motordevs

Data Processing Agreement

Effective date: 30 April 2026. Version 1.0.

What this is. When you (a business customer) upload designs or other content that contains personal data of third parties — your employees, contractors, end clients — motordevs processes that personal data on your behalf. Under GDPR Art. 28 we need a written contract on specific terms; this is it. By accepting our Terms of Service as a business customer, you also accept this Data Processing Agreement (the "DPA").

This DPA is structured to align with the EU Commission's 2021 Standard Contractual Clauses for controllers and processors (Implementing Decision (EU) 2021/915), so that the obligations track directly to the templates approved by EU regulators.

1. Roles and applicability

For the personal data described in § 4 below:

This DPA applies only to processing where you are the controller and we are the processor. Where you are a consumer, or where the personal data being processed is your own (your Google account email used for authentication), this DPA does not apply — instead, our Privacy Policy applies and we are the controller of that data.

2. Subject matter and duration

Subject matter: the processing services described in our Terms of Service — storing your designs, running solvers, returning results, providing user-management and access to your account.

Duration: for the term of your subscription, plus the post-termination retention period set out in our Privacy Policy § 6 (account data deleted within 30 days of account closure; backups purged within an additional 30 days; billing records kept for the period required by Greek tax law).

3. Nature and purpose of processing

We process the personal data you upload only to deliver the Service to you under the Terms of Service. Specifically: ingestion (upload), storage at rest, transmission to our compute workers, computation, return of computed results to your account, retention until you delete the content or close your account.

We do not use your personal data for our own purposes, for the benefit of any other controller, or for AI/ML training of any model.

4. Type of personal data and categories of data subjects

The personal data we process on your behalf depends on what you choose to upload. Typically it is limited to:

Category of personal data Source Categories of data subjects
Names, email addresses, project metadata embedded in motor specifications Files you upload Your employees, contractors, end clients
Free-text comments, annotations, descriptions you add to designs Content you create in the studio Anyone you reference in those texts
Account data of your authorised users (email, name, profile picture URL) Their Google sign-in Your authorised users

We do not knowingly process special categories of data (Art. 9 GDPR) or criminal-conviction data (Art. 10). You should not upload such data to motordevs without first agreeing additional safeguards with us in writing.

5. Customer obligations (you)

6. Our obligations as processor

7. Data-subject requests

If we receive a request from a data subject relating to personal data we process on your behalf, we will not respond substantively (other than acknowledging receipt and forwarding to you) and will inform you without undue delay so that you can respond. If you reasonably request our assistance in responding (for example, to extract specific records), we will provide it on commercially reasonable terms.

8. Sub-processors

You give general authorisation, under Art. 28(2) GDPR, for us to engage the sub-processors listed in our Privacy Policy § 5 (and any successor list at privacy § 5). Each sub-processor is bound by a written contract on terms no less protective than this DPA.

We will give you at least 30 days' email notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that 30-day window; in that case we will work with you to find a workable solution and, failing that, you may terminate your subscription before the new sub-processor takes effect, with a pro-rated refund of any unused prepaid period.

9. International transfers

Personal data is processed primarily in the EU. Where any transfer to a third country occurs (currently: Stripe, Google, Cloudflare for some onward processing), the transfer relies on adequacy decisions, the EU-US Data Privacy Framework, or the EU Standard Contractual Clauses (Implementing Decisions (EU) 2021/914 and 2021/915), supplemented by any technical and organisational measures necessary to provide essentially equivalent protection.

10. Liability

Each party's liability under this DPA is subject to the limitations in our Terms of Service § 14, except where Greek or EU mandatory law prohibits (including under GDPR Art. 82 for liability towards data subjects).

11. Term and termination

This DPA takes effect on the day you accept the Terms of Service as a business customer and ends on the day your subscription ends and we have completed the data deletion described in § 6 above.

12. Governing law and jurisdiction

Greek law applies. Any dispute arising from this DPA is subject to the exclusive jurisdiction of the courts of Athens, Greece. These provisions are without prejudice to any rights of data subjects under GDPR.

Annex A — Technical and organisational security measures

We implement the following technical and organisational measures to protect personal data, in line with GDPR Art. 32:

Annex B — Sub-processors

See Privacy Policy § 5 for the current list of sub-processors. Updates to that list count as updates to this Annex.

Contact

Privacy / DPA questions: [email protected]