Data Processing Agreement
Effective September 22, 2026
This DPA governs how Scribase processes the personal data you place inside your projects, as your processor under GDPR and UK GDPR. It sets out the processing details, our security measures, sub-processing and transfer safeguards, breach notification, audit rights, and how your data is returned and deleted — with export available at any time.
1. Introduction and roles
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer") and Scribase ("we", "us") for use of the Scribase application cloud (the "Service"), and governs our processing of personal data contained in your Customer Data. It supplements and, on the subject of personal-data processing, prevails over the Terms of Service at https://scribase.com/legal/terms.
For personal data that Customer submits to or generates within the Service ("Customer Personal Data"), Customer is the controller (or a processor acting for its own controllers) and Scribase is the processor (or sub-processor). Scribase processes Customer Personal Data only on Customer’s documented instructions, which include the Terms, this DPA, and Customer’s configuration and use of the Service.
Terms such as "controller", "processor", "processing", "personal data", "data subject", "personal data breach", and "supervisory authority" have the meanings given in applicable data-protection law, including the EU General Data Protection Regulation (GDPR) and the UK GDPR.
2. Details of the processing
The subject matter, nature, and purpose of the processing is the provision of the Service to Customer. The details required by Article 28(3) GDPR are:
- Subject matter: provision of a managed application cloud — Postgres database, authentication, storage, realtime, functions, preview branches, import, and the control API and CLI.
- Duration: for the term of the agreement, plus the limited period needed to return or delete data as described in this DPA.
- Nature and purpose: hosting, storing, transmitting, backing up, and processing Customer Personal Data as instructed to operate, secure, and support the Service.
- Types of personal data: determined by Customer — typically account and profile data of Customer’s end users, authentication identifiers, and any personal data Customer chooses to store in its database, storage objects, or functions.
- Categories of data subjects: determined by Customer — typically Customer’s end users, employees, and contacts.
3. Scribase obligations as processor
With respect to Customer Personal Data, Scribase will:
- Process it only on Customer’s documented instructions, including regarding international transfers, unless required to act otherwise by law — in which case we will inform Customer, unless the law prohibits it.
- Ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
- Implement and maintain the technical and organizational security measures described below.
- Respect the conditions in this DPA for engaging sub-processors.
- Assist Customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting Customer’s obligations for security, breach notification, data-protection impact assessments, and prior consultation.
- Make available information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits as described below.
If we form the opinion that an instruction infringes applicable data-protection law, we will inform Customer without undue delay.
4. Security measures
Scribase maintains technical and organizational measures appropriate to the risk, which reflect real properties of the platform:
- Encryption of Customer Personal Data in transit (TLS) and at rest, including backups.
- Access control enforced in Postgres through row-level security, with policies linted for cost so tenant isolation stays both correct and performant.
- A least-privilege operator model for the control plane that does not require cluster-admin inside Customer workloads.
- Preview environments scrubbed of production secrets and swept on a TTL so stale branches do not become credential leaks.
- Durable, idempotent operations that carry an operation ID, making changes safe to retry and traceable.
- Verified restore that ships row-count parity, SHA-256 checksums, policy parity, and a real login proof, so recovery is evidenced rather than assumed.
Our current security posture is described at https://scribase.com/security. We may update specific measures over time provided the overall level of protection is not materially reduced.
5. Sub-processors
Customer provides general authorization for Scribase to engage sub-processors to provide the Service, such as infrastructure and hosting providers. Where a sub-processor processes Customer Personal Data, Scribase will impose data-protection obligations on it that are no less protective than those in this DPA and remains responsible for its sub-processors’ performance.
We maintain a current list of sub-processors and offer a mechanism to subscribe to change notices. We will give reasonable advance notice of any intended addition or replacement of a sub-processor, and Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected part of the Service. The list is available on request at support@scribase.com.
6. International transfers
Where processing of Customer Personal Data involves a transfer that requires safeguards under the GDPR or UK GDPR, the parties agree that the European Commission’s Standard Contractual Clauses (module one or two, as applicable) and the UK International Data Transfer Addendum are incorporated into this DPA by reference and apply to such transfers, together with the technical and organizational measures described above. Where Customer selects a specific data region for a project, we will store the primary copy of that project’s Customer Personal Data in the selected region, subject to the transfers necessary to provide support and resilience.
7. Data-subject requests
Because Customer controls its own data model within the Service, Customer can access, correct, delete, export, and restrict Customer Personal Data directly using the console, control API, CLI, and export tooling. To the extent Customer cannot do so itself, Scribase will provide reasonable assistance to help Customer respond to data-subject requests. If we receive a request directly from a data subject relating to Customer Personal Data, we will refer them to Customer.
8. Personal data breach notification
Scribase will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to help Customer meet its own notification obligations, including the nature of the breach, likely consequences, and the measures taken or proposed to address it. Our notification is not an acknowledgment of fault or liability.
9. Audits and demonstrating compliance
Scribase will make available to Customer information reasonably necessary to demonstrate compliance with its obligations as a processor, including relevant documentation of security measures and, where available, third-party reports. Where that information is insufficient, Customer may request an audit no more than once per year (and following a personal data breach) on reasonable prior notice, conducted during business hours, subject to confidentiality, and in a manner that does not disrupt the Service or compromise other customers’ data.
10. Return and deletion of data
Portability is built into the Service: at any time during the term Customer can use scribase export to obtain a checksummed bundle of its database, storage, authentication configuration, and settings. On termination, and after a limited transition window during which Customer can export, Scribase will delete Customer Personal Data in the ordinary course, unless retention is required by law.
Residual copies may persist in encrypted backups for a limited period until they cycle out on their normal schedule, during which they remain protected by the measures in this DPA and are not restored to active use except to recover the Service.
11. Liability and general terms
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Terms of Service. This DPA does not create additional liability beyond what applicable data-protection law and the Terms provide.
If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. If there is a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail. This DPA remains in effect for as long as Scribase processes Customer Personal Data.
To enter into a signed copy of this DPA, to request the sub-processor list, or for any data-protection question, contact us at support@scribase.com.
Related documents