Data Processing Addendum
Applies automatically to every paid workspace and forms part of the Terms of Service. A countersigned copy is available on request.
1. Roles
You are the controller of personal data contained in the WordPress sites you connect. WPBit Labs BV acts as processor and processes that data only on your documented instructions.
2. Subject matter and duration
Processing lasts for the term of your subscription and covers site management, backup storage, uptime monitoring, vulnerability scanning and reporting.
3. Categories of data subjects
Your personnel, your clients personnel, and end users of the sites you manage, whose data may be present in database backups.
4. Security measures
Encryption in transit (TLS 1.3) and at rest (AES-256), signed per-site connections with rotating keys, least-privilege internal access with mandatory SSO and hardware keys, audit logging, and annual penetration testing. Full detail on the Security page.
5. Sub-processors
Current sub-processors: AWS (EU/US hosting and object storage), Cloudflare (edge and DDoS), Postmark (transactional email), Stripe (payments), Sentry (error tracking, EU region). We remain responsible for their performance and give 30 days notice of additions.
6. International transfers
Where data leaves the EEA, transfers are covered by the EU Standard Contractual Clauses (2021/914) modules two and three, and by the UK Addendum where applicable.
7. Breach notification
We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your workspace, with the facts known at that time and our remediation steps.
8. Audits and assistance
On request we provide our latest penetration test summary and security questionnaire responses, and assist with data subject requests, DPIAs and regulator enquiries.
9. Deletion and return
On termination we delete workspace data within 30 days, except backups already scheduled for expiry under your retention setting, and provide an export on request before deletion.