Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the agreement between you (the "Customer") and Dredo, a service operated by ELAREN GROUP SL ("Dredo", "we", "us"), and governs how Dredo processes personal data on the Customer's behalf under the Terms of Service. It reflects Article 28 of the EU General Data Protection Regulation (GDPR). Where this DPA refers to the processing of personal data provided through Dredo by the Customer's end-users, the Customer acts as the controller and Dredo acts as the processor.
1. Parties and scope
This DPA is entered into between the Customer, as the party that creates and controls one or more workspaces in Dredo, and Dredo (ELAREN GROUP SL), registered address Calle Unión 7, 45100 Sonseca, Toledo, Spain, VAT/NIF ESB75779777, as the provider of the Service.
For the personal data that the Customer's end-users and requesters provide through Dredo (for example when they open a support ticket), the Customer is the controller and Dredo is the processor acting on the Customer's behalf. This DPA does not cover the account, staff-user and billing data for which Dredo is itself the controller; that processing is described in our Privacy Policy.
This DPA is part of, and incorporated into, the Terms of Service. It applies for as long as Dredo processes personal data on the Customer's behalf.
2. Definitions
Terms used in this DPA have the meanings given in the GDPR. In particular:
- GDPR: Regulation (EU) 2016/679 and any national law that implements or supplements it.
- Personal data: any information relating to an identified or identifiable natural person that Dredo processes on the Customer's behalf under this DPA.
- Processing: any operation performed on personal data, such as collection, storage, use, disclosure or deletion.
- Controller: the party that determines the purposes and means of the processing (here, the Customer).
- Processor: the party that processes personal data on behalf of the controller (here, Dredo).
- Data subject: the individual to whom the personal data relates.
- Subprocessor: a third party engaged by Dredo to process personal data on the Customer's behalf.
- Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
3. Subject-matter, duration, nature and purpose
The subject-matter of the processing is the operation of the Dredo help desk service for the Customer. The nature and purpose of the processing is to receive, store, organise and display support requests and related content so that the Customer can provide customer support to its end-users, together with related features such as ticketing, notifications, reporting and satisfaction surveys.
The duration of the processing is the term of the Customer's subscription, plus any period afterwards during which data is returned or deleted under section 11.
The types of personal data processed on the Customer's behalf include:
- requester email addresses (which may be anonymous);
- ticket subject lines, public messages, internal notes and status;
- attachments uploaded to tickets;
- custom-field values defined by the Customer;
- the immutable ticket event log (timeline);
- customer satisfaction (CSAT) ratings and comments.
The categories of data subjects are the Customer's end-users and requesters who contact the Customer for support, and the Customer's own staff users who work inside the workspace.
4. Processor obligations
Dredo will process personal data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law. The Customer's instructions are set out in this DPA, in the Terms of Service, and through the Customer's use and configuration of the Service. If Dredo believes an instruction infringes the GDPR, it will inform the Customer.
Dredo will ensure that the personnel authorised to process personal data are bound by an appropriate duty of confidentiality.
Dredo will implement the technical and organisational security measures described in section 5, and will assist the Customer, taking into account the nature of the processing and the information available, in meeting its obligations under Articles 32 to 36 of the GDPR (security, breach notification, and data protection impact assessments).
5. Security measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Dredo implements appropriate technical and organisational measures under Article 32 of the GDPR, including:
- Per-workspace isolation: each workspace is a separate tenant, and queries are scoped so that a workspace cannot access another workspace's data;
- Hashed credentials: passwords and invitation tokens are stored hashed, not in plain text;
- Encryption in transit: connections to the Service are protected with TLS;
- Role-based access control: staff access inside a workspace is limited by role and permission scope;
- Logging with secrets redacted: application logs redact secrets and are not used for third-party analytics;
- EU hosting: the Service, its database and file storage are hosted in the European Union (Germany), with our infrastructure provider Hetzner.
Dredo may update these measures over time, provided the level of protection is not reduced.
6. Subprocessors
The Customer gives Dredo general authorisation to engage subprocessors to help provide the Service. Dredo imposes on each subprocessor data-protection obligations that are, in substance, equivalent to those in this DPA, and remains responsible to the Customer for the subprocessor's performance.
The current subprocessors are:
- Hetzner Online GmbH (Germany, EU): hosting and infrastructure, including servers, database and file storage;
- Stripe: payment processing and VAT/VIES validation;
- Resend: transactional and notification email delivery;
- Sentry: error monitoring and diagnostics.
Dredo will give the Customer prior notice of any intended addition or replacement of a subprocessor, so that the Customer has the opportunity to object on reasonable data-protection grounds. If the Customer objects and the concern cannot be resolved, the Customer may cease using the affected feature or terminate the affected part of the Service as its remedy.
7. Assistance with data-subject rights
Taking into account the nature of the processing, Dredo will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects to exercise their rights under the GDPR (such as access, rectification, erasure, restriction, portability and objection).
If Dredo receives a request directly from a data subject relating to personal data processed on the Customer's behalf, Dredo will not respond to it directly (except to confirm that the Customer is responsible) and will, where lawful, refer the request to the Customer or forward it without undue delay.
8. Personal data breach
Dredo will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf. The notification will include, to the extent then available, a description of the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
Dredo will provide reasonable assistance to help the Customer meet any obligation it may have to notify a supervisory authority or affected data subjects. Because the Customer is the controller, the Customer is responsible for deciding whether and how to make any such notification.
9. International transfers
The Service, its database and file storage are hosted in the European Union (Germany), with our infrastructure provider Hetzner. Some subprocessors, in particular Stripe, Resend and Sentry, are established in the United States and may process personal data there.
Where a transfer of personal data to a country outside the European Economic Area takes place, it is carried out on the basis of an appropriate transfer mechanism under the GDPR, in particular the European Commission's Standard Contractual Clauses, together with any additional safeguards required.
10. Audits and information
Dredo will make available to the Customer the information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
To respect the confidentiality and security of the multi-tenant Service and of other customers, audits will be conducted on reasonable prior notice, no more than once a year (except where required by a supervisory authority or following a personal data breach), during business hours, and in a way that does not disrupt Dredo's operations. Where available, Dredo may satisfy an audit request by providing existing documentation or reports.
11. Return or deletion of data
At the choice of the Customer, Dredo will return or delete the personal data processed on the Customer's behalf after the end of the provision of the Service, and will delete existing copies, unless EU or Member State law requires the data to be retained.
In practice, after a subscription ends the Customer is given a reasonable window to export its Customer Content before the data is deleted, as described in the Terms of Service. Backups are overwritten or deleted on their ordinary cycle, and data required by law to be kept is retained only for as long as, and to the extent that, the law requires.
12. Liability and precedence
In respect of the processing of personal data on the Customer's behalf, this DPA prevails over any conflicting provision of the Terms of Service. On all other matters, the Terms of Service continue to apply.
The overall and aggregate liability of each party arising out of or relating to this DPA is subject to, and counts towards, the limitations and exclusions of liability set out in the Terms of Service, to the extent permitted by law.
13. Governing law and language
This DPA is governed by the laws of Spain, consistent with the Terms of Service, and any dispute is subject to the same jurisdiction as set out there.
This DPA is provided in English and Spanish. In case of any discrepancy or conflict between the two versions, the Spanish version prevails.
14. Requesting a signed copy
Business customers can request a countersigned copy of this DPA by writing to us at hello@dredo.app. Please include your workspace name and billing details so we can match the request to your account.