Effective date: 2 October 2026
Last updated: 2 October 2026
This Data Processing Addendum (“DPA“) forms part of the Terms and Conditions between Ermada, obrt za računalne usluge, vl. Dalibor Družinec, Stonska ulica 1, 10000 Zagreb, Croatia (“WPservice“, “we“, “us“) and the customer (“you“). It applies whenever we process personal data on your behalf while providing our Services. You do not need to sign it: it applies automatically when you accept the Terms. If you need a countersigned copy, email [email protected].
Terms used in this DPA have the meaning given in the Terms and Conditions and in the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR“). References to the GDPR include the UK GDPR where UK law applies to you.
1. Roles and scope
- For the processing described in Annex 1, you are the controller (or a processor acting for your own client) and we are your processor.
- This DPA does not cover personal data for which we are the controller, such as your account, order and billing data. Our Privacy Policy covers that.
2. Your instructions
- We process the personal data only on your documented instructions. Your instructions are: the Terms, this DPA, your Order, the settings you choose in our Software, and any further written instructions we accept.
- We will tell you if we believe an instruction breaks data protection law. We may pause the affected processing until you confirm or change the instruction.
- If the law requires us to process the personal data in another way, we will tell you first, unless that law forbids it.
3. Your responsibilities
You are responsible for:
- having a legal basis for the processing and giving the required information to the people concerned;
- only giving us access to personal data that the Services need. For example, give us a dedicated administrator account with the narrowest suitable role, and remove it when the work ends; and
- only scanning websites you are authorised to scan (Section D2 of the Terms).
4. Confidentiality
Everyone we authorise to process the personal data is bound by a duty of confidentiality.
5. Security
We apply the technical and organisational measures in Annex 2. We may update them, but will not lower the overall level of protection.
6. Sub-processors
- You give us general authorisation to use the sub-processors listed in Annex 3.
- We will announce a new or replacement sub-processor at least 30 days in advance, by email or on our Website. You may object in writing within that period on reasonable data protection grounds. If we cannot resolve your objection, you may end the affected Service and receive a pro-rata refund of prepaid fees for the unused period.
- We bind each sub-processor by contract to data protection duties no weaker than those in this DPA. We remain responsible to you for their work.
7. International transfers
- Our Website and its database are hosted in the European Union. The Dr. Speed scanning service is hosted in the United States.
- Where personal data is transferred outside the European Economic Area or the United Kingdom, the transfer is covered by an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), with the UK Addendum where UK law applies.
8. Helping you with your obligations
- Requests from individuals. If someone sends us a request about personal data we process for you, we will pass it to you without undue delay and will not answer it ourselves unless you ask us to. We will give you reasonable help in responding.
- Assessments and authorities. We will give you reasonable help with data protection impact assessments and with consultations with supervisory authorities, taking into account the nature of the processing and the information available to us.
9. Personal data breaches
If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay, and within 48 hours where feasible. The notice will describe what we know: the nature of the breach, the data and people likely affected, the likely consequences, and the measures taken or proposed. We will keep you updated as we learn more.
10. Deletion and return
- Professional Services. When the engagement ends, we delete the access credentials you gave us and any copies of personal data from Your Site that we hold, such as backups we took, within 30 days. On request made before that date, we return them to you first.
- Cloud Services. Scan data is deleted according to the retention periods in Section 9 of the Privacy Policy.
- We may keep personal data longer only where the law requires it, and will keep protecting it under this DPA.
11. Audits
- On request, we will give you the information reasonably needed to show that we comply with this DPA.
- If that information is not enough, you may audit our compliance once per year, or more often after a personal data breach or where a supervisory authority requires it. Give us at least 30 days’ written notice. Audits take place during business hours, must not disrupt our operations, and are subject to confidentiality. You bear your own audit costs.
12. Liability and term
- The liability provisions of the Terms apply to this DPA. Nothing in this DPA limits the rights of individuals or the powers of supervisory authorities under the GDPR.
- This DPA applies for as long as we process personal data on your behalf.
- If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.
Annex 1 — Description of the processing
| Professional Services | Dr. Speed Cloud Services | |
|---|---|---|
| Subject matter | Speed optimisation, maintenance and related work on Your Site | Automated scanning and testing of the pages you select |
| Duration | The length of the engagement or maintenance plan | Each scan, plus the retention periods in the Privacy Policy |
| Nature and purpose | Access to Your Site’s admin area, files, database and hosting to carry out the agreed work. We do not use the personal data stored there for any other purpose. | Loading pages in an automated browser, comparing how they display and work, and generating rules. Page content is processed in memory. |
| Types of personal data | Whatever Your Site stores: for example user accounts, customer and order data, form entries, comments | Personal data that appears on the scanned pages or in their URLs; optional staging login; pseudonymised misuse reports (a one-way hash derived from a visitor’s IP address, browser user agent and requested path) |
| People concerned | Your Site’s users, customers, subscribers and staff | People named or shown on the scanned pages; your staff; visitors who trigger a misuse report |
| Special categories | Not intended. Tell us before the work starts if Your Site stores special-category data. | Not intended |
Annex 2 — Security measures
- Encryption in transit (HTTPS/TLS) for all connections to our Website, API and scanning service.
- API keys and job tokens stored only as one-way hashes.
- Optional staging logins stored and queued only in encrypted form.
- Identifiers in logs and telemetry pseudonymised.
- Page content and screenshots from scans processed in memory and not saved to disk.
- Web application firewall, bot protection and rate limiting.
- Access to systems and customer credentials restricted to the people who need it.
- Customer access credentials used only for the agreed work and deleted when it ends.
- Software kept up to date; backups of our own systems.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Hosting of wpservice.pro, its database and email | Germany (Frankfurt), EU |
| Cloudflare, Inc. | Content delivery and security for wpservice.pro | USA, global network |
| Railway Corporation | Hosting of the Dr. Speed scanning service and its job queue | USA (US West) |
| Defiant, Inc. (Wordfence) | Firewall and security for wpservice.pro | USA |