Data Processing Addendum
Effective 3 October 2026. Related: Terms · Master Services Agreement · Data Processing Addendum · SLA · Privacy
This Data Processing Addendum (“DPA”) forms part of the Master Services Agreement (“Agreement”) between NETCETERA OÜ (registry code 16768111), Sepapaja tn 6, 15551 Tallinn, Estonia (“Processor”) and the Customer (“Controller”). It applies when NETCETERA OÜ processes personal data on the Customer's behalf in providing DRSite, and meets Article 28 of the EU General Data Protection Regulation (“GDPR”) and, where they apply, the UK GDPR and Swiss data protection law. It takes effect with the Agreement; a signed copy is available from privacy@drsite.app.
1. Definitions
Customer Personal Data means personal data in Customer Data (as defined in the Agreement) that NETCETERA OÜ processes on the Customer's behalf. Sub-processor means a third party NETCETERA OÜ engages to process Customer Personal Data. Security Incident means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data. Other terms such as controller, processor, personal data and processing have the meanings in the GDPR.
2. Scope and roles
The Customer is the controller (or a processor acting for its own customers) and NETCETERA OÜ is the processor (or sub-processor) of Customer Personal Data. NETCETERA OÜ is a separate controller for account, billing and usage data, as described in its Privacy policy. The details of the processing are in Annex 1. This DPA lasts as long as NETCETERA OÜ processes Customer Personal Data.
3. Instructions
NETCETERA OÜ processes Customer Personal Data only on the Customer's documented instructions: the Agreement, the Customer's settings and use of DRSite (for example which sites to back up, how often, where standby copies live and when to fail over), and other written instructions we agree. If the law requires other processing, we will tell the Customer first unless the law forbids it. We will tell the Customer if we believe an instruction breaks data protection law.
4. Confidentiality and security
NETCETERA OÜ ensures that people authorised to process Customer Personal Data are bound to confidentiality, and applies the technical and organisational measures in Annex 2, which we may update provided the overall level of protection is not reduced.
5. Security incidents
NETCETERA OÜ will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a Security Incident, with the information available then and more as it becomes known, and will take reasonable steps to contain it and help the Customer meet its own notification duties. Notifying an incident is not an admission of fault.
6. Sub-processors
The Customer authorises the Sub-processors listed in Annex 3. NETCETERA OÜ imposes data protection terms on each that are no less protective than this DPA and stays responsible for them. We will give at least 30 days' notice of a new Sub-processor by email or in DRSite. The Customer may object on reasonable data protection grounds within that time; if we cannot reasonably accommodate the objection, the Customer may end the affected Services and receive a pro rata refund of prepaid fees.
7. Assistance
Taking into account the nature of the processing, NETCETERA OÜ will help the Customer, by appropriate measures and as far as possible, to answer requests from data subjects, and with security, impact assessments and consultations with authorities. If a data subject contacts us directly about Customer Personal Data, we will refer them to the Customer. Help beyond the normal features of DRSite may be charged at reasonable cost.
8. International transfers
Customer Personal Data may be processed in the countries listed in Annex 3. Where this involves a transfer from the EEA, UK or Switzerland to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller to processor) or Module 3 (processor to processor), which are incorporated by reference with: the optional docking clause 7 included; clause 9 option 2 (general authorisation, with the notice in clause 6 above); the optional language in clause 11 omitted; clauses 17 and 18 governed by Estonian law and the courts of Estonia; and Annexes I to III completed by Annexes 1 to 3 of this DPA. For UK transfers, the UK International Data Transfer Addendum applies; for Swiss transfers, the clauses are read with references to the Swiss law and authority. Transfers to US recipients certified under the EU-US Data Privacy Framework may rely on it instead.
9. AI processing
NETCETERA OÜ does not use Customer Personal Data to train AI models. Instasite sends to its AI provider only what the Customer submits to it (a brief, a site name, the public text of a website and brand details the Customer chooses to use), solely to produce the requested output. DRSite does not use AI for decisions about data subjects.
