Skip to content

Data Processing Agreement (DPA)

This page explains how data processing agreement topics are handled for DevOpsCentral services.

Where a signed customer-specific DPA is required, that signed DPA controls for the covered service.

1. When a DPA Is Relevant

A DPA is relevant when a customer uses DevOpsCentral services to host, store, transmit, or otherwise process personal data in customer-controlled workloads and DevOps Central acts as a hosting provider and, where applicable, a processor for that workload data.

For general account, billing, and relationship-management data, see the Privacy Policy.

2. Roles of the Parties

2.1 Customer Role

For customer workload data, the customer is generally the controller and decides:

  • what personal data is processed
  • why it is processed
  • how long it is retained
  • which users or systems can access it

DevOps Central does not decide the business purpose of customer-controlled workload processing.

2.2 DevOps Central Role

DevOps Central acts as a hosting provider and, where applicable, a processor only to the extent necessary to:

  • provide the underlying infrastructure or agreed managed service
  • maintain platform security and reliability
  • perform support or troubleshooting
  • carry out customer-requested operational actions
  • comply with applicable legal obligations

3. Scope of Processing

The exact subject matter, duration, categories of personal data, and categories of data subjects depend on the customer's own workloads and the selected service model.

In a customer-specific DPA, those details are defined by reference to the relevant services, order documents, and operational scope.

4. Customer Instructions

DevOps Central processes customer workload data only on the customer's documented instructions, except where processing is required by applicable law.

Documented instructions may come from:

  • the selected service configuration
  • support tickets or authenticated operational requests
  • written project scope documents
  • separate written agreements

5. Security and Confidentiality

DevOps Central applies reasonable technical and organizational measures appropriate to the service context, including platform-level security controls, access management, and operational safeguards.

Personnel with access to relevant systems must handle non-public information confidentially.

Because service models differ, customer-side security responsibilities remain important, especially in Self-Managed environments.

6. Supporting Providers and Workload Processing

For DevOps Central's own customer relationship, billing, and administrative processing, DevOps Central uses:

  • PayU GPO for payment processing
  • Brevo for email delivery
  • Keez.ro for accounting-related processing

Customer workload data processed through DevOpsCentral infrastructure is hosted and operated in DevOps Central's own data center in Romania, unless a separate written agreement states otherwise.

If a customer-specific service scope introduces additional subprocessors for workload processing, those subprocessors are disclosed in the relevant agreement or service documentation.

7. International Transfers

DevOps Central does not transfer customer personal data outside the European Economic Area as part of the service setup described on this page.

If a service scope requires an international transfer, the relevant legal mechanism and contractual handling will be documented before that transfer is used.

8. Assistance with Rights Requests

Taking into account the nature of the processing and the information available to it, DevOps Central will provide reasonable assistance for customer-handled requests relating to access, rectification, deletion, restriction, portability, or objection where required by law and where applicable to the agreed service scope.

9. Incident and Breach Handling

If DevOps Central becomes aware of a personal data breach affecting customer workload data within its processor role, DevOps Central will provide notice without undue delay, taking into account the service context and legal obligations.

The customer remains responsible for assessing its own controller-side notification obligations unless a separate written agreement assigns additional responsibility to DevOps Central.

10. Return and Deletion

Return, export, retention, and deletion of customer workload data depend on:

  • the selected service model
  • the technical capabilities of the service
  • customer-managed deletion actions
  • any separate written agreement
  • legal retention or security obligations where applicable

For Self-Managed services, customers must manage their own workload exports and deletions inside their environment unless a separate agreement states otherwise.

11. Audit and Information Requests

Where a customer-specific DPA includes audit rights, security questionnaires, or compliance evidence, those requests are handled in a way that is reasonable, proportionate, and protective of other customers and of platform security.

Specific audit procedures are defined in the applicable agreement.

13. Contact

For privacy, GDPR, or DPA-related questions, contact privacy@devopscentral.eu.