Legal Policy

Data Processing Agreement

Data Processing Agreement (DPA)

Effective Date: July 2026

This Data Processing Agreement ("DPA") is entered into between SOVEVO (the "Data Processor") and you, the operator or organization using SOVEVO's platform and services (the "Data Controller").

1. Scope and Purpose

This DPA governs the processing of personal data in connection with your use of SOVEVO's infrastructure, community, and related services. It sets forth the rights, obligations, and responsibilities of both parties regarding the processing, storage, and protection of personal data in compliance with the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP), and other applicable data protection laws in the European Economic Area (EEA).

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
  • Data Controller: The organization or entity that determines the purposes and means of processing personal data.
  • Data Processor: SOVEVO, which processes personal data on your behalf as instructed by the Data Controller.
  • Sub-processor: Any third party engaged by SOVEVO to process personal data (including hosting providers, cloud infrastructure, analytics services).

2.1 Infrastructure Disclosure

SOVEVO is an EU Hub operator, not a hosting provider or infrastructure vendor. SOVEVO's core platform infrastructure is provisioned via third-party Infrastructure as a Service (IaaS) providers. While SOVEVO operates the application layer, community platform, and data processing workflows, the underlying compute, storage, and networking infrastructure is managed by third-party IaaS providers, required to comply with this DPA's requirements and applicable data protection safeguards.

SOVEVO does not claim ownership of the underlying IaaS layer. However, SOVEVO takes full responsibility for ensuring that all sub-processors (including IaaS providers) comply with this DPA, GDPR, and all applicable data protection requirements. Personal data remains subject to this DPA's protections, encryption, access controls, and security measures regardless of which IaaS provider hosts the infrastructure at any given time.

All IaaS and sub-processor changes are made transparently with 30 days' notice, and you have the right to object. SOVEVO maintains complete data portability and can migrate your data to alternative infrastructure providers upon request.

3. Scope of Processing

SOVEVO processes personal data solely for the purposes specified in your service agreement, including:

  • Provision and operation of the SOVEVO platform and community infrastructure
  • User authentication, account management, and access control
  • Communication with you regarding your account and service updates
  • Compliance with legal and regulatory obligations (including tax, law enforcement, financial services)
  • Platform analytics, performance monitoring, and improvement (only in aggregated, non-identifiable form)
  • Security monitoring and fraud prevention

SOVEVO will not use personal data for any purpose beyond those authorized in writing by you, nor will it disclose personal data to third parties except as required by law or as specified in this DPA.

4. Data Subject Rights

As the Data Processor, SOVEVO acknowledges your rights as Data Controller and the rights of individuals (data subjects) whose personal data you process, including:

  • Right of access: to obtain confirmation of and access to their personal data
  • Right of rectification: to correct inaccurate personal data
  • Right of erasure ("right to be forgotten"): to request deletion of their personal data
  • Right to restrict processing: to request that processing be limited
  • Right to data portability: to receive their data in a machine-readable format and transfer it elsewhere
  • Right to object: to object to processing on the grounds of legitimate interest or direct marketing
  • Right not to be subject to automated decision-making

You remain responsible for fulfilling data subject requests. SOVEVO will provide reasonable assistance in responding to requests within 30 days of receipt.

5. Sub-processors and Third Parties

SOVEVO may engage sub-processors to provide hosting, storage, analytics, and other infrastructure services. All sub-processors are subject to data processing agreements that impose the same data protection obligations as this DPA. A current list of approved sub-processors is maintained at https://sovevo.eu/sub-processors and updated with 30 days' notice before any changes.

You have the right to object to the appointment of a new sub-processor within 30 days of notification. If you object on reasonable grounds related to data protection, SOVEVO will work with you in good faith to resolve your concerns or offer to terminate the affected services.

6. Data Location and Storage

SOVEVO is headquartered in Rovinj, Croatia, within the European Union, and processes personal data in compliance with the GDPR. SOVEVO's infrastructure is provisioned via third-party IaaS providers, which may process or store data both within and outside the EEA.

No personal data is transferred outside the EEA without implementation of appropriate safeguards, including Standard Contractual Clauses (SCCs) or adequacy decisions recognized by the European Commission. SOVEVO is contractually bound to maintain these protections even as IaaS providers or infrastructure partners change.

7. Security Measures

SOVEVO implements and maintains comprehensive technical and organizational security measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Secure authentication mechanisms (multi-factor authentication available)
  • Role-based access control and principle of least privilege
  • Regular security audits and penetration testing
  • Incident response and breach notification procedures
  • Employee training on data protection and confidentiality
  • Data backup and disaster recovery protocols

You remain responsible for the security of your authentication credentials and for monitoring access to your account. SOVEVO is not liable for unauthorized access resulting from your failure to secure your credentials.

