Data Processing Agreement
Revision 2026-08-16
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Customer", "you") and Individual Entrepreneur OLEKSANDR BONDARENKO, identification number 302312361, Tbilisi, Georgia, trading as DF Views ("DF", "we"). It applies where DF processes personal data on the Customer's behalf.
Terms defined in the GDPR (Regulation (EU) 2016/679) have the same meaning here. "Data Protection Law" means the GDPR, the UK GDPR and Data Protection Act 2018 where applicable, and the Law of Georgia on Personal Data Protection, each as amended.
1Roles
1.1● The Customer is the controller. DF is the processor. The Customer determines the purposes and means of processing personal data contained in its content and in its use of the Service.
1.2The Customer is responsible for:
- a)having a lawful basis for every element of personal data it places into the Service;
- b)giving its own data subjects the information and rights that Data Protection Law requires;
- c)the accuracy, quality and legality of the personal data and of the instructions it gives;
- d)ensuring that its instructions do not cause DF to breach Data Protection Law.
1.3DF acts as an independent controller for the data described in its Privacy Policy — account, authentication, security and billing data. That processing is not governed by this DPA.
1.4Paddle.com Market Ltd acts as an independent controller for payment data, as Merchant of Record.
2Scope and instructions
2.1DF processes personal data only on the Customer's documented instructions, which consist of this DPA, the Terms of Service, the configuration the Customer chooses in the application, and any further written instruction the parties agree.
2.2DF will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, unless legally prohibited from doing so.
2.3If DF is required by law to process personal data beyond the Customer's instructions, it will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
2.4● DF will not use the personal data for its own purposes. In particular DF will not sell it, use it to train machine-learning models, use it for advertising, or use it to build products competing with the Customer.
3Confidentiality
DF ensures that persons authorised to process the personal data are bound by an appropriate duty of confidentiality and are granted access only to the extent necessary.
4Security
4.1DF implements appropriate technical and organisational measures as required by Article 32 GDPR. The measures in force are described in Annex II.
4.2DF may update the measures, provided the level of protection is not reduced.
5Sub-processors
5.1The Customer gives general authorisation for DF to engage sub-processors. Those engaged at the date of this DPA are listed in Annex III.
5.2DF will give the Customer at least 30 days' notice, by e-mail or in the application, before a new sub-processor starts processing. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.
5.3DF imposes on each sub-processor data-protection obligations no less protective than those in this DPA and remains fully liable to the Customer for their performance.
6Assistance to the Customer
6.1Data subject requests. Taking into account the nature of the processing, DF will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data subject rights. Where DF receives such a request directly, it will not respond substantively but will refer the person to the Customer without undue delay, unless legally required to respond.
6.2Wider assistance. DF will assist the Customer, taking into account the nature of processing and the information available to DF, with data protection impact assessments, prior consultations with supervisory authorities, and the security obligations in Articles 32 to 36 GDPR.
6.3DF may charge a reasonable fee for assistance that is disproportionate or repetitive, having given prior notice of the fee.
7Personal data breaches
DF will notify the Customer without undue delay after becoming aware of a personal data breach affecting the personal data it processes for the Customer, and will provide the information reasonably available to it — the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. DF will cooperate with the Customer in investigating and mitigating the breach. Notification is not an acknowledgement of fault.
8Deletion and return
8.1On termination, and at the Customer's choice, DF will delete or return the personal data it processes for the Customer. The Customer may export its content for 30 days after termination; after that period DF deletes it.
8.2Deletion is subject to the retention periods published in the Privacy Policy, to backups that are overwritten in the ordinary course, and to data DF is required by law to retain — which remains subject to this DPA for as long as it is held.
9Audits
9.1DF will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR.
9.2The Customer may audit DF's compliance once in any twelve-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, without access to other customers' data or to systems that would compromise the security of others, and at the Customer's cost. Where DF can demonstrate compliance through a written questionnaire response or a third-party report, that satisfies this clause.
9.3More frequent audits may take place where required by a supervisory authority or following a personal data breach affecting the Customer.