10. Audits
NETCETERA OÜ will make available the information needed to show compliance with this DPA, including answers to reasonable security questionnaires and summaries of relevant reports. If that is not enough, or an authority requires it, the Customer may audit NETCETERA OÜ's compliance once a year, with at least 30 days' notice, during business hours, by an independent auditor bound to confidentiality, at the Customer's cost and without access to other customers' data.
11. Return and deletion
The Customer can download or restore its backups at any time during the Agreement and for 30 days after it ends. After that, NETCETERA OÜ deletes Customer Personal Data, including standby copies, within a further 60 days, except where the law requires us to keep it. Copies in routine backups are deleted as those backups expire and stay protected by this DPA until then.
12. General
Liability under this DPA is subject to the limits in the Agreement, except where the law does not allow them. If this DPA conflicts with the Agreement, this DPA applies to the processing of Customer Personal Data; if the Standard Contractual Clauses apply, they prevail over both. This DPA is governed by the laws of Estonia.
Annex 1: Details of the processing
Subject matter and purpose: providing DRSite: backing up, storing, monitoring and restoring the Customer's websites, keeping standby copies, failing over and back, and related support.
Nature: collection (by backup), storage, copying, transmission, restoration, deletion; automated checks of the public website.
Categories of data subjects: the Customer's Authorized Users, and the people whose data is in the websites the Customer protects, such as its website visitors, customers, subscribers, mailbox users and staff.
Categories of personal data: whatever the Customer's websites, databases and mailboxes contain, typically names, contact details, account details, order history, messages and email content, and technical data such as IP addresses in logs. The Customer decides what its websites contain; special category data is not needed for DRSite and should only be included where the Customer has a lawful basis for it.
Frequency and duration: continuous, on the plan's backup schedule, for the term of the Agreement and the deletion period in clause 11.
Annex 2: Security measures
- Encryption in transit (TLS, FTPS) between the Customer's servers, DRSite and storage.
- Plesk backups on DRSite storage protected with a per-site backup password; storage keys limited to each account's or site's own folder.
- Separate storage folder and FTP login per site, so one customer cannot reach another's backups.
- Access to production systems limited to authorised staff, with individual accounts and multi-factor sign-in where supported.
- Secrets such as API keys, backup passwords and connection credentials never shown back in the interface or written to logs.
- Monitoring of the service from independent locations in the UK, EU and US, and logged administrative actions per site.
- Standby restores that keep the previous copy until a new one has succeeded.
- Vulnerability fixes applied promptly; providers chosen for their own security programmes.
- Deletion of Customer Data on request or at the end of the Agreement as in clause 11.
Annex 3: Sub-processors
| Sub-processor | Processing | Location |
|---|---|---|
| Convex, Inc. | Database for site settings, logs and backup records | EU (Ireland) |
| IDrive Inc. (IDrive e2) | Backup storage | UK (London) |
| Backblaze, Inc. (B2) | Off-site and long-term backup storage (DRSite Cold Vault) | US or EU, by the region set for the account |
| Cloudflare, Inc. | DNS changes for failover, load balancing, page rendering, instasite.app pages | Global |
| Vercel, Inc. | Control panel hosting | Global |
| Clerk, Inc. | Sign-in for Authorized Users | US |
| Resend, Inc. | Alert and account emails | US |
| OpenRouter, Inc. and the AI model provider it routes to (Anthropic) | Instasite briefs and page designs, only for content the Customer submits to Instasite | US |
| PostHog Inc. (EU cloud) | Product analytics on the control panel (account ID, pages used, errors; no cookies) | EU |
| Netcetera group servers (NETCETERA OÜ and affiliates) | Standby copies, DRSite FTP backup storage, uptime monitoring, support chat | UK, EU and US |
Stripe processes payment data as an independent controller and is not a Sub-processor of Customer Personal Data. Contact for this DPA: privacy@drsite.app.