Data Processing Agreement
Version 1 · published 2d ago
Data Processing Agreement
Processor: Zero Folks AB, trading as Koya Labs ("Weblooks", "we", "us") Registered address: Swedenborgsgatan 5B, 118 48 Stockholm, Sweden Company registration number: 559523-7602 (Bolagsverket, Sweden) Controller: the customer identified in the account or order form ("you") Effective from: the date this version was published — see the version stamp at the top of this page. Contact: [email protected]
This Data Processing Agreement ("DPA") forms part of the Terms of Service. It applies where we process personal data on your behalf in the course of providing the Service, and is entered into under Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the UK GDPR.
It takes effect automatically when you accept the Terms of Service. No signature is required. If your organisation requires a countersigned copy, write to [email protected].
Where this DPA conflicts with the Terms of Service on the subject of processing personal data, this DPA prevails.
1. Roles
- You are the controller for personal data contained in your Customer Content, in the websites you build and publish, and in the consent records collected by sites you publish. You determine the purposes and means of that processing.
- We are the processor for that data, and process it only to provide the Service.
- We are a separate, independent controller for data we process for our own purposes — administering your account, billing, securing the platform, meeting our legal obligations, and understanding how the Service is used. The Privacy Policy governs that processing; this DPA does not.
- Where you invite collaborators, reviewers, or clients, you remain the controller for their participation in your projects.
2. Subject matter and duration
We process personal data for as long as you use the Service, and thereafter only as described in section 10.
The subject matter, nature, purpose, categories of data subject, and categories of personal data are set out in Annex I.
3. Processing on documented instructions
We process personal data only on your documented instructions, including for international transfers, unless required to do otherwise by Union or Member State law to which we are subject. Where such a requirement applies, we will inform you before processing unless that law prohibits it on important grounds of public interest.
Your instructions are: the Terms of Service, this DPA, your configuration of the Service, and the actions you and your authorised users take through the Service and its APIs.
We will inform you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law.
We do not sell personal data, use Customer Content to train machine-learning models, or process personal data in Customer Content for our own purposes such as advertising or profiling.
4. Confidentiality
We ensure that persons authorised to process personal data are bound by an appropriate obligation of confidentiality, and that access is limited to those who need it to provide, support, or secure the Service.
5. Subprocessors
You give general written authorisation for us to engage subprocessors. The current list is published at Subprocessors.
- We impose data protection obligations on each subprocessor that are no less protective than those in this DPA.
- We remain fully liable to you for a subprocessor's performance of its obligations.
- We give 30 days' notice before adding or replacing a subprocessor that processes personal data. Subscribe at [email protected].
- You may object on reasonable data-protection grounds within that period. We will work with you in good faith to find an alternative. If none is available and the change is necessary to continue providing the Service, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused term.
6. Security
We implement and maintain the technical and organisational measures described in Annex II, taking account of the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.
We may update these measures over time provided the level of protection is not reduced.
7. Assisting you with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures — insofar as this is possible — in fulfilling your obligation to respond to requests to exercise data subject rights.
In practice:
- The Service provides self-service tools to access, correct, export, and delete data.
- If a data subject contacts us directly about data we process on your behalf, we will not respond substantively. We will refer them to you and inform you without undue delay.
- Where you need help that the self-service tools cannot provide, contact [email protected]. We provide reasonable assistance at no charge for requests proportionate to the Service.
8. Personal data breach
If we become aware of a personal data breach affecting personal data we process on your behalf, we will:
- notify you without undue delay and in any event within 48 hours of becoming aware;
- provide the information reasonably available to us — the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — supplementing it in phases as more becomes known;
- take reasonable steps to contain and remediate the breach; and
- assist you in meeting your own obligations under Articles 33 and 34 GDPR.
Notifying you is not an admission of fault or liability.
Our incident response process is documented internally and is available for review under section 11.
9. Data protection impact assessments
Taking into account the nature of processing and the information available to us, we provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority under Articles 35 and 36 GDPR.
10. Deletion and return
On termination or expiry, and at your choice:
- You may export your projects and content using the tools in the Service for 30 days after termination. See Terms of Service section 22.
- After that period we delete personal data we process on your behalf, except where Union or Member State law requires us to retain it. Deletion covers records held in our primary database and, on the same schedule, associated objects held in our object storage.
- Backups and disaster-recovery copies are overwritten on their normal rotation and are not restored except to recover the Service. Retention periods are listed in the Privacy Policy.
- On written request, we will certify deletion.
11. Audits and information
We make available to you the information necessary to demonstrate compliance with Article 28 GDPR, including:
- this DPA and Annex II
- our security model documentation
- the subprocessor list
- responses to reasonable written security questionnaires
Where that information is not sufficient, you may request an audit — including an inspection — conducted by you or an independent auditor you mandate who is not a competitor of ours and is bound by confidentiality. Audits take place:
- on at least 30 days' written notice
- during normal business hours
- no more than once in any 12-month period, unless required by a supervisory authority or following a personal data breach affecting your data
- without unreasonable disruption to the Service or access to other customers' data
You bear the cost of an audit, unless it identifies a material breach of this DPA.
12. International transfers
We process personal data primarily within the EEA. Where a transfer outside the EEA occurs — see the processing locations in Subprocessors — it is made under:
- an adequacy decision of the European Commission; or
- the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated into this DPA by reference and take effect on the same terms; together with a transfer impact assessment and any supplementary measures required.
