Skip to content

Data processing agreement

If you are a controller in the EU, the EEA or Switzerland and we touch personal data for you, you need a written processor agreement. This page says exactly what ours contains, so your legal review knows what is coming before the first brief.

01

When you need one

You are the controller: it is your customer, employee or visitor data, and you decide what happens to it. We are the processor: we build and run software that handles that data on your instructions, and we do nothing else with it.

The moment that is true, Art. 28 GDPR requires a written agreement between us. That applies even when we never look at a record, because maintaining a database or fixing a production bug means we could. Pretending otherwise is the most common mistake in this market.

02

What the agreement covers

Ours is a normal Art. 28 processor agreement with no surprises in it:

  • Subject matter, duration, nature and purpose of the processing, the categories of data subject and the types of personal data, all listed in an annex specific to your project.
  • Processing only on your documented instructions, and a duty to tell you if an instruction looks unlawful to us.
  • Confidentiality binding everyone who touches the data.
  • Technical and organisational measures, listed below and annexed to the contract.
  • Sub-processors named up front, with prior notice and a right to object before any new one is added.
  • Assistance with data-subject requests, with breach notification, and with your data protection impact assessment where one is needed.
  • Deletion or return of the data at the end of the engagement, at your choice.
  • Information and audit rights, including the records you need to demonstrate compliance.
03

Transfers out of the EEA

Pluton Studio is in Kosovo, and Kosovo has no adequacy decision from the European Commission. We say that plainly rather than burying it, because it is precisely why the paperwork exists.

We therefore sign the EU Standard Contractual Clauses 2021/914, Module Two (controller to processor), together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner where Swiss law applies. We add a short transfer impact assessment: what data is involved, who can reach it, from where, and what protects it.

The European Data Protection Board treats remote access from a third country as a transfer even when the data never leaves its EU server. That is exactly our situation: the database sits in Frankfurt and the engineer reading it sits in Prishtina. The clauses cover it.

04

Technical and organisational measures

The annex lists what is actually true of this stack. We do not claim certifications we do not hold, and there is no ISO or SOC 2 badge on this page for that reason.

  • Encrypted transport everywhere: HTTPS on every public endpoint, TLS to the database and to every provider API.
  • Encryption at rest as provided by the hosting and database providers.
  • Access limited to the engineer working on your project. There is no support pool and no offshore subcontractor chain.
  • Two-factor authentication on the provider accounts that hold your environments.
  • Least-privilege credentials: environment variables scoped per environment, production secrets never on a laptop in plain text, separate staging data wherever it can be synthetic.
  • Repository access control, with your repository owned by you and our access removable by you at any moment.
  • Backups run by the hosting and database providers, with point-in-time restore where the plan includes it.
  • Deletion of working copies and revocation of our access at the end of the engagement, confirmed to you in writing.
05

Sub-processors

These are the providers behind our own systems, and the ones that appear in the annex unless your project runs entirely in your infrastructure. If your project adds one, it is named before it is used, never after.

ProviderPurposeWhere it processes
VercelApplication hosting and delivery, server functionsOur functions are pinned to Frankfurt (fra1); company based in the United States
NeonManaged Postgres databaseAWS eu-central-1, Frankfurt; company based in the United States
ResendSending and receiving project emailUnited States
GroqGenerating replies in the AI chat, where a project includes oneUnited States
06

If a breach happens

We notify you within 48 hours of becoming aware of a personal data breach, in writing, with what we know at that point: what happened, which data and roughly how many records are affected, what we have already done, and what we recommend you do. We do not wait for a complete picture before telling you, because your own 72-hour clock under Art. 33 GDPR starts before ours would finish.

You decide whether to notify the supervisory authority and the data subjects. We give you the technical detail you need for that notification and stay available while it runs.

07

Audit, deletion and the end of the engagement

You may ask at any time for the information needed to demonstrate compliance, and you may audit us or appoint an auditor. In practice most clients accept a written questionnaire and a walkthrough call, which we do without charging for it; an on-site audit is arranged on reasonable notice.

When the work ends, you choose: we delete the personal data and every working copy, or we return it in a usable export first and then delete. Either way you get written confirmation, and our access to your systems is revoked the same week.

08

How to get the signed copy

A signed copy on request. We send the agreement, the annexes and the sub-processor list before the first brief, so your legal review runs in parallel with the project rather than blocking it at the end.

Tell us who signs on your side and which entity is the controller, and the documents come back the same week.

Frequently asked questions

Who signs it on your side?

Adrian Fusha signs for Pluton Studio. There is no legal department to route it through, which is why it usually comes back the same week rather than the same quarter.

How long does it take?

We send the draft within one working day of your request. From there it depends on your review. A standard signature round takes a few days; a marked-up version from your counsel usually takes one exchange to settle.

What if we host everything in our own EU cloud?

Then the sub-processor list shrinks to nothing and the agreement covers only our access to your environment. That is a common setup and we prefer it when your infrastructure team already has one: fewer moving parts, and the data never leaves your account.

Do you touch personal data at all?

On many projects, only in the sense that we can. We build with data minimisation in mind, work against synthetic data where possible, and keep production access to what a fix requires. But the ability to read is enough to require the agreement, so we sign it rather than argue about it.

Can our data protection officer review it before we start?

Yes, and we would rather they did. Send us their questions in whatever form suits them, a questionnaire, a marked-up draft, or a call, and they get direct answers from the engineer who built the system, not from a template.