10International transfers
10.1● DF is established in Georgia, which is not the subject of an adequacy decision of the European Commission. Where the Customer transfers personal data subject to the GDPR to DF, the parties rely on the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this DPA by reference and completed as set out in Annex IV.
10.2The UK Addendum issued under section 119A of the Data Protection Act 2018 applies where the Customer is subject to the UK GDPR.
10.3In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
10.4DF will carry out and maintain a transfer impact assessment covering transfers under these Clauses, and will provide it to the Customer on request. DF will notify the Customer without undue delay if it becomes unable to comply with the Standard Contractual Clauses.
10.5Government access requests. DF will, unless legally prohibited, notify the Customer of any legally binding request from a public authority for the personal data, challenge requests that appear unlawful or excessive, and disclose only the minimum required.
11Liability
The limitations and exclusions of liability in the Terms of Service apply to claims under this DPA, except where Data Protection Law or the Standard Contractual Clauses do not permit them.
12Order of precedence
In case of conflict: the Standard Contractual Clauses prevail over this DPA; this DPA prevails over the Terms of Service, in each case only in respect of the processing of personal data.
Subject matter. Provision of the DF Views platform for hosting, configuring and publishing 3D product presentations.
Duration. For the term of the Terms of Service, plus the retention and deletion periods in §8.
Nature and purpose. Storage, transformation for display, delivery to browsers, access control, security, and provision of the administrative application and its journals.
Types of personal data.
| Category | Notes |
|---|---|
| Identification and contact data of the Customer's personnel | e-mail address, name where provided, role in the organisation |
| Authentication data of the Customer's personnel | encrypted second-factor secrets, hashed codes and tokens |
| Activity records | actions taken in the Customer's organisation, with actor, timestamp and IP address |
| Personal data incidentally contained in Customer content | ● the Service is designed for product presentation; it neither requires nor expects personal data in uploaded models, textures or product records. Any personal data placed there is placed by the Customer's choice |
| Technical data of the Customer's end users | processed in transit when a published presentation is loaded. The viewer sets no cookies and stores nothing identifying; it keeps only a picture-quality preference chosen by the visitor (Privacy Policy §4) |
Categories of data subjects. The Customer's personnel and invited collaborators; visitors to websites where the Customer publishes presentations; any individual whose personal data the Customer chooses to include in its content.
Special categories of data. None. The Customer must not place special categories of personal data (Article 9 GDPR) or criminal-offence data into the Service.
Frequency. Continuous, for the duration of the agreement.
DF maintains technical and organisational measures appropriate to the risk, designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to it. Those measures include, as appropriate to the risk:
| Area | Committed outcome |
|---|---|
| Access control — accounts | Multi-factor authentication is required for every account; re-binding a factor requires possession of the current one |
| Access control — sessions | Session credentials are transmitted and stored securely, are bound to a limited lifetime, and are revoked on sign-out, account disablement and organisation suspension |
| Access control — sensitive actions | Administrative actions with lasting effect require a recent re-authentication, not merely an active session |
| Secret storage | Authentication secrets are encrypted, and one-time codes, recovery codes and session tokens are stored only in a form from which the original cannot be recovered. No payment card data is held |
| Tenant isolation | Isolation between customers is enforced by the data layer itself, not only by application queries, and applies to the account under which the application connects |
| Support access | Support personnel have no general access to customer data; access is limited to purpose-built views that exclude content and authentication secrets, and requires recent re-authentication |
| Accountability | Activity is recorded in append-only journals that the application cannot alter or delete, and export of a journal is itself recorded |
| Content delivery | Published assets are served only against a short-lived signed authorisation; knowledge of a URL is not sufficient |
| Revocation | Removal takes effect immediately for newly issued access; authorisations already issued expire within their short lifetime |
| Abuse prevention | Layered rate limiting on authentication, invitation and registration, keyed by pseudonymised values rather than by the underlying identifiers |
| Encryption in transit | Industry-standard transport encryption throughout |
| Storage location | Object storage is created under EU jurisdiction; see Annex III for the location of each contractor |
| Deletion | Retention periods are enforced by an automated scheduled process, not manually |
| Backup | Backups are encrypted before leaving DF's infrastructure and are retained on a defined schedule; see the Privacy Policy for the maximum window |
| Change management | Releases are gated by automated checks that must pass before deployment |
| Personnel | Access limited to those who need it, under confidentiality obligations |
● Why this Annex states outcomes and not implementation. The specific algorithms, role names, view names and check names by which these outcomes are achieved change as the system improves. Had they been written into this Annex, every such improvement would require re-issuing this agreement — with the practical result that the description would go stale rather than the implementation staying current. The current implementation is described in the Security Whitepaper, provided on request at security@dfviews.com.
