Data Processing Addendum (DPA)
- Purpose and parties
- Roles of the parties
- Controller instructions
- Processor obligations
- Confidentiality of personnel
- Security measures
- Subprocessors
- Assistance with data subject rights
- Personal data breaches
- Impact assessments and prior consultation
- International transfers
- Audit and evidence
- Deletion or return on termination
- Liability
- Term and amendments
- Annex I — Processing details
- Annex II — Technical and organisational measures
- Annex III — Authorised subprocessors
1. Purpose and parties
This Addendum (the "DPA") governs the processing of personal data that EUROPEAN DIGITAL STORES, S.L., tax ID B-70983770, registered office at Calle José Echegaray, 8, Edificio Alvia 3, offices 7 and 8, 28232 Las Rozas (Madrid), Spain ("EDS" or the "Processor"), carries out on behalf of the Customer (the "Controller") in providing ULOX Business.
This DPA forms an integral part of the ULOX Business Terms of Service and is deemed executed upon their acceptance. In the event of conflict between the two on data protection matters, this DPA prevails.
2. Roles of the parties
The Controller determines the purposes and means of processing the personal data that it and its Authorised Users place into the Service. The Processor processes such data solely on the Controller's behalf and in accordance with its instructions.
Essential particularity: ULOX Business operates on a blind server model. Content placed into the Service by the Controller is encrypted on the user's device before it leaves it, and the Processor holds no decryption keys. Accordingly, with respect to that content the Processor provides a service of storing and transmitting unintelligible encrypted material, with no technical ability to access, read, index, copy in readable form or extract it.
The Processor acts as an independent controller only in respect of data relating to the administration of the contractual relationship (billing, support and legal compliance), as described in the Business Privacy Policy.
3. Controller instructions
The Processor shall process personal data solely on the Controller's documented instructions, which are deemed to be contained in the Terms of Service, in this DPA and in the configuration of the Service made by the Controller.
The Processor shall inform the Controller if, in its opinion, an instruction infringes data protection law, and may suspend its execution until clarified.
Where the Processor is required by Union or Member State law to carry out different processing, it shall inform the Controller before doing so, unless that law prohibits such information on important grounds of public interest.
4. Processor obligations
- Process data only to provide the Service and in accordance with the Controller's instructions.
- Not use the data for its own purposes, nor for profiling, model training, advertising or transfer to third parties.
- Maintain a record of processing activities carried out on behalf of the Controller (Art. 30(2) GDPR).
- Make available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR.
- Cooperate with supervisory authorities in the performance of their tasks.
- Appoint a data protection officer where required and communicate their contact details.
5. Confidentiality of personnel
The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality expressly and in writing, or are under an appropriate statutory obligation of confidentiality, and have received the necessary training. This commitment survives the end of their engagement.
Access by the Processor's personnel is limited to the minimum necessary to operate the infrastructure and, by design, never extends to the Controller's encrypted content.
6. Security measures
The Processor implements the appropriate technical and organisational measures under Art. 32 GDPR described in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of individuals.
The Processor may update those measures provided the resulting level of security is no lower than that described.
7. Subprocessors
The Controller grants the Processor general authorisation to engage the subprocessors listed in Annex III.
The Processor shall inform the Controller of any addition or replacement of a subprocessor at least thirty (30) calendar days in advance, by notice to the Administrator's contact email or by publication on this page. The Controller may object on reasonable grounds relating to data protection within that period; if the disagreement persists, it may terminate the agreement without penalty in respect of the affected services.
The Processor shall impose on each subprocessor, by contract, the same data protection obligations it assumes under this DPA, and shall remain liable to the Controller for the subprocessor's performance.
8. Assistance with data subject rights
The Processor shall assist the Controller, insofar as possible and by appropriate technical and organisational measures, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability and objection).
The Controller acknowledges that, as the Processor holds no decryption keys, rights over encrypted content can only be given effect by the Controller itself, from its administration panel and with its organisation's credentials. The Processor cannot locate, extract, rectify or export readable information from the content, and its assistance will be limited to deleting the encrypted material, providing information on technical metadata and supporting the use of the Service's tools.
If the Processor receives a data subject request directly concerning data processed on the Controller's behalf, it shall forward it to the Controller without undue delay and shall refrain from responding on the merits.
9. Personal data breaches
The Processor shall notify the Controller without undue delay and in any case within forty-eight (48) hours of becoming aware of any breach of security of personal data processed on its behalf, providing the information available to it: nature of the incident, categories and approximate number of data subjects and records affected, likely consequences and measures taken or proposed.
It is for the Controller to assess notification to the supervisory authority and, where applicable, to data subjects. The Processor shall provide the reasonable assistance requested.
10. Impact assessments and prior consultation
The Processor shall provide the Controller with reasonable assistance for data protection impact assessments and prior consultations with the supervisory authority, as regards information about the processing it performs and the security measures applied.