For UK transfers, the UK International Data Transfer Addendum applies to the Standard Contractual Clauses. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
Where the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail. For the purposes of the Clauses: the optional docking clause applies; the governing law and forum are as stated in Terms of Service section 29; Annex I and Annex II of this DPA serve as the corresponding Annexes; and Annex III is the Subprocessors page.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits a data subject's rights, or either party's liability to a supervisory authority.
---
Annex I — Description of the processing
Categories of data subject
- your personnel and authorised users
- collaborators, reviewers, and clients you invite to projects
- visitors to websites you publish through the Service, in respect of consent records
- individuals whose personal data appears in content, assets, comments, or CMS entries you upload or connect
Categories of personal data
- identity and contact data: name, email address, avatar
- account and access data: role, workspace membership, permissions, invitation and acceptance records
- authentication and security data: session and token metadata, sign-in events, IP address, device and browser signals, audit log entries
- collaboration data: comments, mentions, review actions and verdicts
- content data: any personal data contained in project files, pages, media, alt text, metadata, and CMS entries you create, upload, or connect
- consent data: pseudonymised consent records for sites you publish, comprising a per-project HMAC subject identifier, the purposes granted or denied, the policy version, and a timestamp. No IP address, user agent, or URL is stored
- billing data, where a paid plan is purchased: billing contact details and transaction metadata
Special categories of personal data
Not requested and not required by the Service. If you choose to place special category data in Customer Content, you are responsible for the lawful basis and any additional safeguards under Article 9 GDPR.
Nature and purpose of the processing
Hosting, storing, transmitting, serving, indexing, backing up, analysing for governance and accessibility checks, and otherwise processing as necessary to provide the Service described in the Terms of Service, on your instructions.
Duration
For the term of your use of the Service, plus the retention and deletion periods in section 10 and in the Privacy Policy.
Frequency
Continuous, for the duration of the agreement.
---
Annex II — Technical and organisational measures
The following measures are in place. They may be updated provided the level of protection is not reduced.
Access control and authentication
- Passwordless sign-in by default (magic link), with passkey support. Password authentication is permitted only with multi-factor authentication enabled.
- Opaque session tokens; only a SHA-256 hash is persisted. Session cookies are `httpOnly`, `secure`, and `sameSite=lax`.
- Sign-in tokens are single-use with a 15-minute expiry.
- Step-up re-authentication is required for sensitive administrative and project-write actions.
- Role-based access control with least-privilege roles (owner, admin, editor, reviewer, client read-only, client comment-only), enforced server-side by a single access predicate.
- Staff access to administrative interfaces is isolated to a separate subdomain and gated by an identity-provider trust policy restricted to company accounts.
- Deactivation and deletion revoke all sessions and tokens immediately.
Encryption
- TLS in transit for all external connections.
- Third-party credentials — source-control tokens, storage credentials, and CMS credentials — are encrypted at rest with AES-256-GCM.
- Session, sign-in, desktop, and API tokens are stored only as SHA-256 hashes.
- Platform secrets are held in a dedicated secret-management system and are never committed to source control, logs, or client bundles.
Tenant isolation and storage segregation
- Object storage is segregated by trust level. Uploaded project source is held in a private bucket that is never publicly readable, is reachable only through an authenticated API, and for which no presigned-URL capability exists.
- Storage keys are validated on every read and write so that they cannot escape a project's prefix.
- Cross-tenant access is gated by the same membership check on every path; the permission suite is a required check in continuous integration.
- Imported files are held in quarantine and are never served until they pass an automated secret scan.
Network and application security
- An enforced Content-Security-Policy, plus `X-Content-Type-Options`, `X-Frame-Options`, `Referrer-Policy`, `Permissions-Policy`, and cross-origin isolation headers.
- Database and cache bound to loopback; a cloud firewall restricts inbound traffic to the CDN's address ranges. Administrative access is via key-only SSH behind an identity-aware proxy.
- Inbound webhooks are verified by HMAC-SHA-256 with constant-time comparison.
- Rate limiting on authentication, intake, comment, upload, scan, and deploy endpoints.
- Input validation at every system boundary; output encoding on rendered content.
- Automated dependency and secret scanning, and static analysis, on every change.
Logging, monitoring, and auditability
- Structured application logs and a tamper-evident audit log covering authentication, permission changes, administrative actions, and deployments. Audit records are retained for 12 months and pruned automatically.
- A separate administrative access log.
- Error monitoring with all text masked and media blocked in session replay; no normal-session replay is collected.
- Documented incident playbooks.
Environment separation and change control
- Production, development, and test environments are separated, with distinct databases and credentials; the production environment fails to start without an explicit environment declaration.
- Changes are reviewed, tested, and deployed through an automated pipeline with unit, integration, permission, accessibility, and end-to-end test suites as required checks.
- Feature rollouts can be ramped and killed independently of deployment.
Data minimisation and retention
- Consent records are pseudonymised with a per-project key so that records from different projects cannot be joined to follow an individual, and fail closed rather than storing a reversible identifier.
- Retention periods are enforced by scheduled jobs, not by manual action.
- Data export and deletion are available to end users as self-service operations.
Availability
- Automated backups with periodic rotation.
- Health checks, error alerting, and post-deploy smoke tests.
- Deployments are versioned and can be rolled back.
Personnel
- Access on a need-to-know basis, reviewed on role change and revoked on departure.
- Confidentiality obligations for all personnel with access to personal data.
---
Annex III — Subprocessors
The current list is published at Subprocessors and forms part of this DPA.