GDPR Article 28
Data processing agreement (DPA)
This DPA applies where a workspace customer is controller and DynaSoft processes personal data on its behalf. It becomes binding when incorporated into a contract or order, or expressly accepted.
1. Parties, subject and duration
The processor is DynaSoft Sàrl, 4a, op der Haart, L-9999 Wemperhardt, Luxembourg. The subject is the delivery and operation of Sprint.manager for the contract term and subsequent return or deletion phase.
2. Nature and purposes
- Storage, organisation, retrieval, display, backup and deletion of customer data
- Projects, tickets, sprints, documentation, files, time tracking and enabled AI features
- Support, diagnostics, security and restoration
3. Data subjects and data types
- Members, employees, contractors, customers, contacts and other persons entered by the customer
- Identity, contact, account and role data
- Project, ticket, communication, documentation, file and time data
- Technical security and usage information
4. Instructions and customer duties
DynaSoft processes customer data only on documented instructions unless legally required otherwise. Use of configured functions constitutes an instruction. The customer is responsible for lawfulness, transparency, minimisation and permissions.
5. DynaSoft duties
- Confidentiality
- Appropriate technical and organisational safeguards
- Reasonable assistance with data subject rights, impact assessments and authority requests
- Notification without undue delay of an identified breach
- Evidence and reasonable audits agreed in advance
6. Security measures
- Encrypted transmission
- Role- and workspace-based access control
- Password hashing, CSRF protection and rate limits
- Logging of security and acceptance events
- Upload and storage limits
- Server, network, update, backup and restoration safeguards
7. Subprocessors
The customer gives general authorisation for subprocessors listed in the privacy policy. OVHcloud currently hosts infrastructure in Germany. Ollama is operated directly by DynaSoft. Material changes will be notified in advance and may be objected to on substantiated data protection grounds.
8. Transfers outside the EEA
Transfers outside the European Economic Area occur only on documented instructions or with a GDPR-compliant basis and safeguards. Core processing is intended to take place in Germany.
9. Return and deletion
At the end of service, DynaSoft returns or deletes customer data on instruction unless retention is legally required. Until automated deletion is available, requests are coordinated through andreas.plumacher@dynasoft.lu.
10. Priority and contact
This DPA takes precedence for processing-on-behalf matters. Individual written agreements and mandatory law remain unaffected.
Contact: andreas.plumacher@dynasoft.lu.