11. International transfers
Processing takes place entirely on servers located in the European Union. The Processor shall not transfer personal data outside the European Economic Area without the Controller's instruction, except as strictly necessary for the subprocessors identified in Annex III and always under a valid transfer mechanism (adequacy decision or Standard Contractual Clauses with supplementary measures).
Where a transfer concerns only encrypted material for which the recipient holds no keys, end-to-end encryption operates as an effective supplementary measure.
12. Audit and evidence
The Processor shall make available to the Controller the information necessary to demonstrate compliance with this DPA and shall allow for audits, including inspections, conducted by the Controller or an auditor mandated by it.
Audits shall be carried out on at least thirty (30) calendar days notice, during business hours, without disrupting operations, no more than once a year — save at the request of a supervisory authority or following a demonstrated security incident — subject to a confidentiality agreement and at the Controller's cost. The Processor may satisfy this obligation by providing third-party independent reports or certifications where sufficient.
13. Deletion or return on termination
On termination of the services, the Processor shall, at the Controller's choice, delete or return the personal data processed on its behalf and delete existing copies, unless applicable law requires their retention.
The Controller shall have the export period provided for in the Terms of Service. Return can only be effected through an export performed by the Controller itself with its credentials, as the Processor cannot produce a readable copy. After that period, the Processor shall delete the encrypted material, including that held in continuity copies, in accordance with its rotation cycles, within a maximum of ninety (90) calendar days.
14. Liability
Each party is liable for damage caused by its own breach of data protection law, on the terms of Art. 82 GDPR. The Processor's liability to the Controller under this DPA is subject to the limitation of liability clause of the Terms of Service, except where mandatory law does not permit limitation.
15. Term and amendments
This DPA remains in force for as long as the Service is provided; obligations of confidentiality, deletion and cooperation that by their nature must survive shall continue after termination. The Processor may amend it to reflect legal changes or changes to its subprocessors, giving notice in accordance with clause 7.
16. Annex I — Processing details
| Subject matter | Provision of ULOX Business: an end-to-end encrypted corporate workspace (communication, files, credential vault, documents and user management). |
|---|---|
| Duration | The term of the contractual relationship, plus the export and deletion periods provided for. |
| Nature and purpose | Hosting, transmission, synchronisation and retention of encrypted material; management of corporate identities and contracted capacity; sending of transactional communications. |
| Types of personal data | Content: in encrypted form only, unintelligible to the Processor (may contain any category the Controller chooses to include). Service data: blinded index of the corporate email address, opaque cryptographic pseudonyms, connection timestamps, credential role and status, and minimal technical operating data. |
| Categories of data subjects | The Controller's Authorised Users (employees, contractors) and third parties invited by it. |
| Special categories | The Controller may include them at its sole discretion and responsibility. As they travel end-to-end encrypted, the Processor cannot identify or process them. |
17. Annex II — Technical and organisational measures
- End-to-end encryption: content is encrypted on the user's device before transmission. The Processor neither holds nor can derive the keys.
- Authentication without knowledge of the password: access uses an asymmetric password-authenticated key exchange (aPAKE/OPAQUE), so that the password is never transmitted or stored, not even encrypted or reversibly hashed.
- Opaque identifiers: identities within a workspace are cryptographic pseudonyms that do not allow the server to correlate them with the user's personal identity.
- Minimisation: the corporate email address is stored only as a per-organisation blinded index; the plaintext address is deleted after the invitation is sent.
- Encryption in transit: TLS with valid certificates on all connections.
- Second factor: available for corporate credentials (TOTP and WebAuthn security keys), with the option to require it for administrators.
- Internal access control: infrastructure access is key-based, restricted to essential personnel and logged.
- Location: servers within the European Union.
- Continuity: periodic replication and infrastructure copies of encrypted material, with automated monitoring and alerting. These do not constitute a customer archiving service (see clause 10 of the Terms).
- Governance audit log: workspace administration actions are recorded in an audit log accessible to the Controller.
- Vulnerability management: dependency updates and periodic review of the exposed surface.
- Segregation: each organisation operates with its own cryptographic material; no keys are shared between customers.
18. Annex III — Authorised subprocessors
| Subprocessor | Service | Location |
|---|---|---|
| IONOS SE / IONOS Cloud | Server and storage infrastructure | European Union |
| SMTP2GO | Transactional email delivery (invitations and verification codes). No access to encrypted content. | EU / USA with appropriate safeguards |
| Stripe Payments Europe, Ltd. | Payment processing and billing for the Service | European Union |
| Apple Inc. · Google LLC | Push notification delivery to mobile devices. Notifications do not include message content. | USA with appropriate safeguards |
The current list of subprocessors is the one published on this page. The Controller may request it in writing at legal@ulox.org.
