Data Processing Addendum

Last updated: 2026-05-02

This Data Processing Addendum ("DPA") forms part of the Splitsoft Terms of Service and applies whenever the Customer ("Controller") submits personal data to the Service for Splitsoft ("Processor") to process on the Controller's behalf. Capitalized terms have the meaning given in the Terms or in Article 4 GDPR.

1. Roles and scope

The Customer is the Controller (or a Processor acting on behalf of a third-party Controller, in which case Customer warrants it has the authority to engage Splitsoft as a Sub-Processor). Splitsoft is the Processor.

2. Processor obligations

  1. Documented instructions. Splitsoft processes personal data only on the Controller's documented instructions, including those embodied in the Terms and the API/SMTP submission of messages.
  2. Confidentiality. All personnel with access to personal data are bound by written confidentiality obligations.
  3. Security (Art. 32). Splitsoft maintains the technical and organizational measures described in Annex II below.
  4. Sub-processing. Splitsoft engages the Sub-Processors listed in Annex III and gives the Controller at least 30 days' notice of additions or replacements, during which the Controller may object on reasonable data-protection grounds.
  5. Data subject requests. Splitsoft will assist the Controller by appropriate technical and organizational measures, including the /api/data-export and /api/data-erase endpoints exposed by the admin panel.
  6. Breach notification. Splitsoft will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal-data breach affecting the Controller's data.
  7. Return or deletion on termination. On termination of the Terms, Splitsoft will, at the Controller's election made within 30 days, either return personal data in a machine-readable format or delete it from production systems within 30 days, with backup purge completing within the further 35-day backup retention window.
  8. Audit rights. Once per 12-month period (more often after a breach or where required by a supervisory authority), Splitsoft will make available information necessary to demonstrate compliance with this DPA.

3. International transfers

Where the Controller's data originates in the EEA, UK, or Switzerland and processing involves transfer to a country not subject to an adequacy decision, the parties incorporate by reference the European Commission Standard Contractual Clauses (Module 2: Controller-to-Processor) adopted on 4 June 2021, with the UK International Data Transfer Addendum and the Swiss FDPIC adaptation as applicable.

4. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms. Nothing in this DPA limits a data subject's rights against either party under GDPR Articles 79–82.

Annex I — Description of processing

Annex II — Technical and organizational measures

Annex III — Authorized sub-processors

As of 2026-05-02 the following sub-processors are engaged:

Sub-processorPurposeRegion
Vultr Holdings, LLCCompute, block storage, BYOIP custodyUS, EU
Stripe, Inc.Payment processing and invoicingUS
Cloudflare, Inc.DNS, edge TLS for marketing site, DDoS protectionUS / global anycast
Backblaze, Inc. (B2)Encrypted off-site backups of Postgres and MariaDBUS

To execute this DPA, request a counter-signed PDF at legal@splitsoft.com. Until executed, the version published on this page applies between the parties as of the Effective Date of the Terms.