Data Processing Agreement
Last updated: June 8, 2026
This Data Processing Agreement (“DPA”) applies when you use OctopusLab to process personal data of your own end users — that is, when you act as Controller and OctopusLab acts as Processor under Article 28 of the EU General Data Protection Regulation (“GDPR”), the United Kingdom GDPR, and equivalent laws. It supplements the Terms of Service and forms a binding part of the agreement between you and OctopusLab.
If you only process your own personal data (for example, a solo developer building a portfolio site), the Privacy Policy alone governs and a separate DPA is not required.
1. Subject Matter and Duration
OctopusLab processes personal data on your behalf for the purpose of providing the Service. The processing continues for the duration of your subscription, plus the retention period set out in the Privacy Policy.
2. Nature, Purpose, and Categories of Data
- Nature of processing: hosting, transmission, transformation, and display of data submitted by your end users to your project.
- Purpose: enabling you to operate the site or application you have built with OctopusLab.
- Data subjects: your end users.
- Categories of personal data: as determined by you. Common categories include contact data, account data, content the end users submit, and technical telemetry. You must not submit special categories of personal data (GDPR Art. 9) without first informing us and amending this DPA in writing.
3. Roles and Responsibilities
You are the Controller and are responsible for the lawful basis, transparency notices, and rights handling vis-à-vis your end users. OctopusLab is the Processor and will:
- Process personal data only on your documented instructions.
- Ensure that personnel authorized to process the data are subject to confidentiality.
- Implement appropriate technical and organizational security measures (see § 7).
- Assist you, taking into account the nature of processing, with data-subject requests, DPIAs, and breach notifications.
- On termination, delete or return personal data on your request, subject to legal retention obligations.
4. Sub-processors
You grant general authorization for OctopusLab to engage sub-processors. The current list is maintained in the Privacy Policy. We will notify you of material changes to the sub-processor list at least 30 days in advance, giving you the opportunity to object on reasonable grounds. If we cannot accommodate the objection, you may terminate the affected Service for cause.
5. International Transfers
Where OctopusLab transfers personal data outside the EEA, the United Kingdom, or other jurisdictions with similar restrictions, the transfer is governed by the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) or equivalent valid transfer mechanisms.
6. Data Subject Rights
You are responsible for responding to data-subject requests. We will, where technically feasible and to the extent permitted by law, provide reasonable assistance — including making available data in a structured, machine-readable format and facilitating deletion.
7. Security Measures
OctopusLab maintains, at minimum, the following measures:
- TLS 1.2+ in transit, AES-256 at rest.
- Application secrets encrypted with AES-256-GCM (BYOK).
- Row-level security (default-deny) on application databases.
- Hardware-key authentication and least-privilege access for our staff.
- Continuous logging and anomaly review via Axiom.
- Annual review of access controls.
8. Audits
On reasonable prior notice and no more than once per twelve months (or following a security incident), you may audit our compliance by reviewing the SOC 2 Type II or equivalent reports we make available, or by submitting a written questionnaire which we will answer within 30 days.
9. Personal Data Breach
We will notify you without undue delay (and, where feasible, within 48 hours) after becoming aware of a personal data breach affecting your data, including the categories and approximate number of data subjects, the likely consequences, and the measures taken or proposed.
10. Liability
Each party's liability under this DPA is subject to the limits of liability set out in the Terms of Service, save where mandatory law requires otherwise.
11. How to Sign
Business customers who require an executed DPA on letterhead should email dpa@octopus-lab.app with the legal name of the Controller and the name and contact of the signatory. We will return a counter-signed copy.