1. Purpose and parties

This Addendum (the "DPA") governs the processing of personal data that EUROPEAN DIGITAL STORES, S.L., tax ID B-70983770, registered office at Calle José Echegaray, 8, Edificio Alvia 3, offices 7 and 8, 28232 Las Rozas (Madrid), Spain ("EDS" or the "Processor"), carries out on behalf of the Customer (the "Controller") in providing ULOX Business.

This DPA forms an integral part of the ULOX Business Terms of Service and is deemed executed upon their acceptance. In the event of conflict between the two on data protection matters, this DPA prevails.

2. Roles of the parties

The Controller determines the purposes and means of processing the personal data that it and its Authorised Users place into the Service. The Processor processes such data solely on the Controller's behalf and in accordance with its instructions.

The Processor acts as an independent controller only in respect of data relating to the administration of the contractual relationship (billing, support and legal compliance), as described in the Business Privacy Policy.

3. Controller instructions

The Processor shall process personal data solely on the Controller's documented instructions, which are deemed to be contained in the Terms of Service, in this DPA and in the configuration of the Service made by the Controller.

The Processor shall inform the Controller if, in its opinion, an instruction infringes data protection law, and may suspend its execution until clarified.

Where the Processor is required by Union or Member State law to carry out different processing, it shall inform the Controller before doing so, unless that law prohibits such information on important grounds of public interest.

4. Processor obligations

5. Confidentiality of personnel

The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality expressly and in writing, or are under an appropriate statutory obligation of confidentiality, and have received the necessary training. This commitment survives the end of their engagement.

Access by the Processor's personnel is limited to the minimum necessary to operate the infrastructure and, by design, never extends to the Controller's encrypted content.

6. Security measures

The Processor implements the appropriate technical and organisational measures under Art. 32 GDPR described in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of individuals.

The Processor may update those measures provided the resulting level of security is no lower than that described.

7. Subprocessors

The Controller grants the Processor general authorisation to engage the subprocessors listed in Annex III.

The Processor shall inform the Controller of any addition or replacement of a subprocessor at least thirty (30) calendar days in advance, by notice to the Administrator's contact email or by publication on this page. The Controller may object on reasonable grounds relating to data protection within that period; if the disagreement persists, it may terminate the agreement without penalty in respect of the affected services.

The Processor shall impose on each subprocessor, by contract, the same data protection obligations it assumes under this DPA, and shall remain liable to the Controller for the subprocessor's performance.

8. Assistance with data subject rights

The Processor shall assist the Controller, insofar as possible and by appropriate technical and organisational measures, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability and objection).

If the Processor receives a data subject request directly concerning data processed on the Controller's behalf, it shall forward it to the Controller without undue delay and shall refrain from responding on the merits.

9. Personal data breaches

The Processor shall notify the Controller without undue delay and in any case within forty-eight (48) hours of becoming aware of any breach of security of personal data processed on its behalf, providing the information available to it: nature of the incident, categories and approximate number of data subjects and records affected, likely consequences and measures taken or proposed.

It is for the Controller to assess notification to the supervisory authority and, where applicable, to data subjects. The Processor shall provide the reasonable assistance requested.

10. Impact assessments and prior consultation

The Processor shall provide the Controller with reasonable assistance for data protection impact assessments and prior consultations with the supervisory authority, as regards information about the processing it performs and the security measures applied.

11. International transfers

Processing takes place entirely on servers located in the European Union. The Processor shall not transfer personal data outside the European Economic Area without the Controller's instruction, except as strictly necessary for the subprocessors identified in Annex III and always under a valid transfer mechanism (adequacy decision or Standard Contractual Clauses with supplementary measures).

Where a transfer concerns only encrypted material for which the recipient holds no keys, end-to-end encryption operates as an effective supplementary measure.

12. Audit and evidence

The Processor shall make available to the Controller the information necessary to demonstrate compliance with this DPA and shall allow for audits, including inspections, conducted by the Controller or an auditor mandated by it.

Audits shall be carried out on at least thirty (30) calendar days notice, during business hours, without disrupting operations, no more than once a year — save at the request of a supervisory authority or following a demonstrated security incident — subject to a confidentiality agreement and at the Controller's cost. The Processor may satisfy this obligation by providing third-party independent reports or certifications where sufficient.

13. Deletion or return on termination

On termination of the services, the Processor shall, at the Controller's choice, delete or return the personal data processed on its behalf and delete existing copies, unless applicable law requires their retention.

The Controller shall have the export period provided for in the Terms of Service. Return can only be effected through an export performed by the Controller itself with its credentials, as the Processor cannot produce a readable copy. After that period, the Processor shall delete the encrypted material, including that held in continuity copies, in accordance with its rotation cycles, within a maximum of ninety (90) calendar days.

14. Liability

Each party is liable for damage caused by its own breach of data protection law, on the terms of Art. 82 GDPR. The Processor's liability to the Controller under this DPA is subject to the limitation of liability clause of the Terms of Service, except where mandatory law does not permit limitation.

15. Term and amendments

This DPA remains in force for as long as the Service is provided; obligations of confidentiality, deletion and cooperation that by their nature must survive shall continue after termination. The Processor may amend it to reflect legal changes or changes to its subprocessors, giving notice in accordance with clause 7.

16. Annex I — Processing details

Subject matterProvision of ULOX Business: an end-to-end encrypted corporate workspace (communication, files, credential vault, documents and user management).
DurationThe term of the contractual relationship, plus the export and deletion periods provided for.
Nature and purposeHosting, transmission, synchronisation and retention of encrypted material; management of corporate identities and contracted capacity; sending of transactional communications.
Types of personal dataContent: in encrypted form only, unintelligible to the Processor (may contain any category the Controller chooses to include). Service data: blinded index of the corporate email address, opaque cryptographic pseudonyms, connection timestamps, credential role and status, and minimal technical operating data.
Categories of data subjectsThe Controller's Authorised Users (employees, contractors) and third parties invited by it.
Special categoriesThe Controller may include them at its sole discretion and responsibility. As they travel end-to-end encrypted, the Processor cannot identify or process them.

17. Annex II — Technical and organisational measures

18. Annex III — Authorised subprocessors

SubprocessorServiceLocation
IONOS SE / IONOS CloudServer and storage infrastructureEuropean Union
SMTP2GOTransactional email delivery (invitations and verification codes). No access to encrypted content.EU / USA with appropriate safeguards
Stripe Payments Europe, Ltd.Payment processing and billing for the ServiceEuropean Union
Apple Inc. · Google LLCPush notification delivery to mobile devices. Notifications do not include message content.USA with appropriate safeguards

The current list of subprocessors is the one published on this page. The Controller may request it in writing at legal@ulox.org.