Devoku · Last updated: August 3, 2026
TEMPLATE STUB — NOT LEGAL ADVICE, NOT READY TO SIGN. This is a skeleton to give
counsel a starting point. A DPA is a binding contract and must be completed and
reviewed by a qualified lawyer (and aligned with your sub-processors' own DPAs and
Standard Contractual Clauses) before use. The codebase's own compliance notes
(P6) list the DPA template as outstanding work.
Effective date: August 3, 2026
Version: privacy-policy-2026-08-03
This Data Processing Addendum ("DPA") forms part of the
Terms of Service between Coded, UAB
("Devoku", "Processor") and the customer accepting it ("Customer",
"Controller"), and applies where Devoku processes Personal Data on the Customer's
behalf in connection with the managed Devoku Cloud service.
Terms such as "Personal Data", "Processing", "Controller", "Processor",
"Sub-processor", "Data Subject", and "Supervisory Authority" have the meanings given
in the EU General Data Protection Regulation (GDPR) 2016/679 and, where applicable, the
UK GDPR. [pending: define any additional terms and referenced laws, e.g. CCPA]
Devoku shall:
1. process Personal Data only on documented instructions from the Controller, including
as set out in the Terms and this DPA;
2. ensure persons authorized to process Personal Data are bound by confidentiality;
3. implement appropriate technical and organizational measures (Annex 2);
4. respect the conditions for engaging Sub-processors (Section 4);
5. assist the Controller, taking into account the nature of processing, with data-subject
requests and with Articles 32–36 GDPR obligations;
6. at the Controller's choice, delete or return Personal Data at the end of the services
(subject to legally required retention); and
7. make available information necessary to demonstrate compliance and allow for audits
[pending: define audit scope, frequency, and cost allocation].
subprocessors.md, published athttps://legal.devoku.com/subprocessors/, and summarized in theStripe, and enabled AI providers).Where processing involves transfers of Personal Data outside the EEA/UK, the parties will
rely on an approved transfer mechanism, such as the EU Standard Contractual Clauses
and the UK Addendum, incorporated by reference [pending: attach/module selection].
Devoku maintains the technical and organizational measures described in Annex 2,
including encryption in transit, access controls, secret management, hashed credentials,
optional two-factor authentication, and audit logging.
Devoku will notify the Controller without undue delay after becoming aware of a
Personal Data breach affecting the Controller's data, and will provide information
reasonably available to assist the Controller's own obligations
[pending: notification timeframe/target, e.g. within 72 hours].
Devoku will assist the Controller in responding to data-subject requests, including via
the Service's built-in export and deletion tools (/api/v1/me/export,
/api/v1/me/delete) and consent controls.
On termination, Devoku will delete or anonymize Personal Data as described in the
Privacy Policy, subject to legally required retention of billing and
audit records for up to 7 years for billing and tax records where required; otherwise only as needed for legal, security, and fraud-prevention purposes.
Liability under this DPA is subject to the limitations in the Terms of Service. In case of
conflict regarding Personal Data processing, this DPA prevails over the Terms
[pending: confirm precedence].`
[pending: categories of data subjects, types of personal data, special categories (if
any), processing operations, duration.]
[pending: detailed security measures — encryption, access control, logging, backups,
network security, personnel, incident response, vendor management.]
[pending: current sub-processor list with entity, purpose, and location; keep in sync
with the Privacy Policy and SUBPROCESSOR_LIST_URL.]
Signatures
[pending: signature blocks for Controller and Processor, or click-through acceptance
mechanism.]