GDPR & Data Processing Agreement (DPA)
Last update: 28-01-2025
This agreement outlines how YottaSrc processes personal data on behalf of its clients, ensuring full compliance with the EU General Data Protection Regulation (GDPR).
1. PARTIES TO THE AGREEMENT
This Data Processing Agreement ("DPA") is entered into between:
-
Client (Data Controller):
Any customer of YottaSrc using its services for processing personal data -
Processor (Service Provider):
YottaSrc Inc., a limited liability company registered in Saudi Arabia & Romania
Company Registration No.: 2511130857
Registered Office: Cluj-Napoca, 400454, Romania
Website: https://yottasrc.com
Email: [email protected]
2. SUBJECT MATTER AND DURATION
This DPA governs the processing of personal data by YottaSrc on behalf of the Client as necessary to provide hosting, licensing, and related services. It remains valid as long as the Client continues to use YottaSrc services.
3. NATURE AND PURPOSE OF PROCESSING
YottaSrc processes personal data for the following purposes:
-
Providing web hosting, cloud servers, VPS/VDS, RDP, and licensing services
-
Managing accounts, subscriptions, and billing
-
Offering support and resolving technical issues
-
Ensuring platform security and service optimization
4. TYPES OF PERSONAL DATA
YottaSrc may process the following personal data:
-
Full name
-
Email address
-
IP address
-
Billing address and payment method (excluding card numbers)
-
Login and usage logs
-
Support ticket content
-
Telephone number (if provided)
5. CATEGORIES OF DATA SUBJECTS
The personal data processed typically relates to:
-
Clients of YottaSrc (natural persons or client contacts)
-
End users authorized by the client
6. OBLIGATIONS OF YOTTASRC (DATA PROCESSOR)
YottaSrc agrees to:
-
Process data only on documented instructions from the Client
-
Maintain strict confidentiality of data
-
Implement technical and organizational measures to protect data (e.g., SSL, firewalls, access controls)
-
Assist in responding to data subject requests (access, deletion, correction)
-
Notify the Client without undue delay in case of a data breach
-
Keep records of processing activities
-
Cooperate with supervisory authorities upon lawful request
7. SUB-PROCESSORS
YottaSrc may use the following sub-processors:
-
cPanel, LLC (hosting control panel, USA)
-
Cloudflare, Inc. (CDN & DNS, USA)
-
Stripe Payments Europe, Ltd. (payment processing, Ireland)
-
PayPal (Europe) (payment processing, Luxembourg)
8. INTERNATIONAL TRANSFERS
If personal data is transferred outside the European Economic Area (EEA), YottaSrc ensures appropriate safeguards, such as:
-
Standard Contractual Clauses (SCCs) adopted by the European Commission
-
Data processing agreements with third parties
-
Hosting data in GDPR-compliant data centers (primarily within the EEA)
9. DATA RETENTION AND DELETION
Upon termination of the service:
-
All stored personal data will be securely deleted within 12 months of service termination, unless retention is required for legal, compliance, or legitimate business purposes.
-
Backups are deleted within 90 days from service cancellation.
10. AUDITS AND INSPECTIONS
YottaSrc will:
-
Provide relevant information to demonstrate compliance with Article 28 of the GDPR
-
Allow for audits and inspections upon reasonable notice, provided they do not interfere with normal operations
11. LIABILITY AND GOVERNING LAW
This Agreement is governed by the laws of Romania and subject to the exclusive jurisdiction of the Brașov Tribunal.
12. CONTACT INFORMATION
For GDPR inquiries, contact:
Email: [email protected]
Mail: YottaSrc Inc. Cluj-Napoca, Romania
Website: https://yottasrc.com/privacy-policy