Data Processing Agreement
Effective date: April 13, 2026 · Last updated: April 13, 2026
This Data Processing Agreement (the "DPA") forms an integral part of the Terms and Conditions entered into between ALIADO EXTERNO, SLU, a company incorporated under the laws of the Principality of Andorra, with registered office at Passatge Arnaldeta de Caboet, 11 Ed. La Torre 2-1, AD700 Escaldes-Engordany, Andorra, company ID L-719104-A (the "Processor", "Tuploy") and the Customer (the "Controller").
This DPA governs the processing of personal data that Tuploy carries out on behalf of the Customer when the Customer uses the Platform to deploy Apps, Databases or Websites that store, transmit or otherwise process personal data of end users or third parties. It is entered into in compliance with Article 28 of Regulation (EU) 2016/679 ("GDPR") and Andorran Qualified Law 29/2021 on the protection of personal data ("LQPD").
By accepting the Terms and Conditions and by uploading, storing or otherwise processing personal data through the Platform, the Customer is deemed to have accepted and entered into this DPA. The Customer may request a countersigned copy at privacy@tuploy.com.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "supervisory authority" and "personal data breach" have the meanings given in Article 4 GDPR.
"Customer Personal Data" means any personal data that the Processor processes on behalf of the Controller in the course of providing the Platform, as described in Annex I.
"Subprocessor" means any third party engaged by the Processor to process Customer Personal Data.
2. Roles of the parties
2.1 With respect to Customer Personal Data, the Customer acts as Controller (or as processor on behalf of its own controllers) and Tuploy acts as Processor.
2.2 Each party shall comply with its own obligations under applicable data protection law. The Customer is responsible for having a valid legal basis for the processing and for providing adequate information to data subjects.
2.3 When Tuploy processes personal data about the Customer itself (account, billing, usage) or about visitors of tuploy.com, Tuploy acts as controller and the Privacy Policy applies instead of this DPA.
3. Subject matter, duration, nature and purpose
3.1 Subject matter: the processing of Customer Personal Data necessary to provide the Platform (hosting, deployment, storage, network delivery, backups, support and security operations).
3.2 Duration: for as long as the Customer uses the Platform, plus the retention and deletion periods set out in section 10 and in the Terms.
3.3 Nature and purpose: operation of a managed Platform-as-a-Service, including building, deploying and running web applications, managed databases and static websites on infrastructure managed by the Processor.
3.4 Types of personal data and categories of data subjects: as described in Annex I. The Controller is solely responsible for the content and nature of the personal data uploaded to the Platform.
4. Processor's obligations
The Processor shall:
- process Customer Personal Data only on documented instructions from the Controller, including as regards transfers outside the EEA/Andorra, unless required to do so by Union or Member State law to which the Processor is subject (in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such notice);
- ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- implement the technical and organizational measures described in Annex II to ensure a level of security appropriate to the risk (Article 32 GDPR);
- respect the conditions for engaging Subprocessors set out in section 6;
- assist the Controller, taking into account the nature of the processing, in fulfilling its obligations to respond to requests from data subjects exercising their rights under Articles 12 to 23 GDPR;
- assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and the information available;
- at the choice of the Controller, delete or return all Customer Personal Data after the end of the provision of services, and delete existing copies unless storage is required by applicable law;
- make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, as set out in section 8.
5. Instructions
5.1 The Terms, this DPA, the configuration options of the Platform and any documented instructions issued by the Controller through the dashboard, the API or support channels constitute the complete set of instructions from the Controller to the Processor.
5.2 The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes applicable data protection law. The Processor may suspend execution of such instruction until it is confirmed or amended by the Controller.
6. Subprocessors
6.1 The Controller grants the Processor a general authorization to engage Subprocessors to provide the Platform. The current list of authorized Subprocessors is published at /legal/subprocessors.
6.2 The Processor shall give at least 15 days prior notice of any intended addition or replacement of a Subprocessor by updating that page and notifying subscribed Customers by email or in-dashboard notification. The Controller may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the affected services without penalty.
6.3 The Processor shall impose on each Subprocessor, by contract, data protection obligations that are no less protective than those set out in this DPA, and remains fully liable to the Controller for the performance of its Subprocessors' obligations.
7. International transfers
7.1 The Processor stores and primarily processes Customer Personal Data on infrastructure located in the European Economic Area. The Principality of Andorra, where the Processor is established, has been recognized by the European Commission as offering an adequate level of data protection (Decision 2010/625/EU), allowing free flow of personal data between the EU/EEA and Andorra.
