Data Processing Addendum
Questions about this document? Write to legal@layerport.app.
This Data Processing Addendum applies when a customer uses LayerPort to process personal data on behalf of that customer, principally visitor submissions received through a published form and personal data present in an authorized capture. It forms part of the Terms of Service.
1. Roles and instructions
The customer is the controller or business and Adrian Fernando Santelis Mendoza is the processor or service provider for Customer Data. We process Customer Data only to provide, secure and support the service, on the customer's documented instructions in the Terms and product controls, or where law requires it. Each party remains independently responsible for account, billing, fraud and legal-contact data it controls.
2. Customer obligations
The customer must have a lawful basis and give any required notice for data it submits or asks us to collect, configure forms to request no more than necessary, answer data-subject requests, and not use the service for sensitive data, children's data or regulated high-risk decisions without a separate written agreement.
3. Confidentiality and security
People authorized to handle Customer Data are bound to confidentiality. Measures include TLS in transit, account-scoped storage, server-side authorization, hashed session and verification values, rate and resource limits, an isolated preview origin, restricted network egress, protected backups, audit records and access limited to support or security need. Security measures may evolve without materially reducing protection.
4. Subprocessors and location
- Hetzner — compute, storage and backup in Germany.
- Resend — transactional delivery when Customer Data must be emailed.
Google authentication and Paddle billing primarily process account or transaction data for their own stated roles; they do not receive captured project files or form submissions through this service. We remain responsible for subprocessors to the extent required by applicable law and will give reasonable notice of a material new subprocessor through the service or account email.
5. Assistance and incidents
Taking into account the nature of processing, we provide product controls and reasonable assistance for access, correction, deletion, objection, security assessments and legally required consultations. We notify the customer without undue delay after confirming a breach of Customer Data and provide available information about its nature, likely consequences and mitigation. The customer decides whether it must notify its users or an authority.
6. Return, deletion and audits
The customer can export project files and delete projects or the account. On termination we delete Customer Data from live service storage, subject to rolling backup expiry and legal preservation. We provide the security documentation reasonably necessary to demonstrate these commitments; an on-site audit requires reasonable advance notice, confidentiality, no access to another customer's data and reimbursement of unusual costs.
7. International transfers and conflict
Hosting location is Germany. The customer must ensure any international transfer it initiates is lawful. This addendum does not by itself incorporate EU Standard Contractual Clauses; customers that require GDPR transfer terms must obtain a separately executed addendum before sending regulated data. If this addendum conflicts with the Terms about processing Customer Data, this addendum controls.
Privacy and DPA contact: privacy@layerport.app.