This Data Processing Agreement (the “DPA”) is part of the Terms of Service (the “Agreement”) between Rouhee Group Ltd, Business ID 2684686-4, Finland (“Processor”, “BehindGate”) and the Customer (“Controller”). It applies whenever BehindGate processes personal data on the Customer’s behalf in providing the Service. It is accepted together with the Agreement and applies to every plan. No separate signature is required. Where the Customer needs a countersigned copy for its records, it may request one from legal@behindgate.com.

Capitalised terms not defined here have the meaning given in the Agreement. “GDPR” means Regulation (EU) 2016/679. “Personal Data”, “processing”, “data subject”, “personal data breach”, and “supervisory authority” have the meaning given in the GDPR.

1. Roles and scope

1.1 The Customer is the controller of the Personal Data described in Annex 1 and BehindGate is the processor. Where the Customer acts as a processor for its own clients, BehindGate is a sub-processor and the Customer warrants that its instructions are authorised by the relevant controller.

1.2 This DPA applies to Personal Data that BehindGate processes on the Customer’s behalf: Viewer data, including the Customer’s viewer authentication configuration and the data processed when a Viewer signs in, the content of Apps to the extent it contains Personal Data, and related logs. It does not apply to data that BehindGate processes as a controller, such as account holder and billing data, which is covered by the Privacy Policy.

2. Instructions

2.1 BehindGate processes Personal Data only on the documented instructions of the Customer. The Agreement, this DPA, and the Customer’s configuration of the Service in the dashboard and API are the complete instructions. Additional instructions must be agreed in writing and may be subject to a fee if they require work beyond the Service.

2.2 BehindGate will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law, unless it is prohibited from doing so.

2.3 BehindGate may process Personal Data where required by Union or Member State law, and will inform the Customer of that requirement before processing, unless the law prohibits it.

3. Customer obligations

The Customer is responsible for: (a) the lawfulness of the Personal Data and of the instructions it gives; (b) providing Viewers and other data subjects with the information required by Articles 13 and 14 GDPR; (c) choosing the viewer authentication method for each site and configuring it correctly, meaning the access rules in its identity provider or the allowed email domains and allowed email addresses for email one-time codes; and (d) not publishing special categories of Personal Data under Article 9 GDPR unless agreed in writing.

4. Confidentiality

BehindGate ensures that every person authorised to process Personal Data is bound by a contractual or statutory duty of confidentiality, and that access is limited to those who need it to provide, secure, and support the Service.

5. Security

5.1 BehindGate implements and maintains the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.

5.2 BehindGate may update the measures from time to time provided that the updates do not materially reduce the overall level of security.

6. Sub-processors

6.1 The Customer gives general authorisation for BehindGate to engage the sub-processors listed in the Sub-processor List.

6.2 BehindGate will notify the Customer by email to the account administrators at least 30 days before adding or replacing a sub-processor. The Customer may object in writing within that period on reasonable data protection grounds. If the parties cannot resolve the objection within 30 days, the Customer may terminate the Agreement by written notice and BehindGate will refund prepaid fees for the period after termination. That is the Customer’s sole remedy for an objection.

6.3 BehindGate imposes on every sub-processor data protection obligations substantially equivalent to those in this DPA, and remains liable to the Customer for the sub-processor’s performance.

7. Data subject rights

7.1 Taking into account the nature of the processing, BehindGate assists the Customer with appropriate technical and organisational measures in responding to requests from data subjects under Chapter III GDPR. The dashboard and API give the Customer direct access to most of the data needed.

7.2 If a data subject contacts BehindGate directly about Personal Data processed for the Customer, BehindGate will refer the request to the Customer without undue delay and will not respond on the Customer’s behalf unless instructed.

8. Personal data breach

8.1 BehindGate will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Personal Data processed for the Customer.

8.2 The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available.

8.3 BehindGate will cooperate with the Customer and take reasonable steps to contain and remedy the breach. A notification is not an admission of fault or liability.

9. Assistance

Taking into account the nature of the processing and the information available to it, BehindGate will assist the Customer in ensuring compliance with Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation with a supervisory authority. Assistance beyond providing existing documentation may be charged at BehindGate’s then current rates.

10. Audit

10.1 BehindGate will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR. This includes this DPA, Annex 2, the Sub-processor List, security documentation published at behindgate.com/trust, responses to reasonable written security questionnaires no more than once per year, and, once available, summaries or reports of independent audits or certifications such as SOC 2 or ISO 27001.

10.2 Where the information in Section 10.1 is not sufficient to demonstrate compliance, or where a supervisory authority requires it, the Customer or an independent auditor bound by confidentiality and approved by BehindGate may audit BehindGate’s processing. Such an audit: (a) is limited to once per 12 months unless a personal data breach or a supervisory authority requires otherwise; (b) requires at least 30 days’ written notice; (c) takes place during business hours with minimal disruption; (d) does not extend to the systems of sub-processors, whose own audit reports are provided instead; and (e) is at the Customer’s expense, including BehindGate’s reasonable time.