▲ This is not a licence to weaken protection. Under §4.2 DF may update individual measures only where the overall level of protection is not reduced. The commitments above are the floor; the whitepaper describes how the floor is met today.
| Sub-processor | Established in | Purpose | Location of processing |
|---|---|---|---|
| Cloudflare, Inc. | United States | Application execution, object storage of uploaded and published files, content delivery, network security | Object storage buckets created with EU jurisdiction; delivery via the global network |
| Neon, Inc. | United States | Managed PostgreSQL database for account, activity and consent records | European Union — AWS Europe Central 1 (Frankfurt, Germany) |
| Plus Five Five, Inc. (Resend) | United States | Transactional e-mail: sign-in codes, invitations, service notices | European Union (Ireland region) |
| Hetzner Online GmbH | European Union (Germany) | Two separate roles. (1) Hosting of the community gallery: a virtual server and its database holding gallery records — public author profiles, published works, likes, follows, view counts, reports and moderation decisions. (2) Off-site backup: a separate machine and storage box that receive the encrypted daily backup of the platform, which includes uploaded source files, published assets, publication manifests and the database | European Union — Helsinki, Finland |
The two Hetzner roles are separate systems and must not be read as one. The gallery circuit holds only the gallery records described above: it holds no 3D geometry, no textures, no publication manifests, no signing keys and no billing data. The backup machine is a different system and does hold that material — as an encrypted copy, which is written and read only by us, and from which no service is served. Backups are encrypted before they leave our infrastructure.
Paddle.com Market Ltd is deliberately not listed above. It is the Merchant of Record and acts as an independent controller for the payment data it collects from buyers (§1.4), not as a sub-processor engaged by DF on the Customer's behalf. It is disclosed in the Privacy Policy §5 with that role stated, so that a customer auditing our contractors still finds it — but the obligations of §5.3, including DF's liability for its sub-processors, do not and cannot extend to a controller acting on its own account.
The current list is published at dfviews.com/legal/dpa. Customers are notified at least 30 days in advance of any addition, replacement or removal (§5.2).
| Clause | Completion |
|---|---|
| Module | Module Two — controller (data exporter) to processor (data importer) |
| Data exporter | The Customer, as identified in its account |
| Data importer | Individual Entrepreneur OLEKSANDR BONDARENKO, identification number 302312361, registered in Georgia. Contact: privacy@dfviews.com. ⚠️ The full registered address is inserted in the executed copy of the Clauses — Annex I.A of Implementing Decision (EU) 2021/914 requires the parties' addresses, and the published template is completed on execution. It is also verifiable in the public register (napr.gov.ge) by identification number |
| Clause 7 (docking) | Not applied |
| Clause 9 (sub-processors) | Option 2 — general written authorisation, 30 days' notice (§5.2) |
| Clause 11 (redress) | Optional independent dispute-resolution body: not applied |
| Clause 17 (governing law) | The law of Ireland. ⚠️ Conventional default for these Clauses, chosen because Ireland is an English-language common-law-influenced EU forum widely used for this purpose — not because it was advised for this business. Revisit with counsel |
| Clause 18 (forum) | Courts of Ireland |
| Annex I.A (parties) | As above |
| Annex I.B (description of transfer) | As in Annex I of this DPA |
| Annex I.C (supervisory authority) | The Data Protection Commission of Ireland |
| Annex II (security measures) | As in Annex II of this DPA |
| Annex III (sub-processors) | As in Annex III of this DPA |
Contact: privacy@dfviews.com · Individual Entrepreneur OLEKSANDR BONDARENKO, identification number 302312361, registered in Georgia; registry entry verifiable at napr.gov.ge, extract on request.