Data Processing Agreement (DPA)
Last updated: April 2026
This Data Processing Agreement ('DPA') is entered into between athcode ('Amendly', processor) and any organisation using the Amendly platform ('the Client', controller). It supplements the Terms of Service and applies to all processing of personal data carried out by Amendly on behalf of the Client, in accordance with Article 28 GDPR (Regulation EU 2016/679).
1. Subject matter and duration
Amendly agrees to process personal data provided or generated by the Client solely for the purpose of providing the Amendly service (collaborative amendment management). This DPA takes effect on the date of acceptance of the Terms of Service and remains in force for the duration of the service agreement.
2. Nature and purpose of processing
Amendly processes the Client's data for the following purposes: storing and displaying documents, amendments, comments, and activity logs; sending transactional notifications to members and contributors; authenticating members (magic link, Google OAuth); enforcing security rules and rate limits.
3. Categories of data and data subjects
Data subjects: members of the Client's organisation (email, name, job title, company); external contributors (optional name and email); invitees (email, invitation status). Data categories: identification data (name, email); professional data (company, job title); content data (document and amendment text); traceability data (timestamps, IP addresses, activity logs).
4. Obligations of Amendly
Amendly agrees to: process data only on documented instructions from the Client; maintain data confidentiality (TLS encryption, restricted access); not use the data for its own commercial purposes; only engage sub-processors listed in Article 6; notify the Client within 72 hours of becoming aware of a data breach; cooperate in responding to data subject rights requests.
5. Article 9 data and allocation of responsibilities
Amendly is built to collect amendments to political, statutory and trade union texts. A proposal signed with a name can reveal political opinions, philosophical beliefs or trade union membership. That data falls under Article 9 GDPR, and Amendly processes it on the Client's behalf in full knowledge of that fact. Measures applied by Amendly. Data is hosted within the European Economic Area, with Hetzner Online GmbH, in its Helsinki data centre (Finland). Traffic between the browser and the platform is encrypted in transit (TLS). Access to production systems is limited to the people at athcode who need it, through named SSH keys; no third party has access. An organisation's documents and amendments are visible only to the members it has invited. Authentication tokens are stored as hashes. Public endpoints are protected by rate limiting and bot detection. Backups are Hetzner Cloud snapshots kept in the same region. The public contribution link carries an expiry date and can be revoked by the Client at any time. Any personal data breach is notified to the Client within 72 hours (Article 7). Sub-processors in contact with this data. Hetzner Online GmbH hosts all content. Cloudflare Inc. relays traffic and runs bot detection: content passes through its servers without being retained there. Amazon Web Services delivers notification emails through Amazon SES in its Ireland region, so email delivery stays within the European Union; these emails carry the contributor's name, the document title and the section concerned, but not the text of the amendment. Transfers to Cloudflare, and the fact that Amazon Web Services has a parent company established in the United States, are covered by the EU standard contractual clauses. Stripe Inc. (payments) and Google LLC (OAuth authentication) receive no content data. Retention. Amendments and contributor data are deleted at the same time as the document they are attached to, with no delay. A contributor can delete their own contribution using the personal link issued when they submit it. A contributor's IP address is used for bot detection and rate limiting; it is not stored with the contribution and leaves the technical server logs after 30 days at the latest. At the end of the contract, Client data is deleted within 30 days (Article 8). What remains with the Client. The Client determines the purposes and the legal basis of the processing, including which Article 9(2) exception it relies on: explicit consent (point a) where the contribution link is open beyond its own members, or point (d) where processing is confined to its members and regular contacts. The Client informs data subjects at the point of collection, in particular through the notice displayed on the contribution form. The Client answers requests to exercise data subject rights; Amendly assists and provides the means to rectify and to delete. The Client assesses whether a data protection impact assessment is required (Article 35) and carries it out where it is. The Client sets the retention period by deleting its documents. The Client will not use Amendly to collect health data, data concerning sex life or sexual orientation, or genetic or biometric data: the platform is not designed for those categories and no specific measure covers them.
6. Authorised sub-processors
Hetzner Online GmbH (Helsinki, Finland) — hosting. Stripe Inc. (United States) — payments; EU SCCs in place. Amazon Web Services (Ireland) — transactional email via Amazon SES; parent company in the United States, EU SCCs in place. Cloudflare Inc. (United States) — anti-bot protection (Turnstile); EU SCCs in place. Google LLC (United States) — OAuth authentication; EU SCCs in place. Any addition or replacement of a sub-processor will be notified to the Client with 14 days' notice.
7. Data breach notification
In the event of a personal data breach affecting the Client's data, Amendly will notify the Client by email (to the organisation owner's address) within 72 hours of becoming aware of the incident. The notification will include: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address it.
8. Fate of data at end of contract
Upon expiry or termination of the service contract, Amendly will delete the Client's data within 30 days, unless required by law to retain it. On request made before that deadline to [email protected], Amendly can provide an export of documents and amendments in DOCX or JSON format.
9. Audit rights
The Client may, upon written request to [email protected] with 30 days' notice, request information on Amendly's security and compliance measures. Amendly will respond within a reasonable timeframe. If a more extensive audit is required, it shall be conducted by an independent third party at the Client's expense and must not disrupt Amendly's operations.
Contact
For any questions regarding this DPA or to report a breach, email [email protected].