Legal

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", "Controller") and Nodebyte OÜ ("we", "us", "Processor"), a company registered in Estonia. It applies where we process personal data on your behalf in providing Mediastilo (the "Service"), and it reflects the requirements of Article 28 of the General Data Protection Regulation (GDPR).

Where you use the Service to process personal data about your own contacts, audiences, or the subjects of the content you produce, you are the controller of that data and we are your processor. This DPA governs that processing. It does not cover the data we handle as our own controller (your account and billing data), which is covered by our Privacy Policy.

Last reviewed: 20 July 2026

1. Roles

You are the Controller and we are the Processor for the Customer Personal Data processed under the Service. You determine the purposes and means of the processing. We process it only to provide the Service and only on your instructions.

2. Subject matter and details of processing

  • Subject matter: our provision of the Service to you under the Terms.
  • Duration: for as long as your account is active, followed by the deletion timelines in section 9.
  • Nature and purpose: hosting, storing, transmitting, and processing Customer Personal Data so you can monitor sources, generate and analyse content, and publish it, including processing by our AI provider to generate output at your request.
  • Categories of data subjects: individuals referenced in the content and source material you process, the recipients of content you publish, and the team members you invite.
  • Categories of personal data: whatever you choose to include in the content, prompts, documents, and configuration you submit. You should not include special categories of personal data unless you have a lawful basis to process them.

3. Your instructions

We process Customer Personal Data only on your documented instructions, which include the Terms, this DPA, your configuration of the Service, and your use of its features. We will tell you if, in our opinion, an instruction breaks data-protection law, unless we are legally barred from doing so. If the law requires us to process the data for another reason, we will tell you first unless that law forbids it.

4. Confidentiality

We ensure that the people we authorise to process Customer Personal Data are bound by an appropriate duty of confidentiality and are trained and instructed on their obligations. We limit access to those who need it to provide and support the Service.

5. Security

We implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access, taking into account the state of the art, the cost of implementation, and the risk. These measures include encryption of data in transit and at rest, access controls, encrypted backups, and monitoring. A summary is in the "How we protect data" section of our Privacy Policy.

6. Subprocessors

You give us general authorisation to engage subprocessors to help provide the Service. Our current subprocessors, each with its purpose, the data it handles, and its location, are listed on our Subprocessors page, which forms part of this DPA.

We impose data-protection obligations on each subprocessor by written contract that are at least as protective as those in this DPA, and we remain responsible to you for each subprocessor's performance. We will update the Subprocessors page before a new subprocessor begins processing Customer Personal Data. You may object to a new subprocessor on reasonable data-protection grounds as described on that page; if we cannot offer a reasonable alternative, you may terminate the affected part of the Service and receive a pro-rated refund of any prepaid, unused fees.

7. Assisting you

Taking into account the nature of the processing and the information available to us, we will assist you:

  • to respond to requests from data subjects exercising their rights, including through features in the Service that let you access, export, correct, and delete data yourself;
  • to meet your obligations on security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.

8. Personal data breaches

If we become aware of a breach affecting Customer Personal Data, we will notify you without undue delay after becoming aware of it, and give you the information you reasonably need to meet your own notification obligations, as it becomes available.

9. Return and deletion

On the end of your account, we delete Customer Personal Data on the timelines in the Terms and Privacy Policy: a 30-day recovery window, then permanent deletion, with backups ageing out afterwards. Before then, the Service lets you export and delete your data yourself. We will delete or return Customer Personal Data on your request, except where we are required by law to keep it, in which case we keep it only as long and as far as that law requires.

10. International transfers

Where providing the Service involves transferring Customer Personal Data outside the European Economic Area, we rely on a valid transfer mechanism, being an adequacy decision where one applies (including the EU-US Data Privacy Framework where the provider is certified) or Standard Contractual Clauses with supplementary measures. Details are on the Subprocessors page and in section 6 of our Privacy Policy.

11. Audits

We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. To keep other customers' data and our security safe, audits are conducted on reasonable prior notice, no more than once a year unless a supervisory authority requires otherwise or a breach has occurred, under confidentiality, and in a way that does not disrupt our operations. We may satisfy an audit request by providing relevant documentation and answering your questions.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. If this DPA conflicts with the rest of the Terms on the processing of Customer Personal Data, this DPA prevails.

13. Contact

Data-protection questions under this DPA: contact@heap-software.com

Nodebyte OÜ, Tallinn, Estonia.