Data Processing Agreement
This DPA is structured to align with the EU Commission's 2021 Standard Contractual Clauses for controllers and processors (Implementing Decision (EU) 2021/915), so that the obligations track directly to the templates approved by EU regulators.
1. Roles and applicability
For the personal data described in § 4 below:
- You ("Customer") are the data controller.
- We ("motordevs", currently Giorgos Sakkas, sole trader in Greece, future Ι.Κ.Ε.) are the data processor.
This DPA applies only to processing where you are the controller and we are the processor. Where you are a consumer, or where the personal data being processed is your own (your Google account email used for authentication), this DPA does not apply — instead, our Privacy Policy applies and we are the controller of that data.
2. Subject matter and duration
Subject matter: the processing services described in our Terms of Service — storing your designs, running solvers, returning results, providing user-management and access to your account.
Duration: for the term of your subscription, plus the post-termination retention period set out in our Privacy Policy § 6 (account data deleted within 30 days of account closure; backups purged within an additional 30 days; billing records kept for the period required by Greek tax law).
3. Nature and purpose of processing
We process the personal data you upload only to deliver the Service to you under the Terms of Service. Specifically: ingestion (upload), storage at rest, transmission to our compute workers, computation, return of computed results to your account, retention until you delete the content or close your account.
We do not use your personal data for our own purposes, for the benefit of any other controller, or for AI/ML training of any model.
4. Type of personal data and categories of data subjects
The personal data we process on your behalf depends on what you choose to upload. Typically it is limited to:
| Category of personal data | Source | Categories of data subjects |
|---|---|---|
| Names, email addresses, project metadata embedded in motor specifications | Files you upload | Your employees, contractors, end clients |
| Free-text comments, annotations, descriptions you add to designs | Content you create in the studio | Anyone you reference in those texts |
| Account data of your authorised users (email, name, profile picture URL) | Their Google sign-in | Your authorised users |
We do not knowingly process special categories of data (Art. 9 GDPR) or criminal-conviction data (Art. 10). You should not upload such data to motordevs without first agreeing additional safeguards with us in writing.
5. Customer obligations (you)
- You warrant that you have a lawful basis under GDPR Art. 6 (and, where relevant, Art. 9) for the personal data you upload, and that you have given the data subjects the information they are entitled to under Arts 13 and 14.
- You give documented instructions to us only through the functionality of the Service (uploading content, deleting content, configuring your account). Any other instruction must be in writing and we will confirm whether we can act on it; we may decline if the instruction is unlawful or materially expands our obligations.
- You are responsible for the accuracy of the personal data you upload and for keeping it up to date.
- You are responsible for responding to data-subject requests received by you about content under your control. We will assist as set out in § 7 below.
6. Our obligations as processor
- Process only on your documented instructions (GDPR Art. 28(3)(a)), including with regard to international transfers, except where a Greek or EU law to which we are subject requires otherwise (in which case we will inform you of that legal requirement before processing, unless the law prohibits it).
- Confidentiality (Art. 28(3)(b)): personnel authorised to process the personal data are bound by contractual or statutory confidentiality obligations.
- Security measures (Art. 28(3)(c) and Art. 32): see Annex A below.
- Sub-processors (Art. 28(3)(d) and Arts 28(2) and (4)): see § 8 below.
- Assist you with data-subject rights (Art. 28(3)(e)): see § 7 below.
- Assist you with security, breach notification, DPIA, and consultation with supervisory authority (Art. 28(3)(f), Arts 32–36): we will (i) notify you of any personal data breach affecting your data without undue delay (and in any event within 48 hours of becoming aware), with the information required by Art. 33(3) so far as we possess it; (ii) provide you reasonable assistance in conducting a Data Protection Impact Assessment if you request one; (iii) cooperate with consultation by a supervisory authority that arises from your processing on our infrastructure.
- Return or delete data (Art. 28(3)(g)): on termination of the Terms of Service, we will delete your personal data within 30 days unless retention is required by Greek or EU law (in which case we will inform you of the retention period and basis). You may export your designs and metadata at any time before deletion using the export functionality in the studio.
- Make information available; permit audits (Art. 28(3)(h)): we will, on reasonable written request and no more than once per twelve-month period, provide you with information necessary to demonstrate compliance with this DPA and Art. 28 GDPR. Audits beyond reviewing such information are by mutual agreement; reasonable costs of an on-site audit are borne by you. Our compliance with industry security standards (ISO 27001, SOC 2) at our sub-processor level — once formally certified — may be relied on in lieu of on-site audits at our level.
7. Data-subject requests
If we receive a request from a data subject relating to personal data we process on your behalf, we will not respond substantively (other than acknowledging receipt and forwarding to you) and will inform you without undue delay so that you can respond. If you reasonably request our assistance in responding (for example, to extract specific records), we will provide it on commercially reasonable terms.
8. Sub-processors
You give general authorisation, under Art. 28(2) GDPR, for us to engage the sub-processors listed in our Privacy Policy § 5 (and any successor list at privacy § 5). Each sub-processor is bound by a written contract on terms no less protective than this DPA.
We will give you at least 30 days' email notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that 30-day window; in that case we will work with you to find a workable solution and, failing that, you may terminate your subscription before the new sub-processor takes effect, with a pro-rated refund of any unused prepaid period.
9. International transfers
Personal data is processed primarily in the EU. Where any transfer to a third country occurs (currently: Stripe, Google, Cloudflare for some onward processing), the transfer relies on adequacy decisions, the EU-US Data Privacy Framework, or the EU Standard Contractual Clauses (Implementing Decisions (EU) 2021/914 and 2021/915), supplemented by any technical and organisational measures necessary to provide essentially equivalent protection.
10. Liability
Each party's liability under this DPA is subject to the limitations in our Terms of Service § 14, except where Greek or EU mandatory law prohibits (including under GDPR Art. 82 for liability towards data subjects).
11. Term and termination
This DPA takes effect on the day you accept the Terms of Service as a business customer and ends on the day your subscription ends and we have completed the data deletion described in § 6 above.
12. Governing law and jurisdiction
Greek law applies. Any dispute arising from this DPA is subject to the exclusive jurisdiction of the courts of Athens, Greece. These provisions are without prejudice to any rights of data subjects under GDPR.
Annex A — Technical and organisational security measures
We implement the following technical and organisational measures to protect personal data, in line with GDPR Art. 32:
- Encryption in transit: all communication between your browser and our service uses HTTPS (TLS 1.2+).
- Encryption at rest: personal data at rest is encrypted by our sub-processors using industry standards (AES-256 or equivalent).
- Access control: least-privilege access internally; access to production data is limited to named personnel; passwords never reach our infrastructure (sign-in via Google OAuth).
- Row-Level Security: our database enforces per-user row-level security so even our own application code can only see rows owned by the authenticated user.
- Network isolation: compute workers run on isolated machines; intermediate compute artefacts are deleted from worker disks after final results are uploaded.
- Backups: Postgres-level backups managed by Supabase, encrypted and EU-resident.
- Logging and monitoring: server access logs rotated within 30 days; security events monitored.
- Vulnerability management: dependencies updated regularly; security advisories reviewed and actioned.
- Incident response: personal data breaches notified to you within 48 hours of awareness.
Annex B — Sub-processors
See Privacy Policy § 5 for the current list of sub-processors. Updates to that list count as updates to this Annex.
Contact
Privacy / DPA questions: [email protected]