11. International transfers

11.1 Personal Data is stored in the European Union (AWS region eu-west-1, Ireland). Certain components of the content delivery network, including edge locations and services that must be operated in the United States (AWS region us-east-1) for technical reasons, process request data in transit.

11.2 Transfers of Personal Data to a country outside the European Economic Area are made only under a valid transfer mechanism in Chapter V GDPR: an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or the Standard Contractual Clauses adopted by the European Commission, together with supplementary measures where required. BehindGate’s agreements with the sub-processors listed in the Sub-processor List include the Standard Contractual Clauses where that mechanism applies.

12. Deletion and return

12.1 The Customer may delete Personal Data at any time through the Service. On termination of the Agreement, BehindGate deletes all Personal Data within 30 days and from backups within 90 days, unless Union or Member State law requires longer storage.

12.2 The Customer is responsible for exporting Customer Content before termination. The Service provides export tools during the term.

13. Liability

The liability of each party under this DPA is subject to the exclusions and limitations in the Agreement. Nothing in this DPA limits the liability of a party towards data subjects or supervisory authorities where the GDPR does not allow it.

14. Term

This DPA applies for as long as BehindGate processes Personal Data on the Customer’s behalf and survives termination of the Agreement until deletion is complete.

15. Changes

BehindGate may update this DPA in accordance with the change procedure in the Agreement. Changes required by a change in the law or by a supervisory authority may take effect on shorter notice.

Annex 1. Details of processing

Subject matter. Hosting of the Customer’s static sites and applications and authentication of Viewers, as described in the Agreement. The Customer chooses the viewer authentication method for each site: a customer-managed identity provider, or email one-time codes (“email OTP”).

Duration. The term of the Agreement plus the deletion period in Section 12.

Nature and purpose. Storing, transmitting, and displaying Customer Content to authenticated Viewers; storing the Customer’s viewer authentication configuration, including any allowed email domains and allowed email addresses; authenticating Viewers against the Customer’s identity provider or, where the Customer has chosen email OTP, by verifying an email address the Customer’s configuration permits; maintaining authenticated sessions; logging access for security and audit. BehindGate does not receive or maintain a directory of the Customer’s Viewers under either method. With email OTP, eligibility is decided by the Customer’s allowed domains and allowed addresses, and the address a Viewer provides is processed to authenticate that Viewer and establish the resulting session.

Categories of data subjects. The Customer’s employees, contractors, and other people the Customer allows to view its Apps; the Customer’s administrators and members to the extent their actions are logged in tenant audit data.

Categories of Personal Data. Individual email addresses the Customer places on an allowlist; the email address a Viewer provides for email OTP authentication; identifiers and claims sent by the Customer’s identity provider, such as subject identifier, email address, name, and group membership; IP address, user agent, and timestamps; session identifiers; any Personal Data the Customer chooses to include in Customer Content.

Special categories. None, unless agreed in writing under Section 3.

Annex 2. Technical and organisational measures

Hosting and isolation. The Service runs on Amazon Web Services with data at rest in eu-west-1 (Ireland). Customer Content is stored in private storage that is never publicly accessible and is served only through the authenticated content edge. Tenants are logically separated at every layer of the Service.

Access control. Every request for Customer Content is verified at the edge before content is served; unverified requests are denied (fail closed). Viewer authentication is delegated to the Customer’s identity provider or, where the Customer has chosen it, performed with email OTP against the addresses and domains the Customer allows. Email addresses used for authentication are not written to logs. Staff access to production is limited to named individuals, protected by multi factor authentication, granted on the principle of least privilege, and logged. Staff do not view Customer Content in the ordinary course of operations.

Encryption. All data is encrypted in transit using TLS 1.2 or later and at rest using AWS managed encryption. Signing keys and identity provider secrets are stored in a managed secrets service, rotated, and never written to logs.

Separation of trust planes. Viewer authentication, customer administration, and internal operations run on separate systems with separate credentials and no shared tokens.

Logging and monitoring. Access, administrative actions, and security events are logged with timestamps and retained for the period stated in the Customer’s plan. Logs are monitored for anomalies and alerts are reviewed.

Availability and backup. Infrastructure is defined as code and deployed through reviewed, automated pipelines. Data stores use managed backups. Release history allows instant rollback of Customer Content.

Secure development. Changes are reviewed before deployment, dependencies are scanned for known vulnerabilities, and security reviews are performed against the OWASP guidance.

Incident response. BehindGate maintains a documented incident response process, including the customer notification described in Section 8. Vulnerability reports are accepted at security@behindgate.com.

Sub-processors. Sub-processors are assessed before engagement and bound by written data protection terms.

Deletion. Customer Content and Personal Data are deleted within the periods in Section 12 using the deletion facilities of the underlying cloud services.