation of web protection, continuity and recovery for the services you enrol.
What is processed
Categories of data subject: your personnel who use the platform, and — only in the coarse form described below — visitors to the websites you protect.
Categories of personal data:
- Users of the platform: email address, display name, organization membership, role, authentication factors, and the record of actions they take.
- Visitors to protected websites: country of origin, at country granularity, derived from the connection and stored only as a counter within a time bucket.
What is deliberately excluded. We do not process visitors’ IP addresses, query strings, request bodies, headers, cookies or user agents, and we do not store full URLs. The database has no column anywhere for a visitor identifier. Traffic records are counters against a time bucket, a normalized route and a country code — a design decision, not a configuration you have to trust us to keep.
Special categories. We neither seek nor expect special-category data under Art. 9. Do not send it through the contact form.
Security measures
Technical and organizational measures under Art. 32:
- Every row of operational data is scoped to one organization by row-level security enforced in the database, with the runtime identity holding no superuser or bypass rights.
- Self-hosted identity with passkeys, TOTP and step-up verification before sensitive actions; opaque server-side sessions.
- Protected origins can remain entirely private, reachable only over mutual TLS from the AegiFlow edge; the platform’s own connections are outbound-only.
- Encrypted transport everywhere, encrypted off-site backups, and monthly restore drills that are recorded pass or fail.
- Immutable releases with checksums, a rehearsed rollback, and an automated audit that fails the build if a public page states a figure without a verified source.
- Ingestion is admission-controlled per producer with persistent daily quotas, so one tenant cannot drown another’s telemetry.
Sub-processors
You give general authorization for the sub-processors below. We publish additions to this list before they take effect, giving you the opportunity to object; if you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the affected service.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Global ingress, DNS and TLS termination for enrolled hostnames | Global edge, EU-first routing |
| Stripe Payments Europe, Ltd. | Payment processing, on paid plans only | Ireland (EU) |
Identity is not a sub-processor: AegiFlow runs its own identity service on its own infrastructure, so account credentials never reach a third party. The platform itself, and all operational records, run on infrastructure we operate in Romania (EU).
International transfers
The platform and its records are in the EU. Where a sub-processor’s global network necessarily processes a connection outside the EEA, that transfer relies on the European Commission’s Standard Contractual Clauses together with the supplementary measures in that provider’s own transfer framework. No operational record described above is stored outside the EU.
Assisting you
We will help you, taking into account the nature of the processing:
- Data subject requests. If a request reaches us that is yours to answer, we forward it promptly and give you the technical means to satisfy it.
- Breach notification. We notify you without undue delay after becoming aware of a personal data breach, with what we know, what we are doing, and what remains unknown — stated as unknown rather than rounded off.
- Impact assessments. We provide the information you reasonably need for a DPIA or prior consultation.
Audit
We make available the information needed to demonstrate compliance with Art. 28. You may audit no more than once in a twelve-month period, on 30 days’ notice, at your cost, subject to confidentiality — or more often if a supervisory authority requires it or after a breach affecting your data.
Confidentiality
Everyone we authorize to process personal data is bound by confidentiality and is granted only the access their role requires.
Return and deletion
On termination, and at your choice, we return or delete the personal data we hold for you. Evidence can be exported before you go. Deletion completes within 30 days, except where EU or member-state law requires us to keep something — in which case we tell you what and for how long. Encrypted backups age out on their own cycle and are not restored to serve anyone else.
Precedence
Where this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails. The English version governs.