DATA PROCESSING AGREEMENT · VERSION 1 · 8 OCTOBER 2026
Data Processing Agreement (Art. 28 GDPR)
Ovaj ugovor dostupan je na engleskom (obvezujući tekst) i njemačkom jeziku.
This agreement applies when the customer processes personal data of other people through SendVeil. It is accepted together with the SendVeil Terms and needs no separate signature. The English text is binding; translations are for convenience.
1. Parties
- Controller: the customer that holds the SendVeil workspace (identified by its account).
- Processor: Michael König-Weichhardt, Einzelunternehmer, Sporgasse 24, 8010 Graz, Austria, operator of SendVeil (sendveil.link). Contact: privacy@sendveil.link.
2. Subject matter and nature
The Processor hosts and delivers the files, transfer metadata (titles, file names, expiry, download events), brand assets, file-request submissions and workspace user data (email, role, sessions, audit events) that the Controller places in its SendVeil workspace. Operations: receipt of resumable uploads, storage of original bytes, signed-link delivery, optional email notification, expiry, purge and export. Purpose: providing the SendVeil service to the Controller. Categories of data subjects: the Controller's workspace members, recipients and uploaders. Data categories: those the Controller chooses to upload (may include special categories; the Controller is responsible for its legal basis).
3. Duration
For as long as the workspace exists. Transfers follow the Controller's chosen expiry (from 1 day up to the plan maximum of 7–365 days; no fixed expiry with the Infinity add-on, 30-day tail when it ends). Audit events are deleted after 365 days. A workspace without an active paid subscription is deleted after 180 days without account activity. The agreement ends with deletion of the workspace.
4. Processor obligations (Art. 28(3))
- Processes only on the Controller's documented instructions (use of the product and its settings are the instructions); tells the Controller if an instruction appears unlawful.
- Persons with access are bound to confidentiality. The Processor is currently the sole person with administrative access.
- Implements the measures in section 5.
- Sub-processors only under section 6; the Controller is informed of changes.
- Assists with data-subject requests (owner export and deletion in the Settings app; other requests via privacy@sendveil.link) and with Art. 32–36 obligations.
- Notifies the Controller without undue delay after becoming aware of a personal data breach.
- Provides information needed to demonstrate compliance and allows reasonable audits on prior notice, preferably by documentation first.
5. Technical and organisational measures (as implemented)
- Storage and tenancy: dedicated Cloudflare Worker, R2 and Durable Objects with EU jurisdiction; production and sandbox separated; one Durable Object per workspace; tenant isolation enforced on every route.
- Access control: passwordless sign-in links, server-side sessions, CSRF protection, owner/member roles, optional transfer passwords, signed private tokens for downloads and uploads, rate limits and Cloudflare Turnstile on abuse signals.
- Transport: TLS for all traffic.
- Minimisation: no analytics or advertising trackers; functional cookies only; recipient email addresses for optional notices are not stored in workspace data.
- Deletion: expiry and purge jobs remove file objects and registry entries; audit retention is bounded.
- Operations: audited releases with rollback; secrets held in the platform secret store, not in code.
Encryption at rest is provided by the storage providers; any stronger claim (e.g. customer-managed keys) is not made here.
6. Sub-processors
Cloudflare, Inc. is the only sub-processor for workspace content: Workers, R2 and Durable Objects under EU jurisdiction, outbound email and Turnstile. Storage is in the EU; network and operational data may be processed outside the EU under Cloudflare's own data processing terms.
Stripe (Managed Payments) processes payment, billing and tax data as an independent controller, not as a sub-processor.
Support correspondence sent to hello@sendveil.link or privacy@sendveil.link, including its copy in Google Gmail and optional AI reply suggestions via Mistral AI, is not workspace content and is described in the privacy notice.
The Processor will inform the Controller of intended additions by email or in the product at least 30 days in advance; the Controller may object or close the workspace.
7. International transfers
Customer content stays in the EU storage configuration. Where Cloudflare processes operational data outside the EU, Cloudflare's own data processing terms apply.
8. Deletion and return on account closure
On account deletion by the owner, or automatic deletion after inactivity, the Processor removes the workspace registry, all file objects in R2, sessions, branding, memberships, application database tables and Durable Object storage including alarms; public and guest links return not-found as soon as deletion starts. Before deleting, the owner can export account metadata; the Controller is responsible for downloading its files beforehand. Records held by Cloudflare (mail delivery or suppression logs) or Stripe (payment and tax records), copies of support correspondence and records the Processor must keep by law are retained under their own periods and are not removed by account deletion.
9. Liability, governing law
Liability follows the SendVeil Terms; this agreement adds no separate cap, and Art. 82 GDPR remains unaffected. Austrian law applies, excluding its conflict-of-law rules. The courts competent for Graz have jurisdiction unless mandatory law provides otherwise.