7.2 Where the Processor transfers Customer Personal Data to a Subprocessor located outside the EEA or an adequacy-recognized country, such transfer shall be subject to appropriate safeguards under Chapter V GDPR, including the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914) and, where necessary, supplementary measures.
8. Audits
8.1 The Processor shall make available to the Controller, upon reasonable request, the information and documentation necessary to demonstrate compliance with its obligations under this DPA and Article 28 GDPR.
8.2 The Controller may carry out audits, including through an independent third-party auditor bound by confidentiality, no more than once per year, with reasonable prior notice (no less than 30 days), during business hours and in a manner that does not unreasonably disrupt the Processor's operations or the security of other customers. The Controller shall bear the costs of such audits, unless the audit reveals a material breach by the Processor.
8.3 The Processor may satisfy audit obligations by providing recent third-party certifications or independent audit reports, where available and relevant.
9. Personal data breaches
9.1 The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, so as to allow the Controller to comply with its own obligations under Articles 33 and 34 GDPR. The parties acknowledge that the time required to notify depends on the nature, scope and investigation of the incident.
9.2 The notification shall include, to the extent available, the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences and measures taken or proposed to address the breach and mitigate its effects.
9.3 Breach notifications are sent to the email address on file for the Controller. The Controller is responsible for keeping its contact information up to date and for notifying its own data subjects and supervisory authorities where required.
10. Return and deletion of Customer Personal Data
10.1 Upon termination or expiry of the Agreement, and subject to the grace periods set out in the Terms, the Processor shall delete all Customer Personal Data and existing copies, unless storage is required by applicable law.
10.2 During the term of the Agreement, the Controller can export and delete Customer Personal Data at any time through the Platform's dashboard and APIs (e.g. database dumps, project deletion). The Controller is responsible for downloading its own data before termination takes effect.
10.3 Backups containing Customer Personal Data are retained for the retention window of the applicable service tier and are rotated and overwritten in the normal course of operations.
11. Liability
The liability of the parties under this DPA is governed by, and subject to, the limitations of liability set out in the Terms and Conditions. Nothing in this DPA shall limit either party's liability where such limitation is not permitted by applicable data protection law.
12. Term, order of precedence and governing law
12.1 This DPA is effective for as long as the Processor processes Customer Personal Data on behalf of the Controller.
12.2 In case of conflict between this DPA and the Terms, this DPA prevails with respect to the processing of Customer Personal Data. In case of conflict between this DPA and any Standard Contractual Clauses incorporated for international transfers, the Standard Contractual Clauses prevail.
12.3 This DPA is governed by the laws of the Principality of Andorra, without prejudice to the mandatory application of GDPR and of the law of the Controller's establishment where required.
Annex I — Description of the processing
Categories of data subjects: end users, customers, employees, contractors, suppliers and any other individual whose personal data the Controller chooses to process through the Platform.
Categories of personal data: any personal data that the Controller uploads, stores, deploys or otherwise processes through the Platform, which may include identification data, contact data, authentication credentials, profile data, content generated by users, transactional data, logs and any other category defined by the Controller. The Controller undertakes not to upload special categories of personal data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR) unless it has previously informed the Processor and both parties have agreed on additional safeguards in writing.
Nature and purpose of processing: hosting, storage, computation, transmission, backup, monitoring and security operations strictly necessary to provide the Platform and the services ordered by the Controller.
Duration: for the duration of the Agreement plus the grace and deletion periods set out in the Terms and in section 10 of this DPA.
Annex II — Technical and organizational measures
The Processor implements the following measures, adapted from time to time to the state of the art and to the risks of the processing:
- Encryption of personal data in transit (TLS 1.2+) and at rest where technically feasible for the relevant service tier.
- Access control: least-privilege access to production systems, unique named accounts, strong authentication, role-based permissions and audit logging of administrative actions.
- Network segmentation: private networking between internal components, firewalling and restricted public exposure of management interfaces.
- Isolation: logical isolation of Customer workloads and data at the application, database and network layers.
- Backups: periodic backups for database service tiers that include them, with integrity checks and controlled restoration procedures.
- Vulnerability management: regular patching of operating systems and dependencies, monitoring of security advisories and timely remediation of known vulnerabilities.
- Logging and monitoring: collection and review of security-relevant events to detect and investigate incidents.
- Incident response: documented procedures to identify, contain, eradicate and recover from security incidents, and to notify affected Controllers.
- Personnel: confidentiality commitments and security awareness for personnel with access to Customer Personal Data.
- Business continuity: reasonable measures to restore availability and access to personal data in a timely manner in the event of a physical or technical incident.
These measures may evolve over time. Material changes that would lower the level of protection will not be applied without a corresponding update to this DPA.