8. Data Breach Notification

In the event of a personal data breach, SOVEVO will notify you without undue delay and, where feasible, no later than 72 hours after discovery. Notification will include:

  • The nature and scope of the breach
  • Categories and approximate number of affected individuals
  • Likely consequences of the breach
  • Measures taken or proposed to mitigate the breach
  • SOVEVO's Data Protection Officer contact information

You are responsible for notifying affected data subjects and regulatory authorities as required by applicable law. SOVEVO will reasonably cooperate and provide information necessary for you to fulfill your notification obligations.

9. Data Subject Requests and Assistance

SOVEVO will provide reasonable technical and organizational assistance to you in fulfilling data subject requests, including:

  • Extracting and delivering personal data in response to access requests
  • Facilitating data portability by providing data in structured, commonly used formats
  • Deleting or anonymizing personal data upon request
  • Correcting inaccurate data

Requests must be submitted in writing through your account or to our Data Protection Officer.

10. Deletion and Return of Data

Upon termination of your account or this DPA, SOVEVO will, at your direction:

  • Return a copy of all personal data processed on your behalf in a portable, machine-readable format
  • Delete all copies of personal data (except as required by law for tax, legal, or audit purposes)
  • Provide written certification of deletion within 30 days

Data retained for legal compliance will be pseudonymized and isolated from further processing, except as required by law.

11. Audits and Compliance Verification

SOVEVO undergoes annual third-party security audits and maintains ISO 27001 certification. You may request audit reports and compliance documentation at any time. SOVEVO will provide:

  • Proof of certification and audit reports
  • Documentation of security measures and safeguards
  • Sub-processor agreements upon request

Upon reasonable notice, SOVEVO will permit you or an independent auditor to conduct compliance audits at our offices during normal business hours.

12. International Data Transfers

Any transfer of personal data outside the EEA requires:

  • Your prior written consent
  • An adequacy decision by the European Commission, OR
  • Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs) with our sub-processors

13. Your Obligations

As the Data Controller, you agree to:

  • Ensure you have a lawful basis for processing personal data and have complied with all notification requirements
  • Provide accurate, complete information about your processing activities
  • Obtain necessary consent or establish legitimate interest for data collection
  • Implement your own security measures to protect against unauthorized access
  • Comply with all applicable data protection laws
  • Indemnify SOVEVO against claims arising from your processing activities or violation of your obligations

14. Data Protection Impact Assessment (DPIA)

If your processing activities pose high risk to data subject rights, SOVEVO will provide reasonable assistance in conducting a Data Protection Impact Assessment (DPIA), including:

  • Providing documentation of security and organizational measures
  • Describing data processing activities
  • Identifying risks and mitigation strategies

15. Data Protection Officer

SOVEVO has appointed a dedicated Data Protection Officer (DPO) responsible for monitoring compliance with this DPA and applicable data protection laws.

Contact: dpo@sovevo.eu

16. Liability and Indemnification

SOVEVO's liability for data breaches or processing violations is subject to the limitations of your service agreement. You agree to indemnify SOVEVO against claims arising from:

  • Your unauthorized or unlawful processing of personal data
  • Your violation of any data protection law or this DPA
  • Your failure to obtain necessary consents or establish lawful bases
  • Your security failures or unauthorized disclosure of credentials

17. Duration and Amendment

This DPA is effective as of the date you accept these terms and continues for the duration of your service agreement. SOVEVO may update this DPA to reflect changes in law or regulatory requirements with 30 days' notice. Continued use of SOVEVO services constitutes acceptance of amendments.

18. Governing Law and Dispute Resolution

This DPA is governed by the laws of Croatia (EU) and the GDPR, regardless of your location. Any disputes arising from this DPA will be resolved through:

  1. Good-faith negotiation between the parties
  2. Mediation by the relevant data protection authority
  3. Binding arbitration or litigation in Croatian courts as a last resort

19. Contact Information

For questions about this DPA or data protection practices:

  • Data Protection Officer: dpo@sovevo.eu
  • Legal Inquiries: legal@sovevo.eu
  • Mailing Address: SOVEVO, Rovinj, Croatia

This Data Processing Agreement is provided as a template and reflects SOVEVO's commitment to GDPR compliance and data protection. It is intended to be clear, enforceable, and protective of both parties' rights. If you require modifications or have additional requirements, please contact our legal team.