Skip to content
Kodvalley

Legal

Data processing agreement

Article 28 GDPR terms when we process data for customers.

Last updated: 3 October 2026

This Data Processing Agreement ("DPA") applies whenever MB Kodvalley ("Processor") processes personal data on behalf of a customer ("Controller") while providing services, for example hosting, managed servers, software maintenance, support or security assessments. It implements Article 28 of the GDPR and forms part of the contract between the parties. A signed copy is available on request at legal@kodvalley.com.

1. Subject matter and duration

The Processor processes personal data only to provide the services agreed in the contract, for the duration of the contract and any agreed retention period afterwards.

2. Nature, purpose and data

The nature and purpose of processing are hosting, storage, maintenance, support, testing and other operations needed to provide the services. Categories of data subjects and personal data depend on the customer's systems and typically include the customer's employees, customers and users, with contact data, account data, usage data and any content stored by the customer. Special categories of data are processed only if the customer stores them in its systems and has informed the Processor.

3. Instructions

The Processor processes personal data only on documented instructions from the Controller, including the contract, this DPA and instructions given through the client portal or in writing. If the Processor believes an instruction infringes data protection law, it informs the Controller immediately.

4. Confidentiality

All persons authorised to process personal data are bound by confidentiality obligations.

5. Security measures (Article 32 GDPR)

  • encryption of data in transit and, where appropriate, at rest;
  • access control based on least privilege, individual accounts and multi-factor authentication;
  • logging and monitoring of administrative access;
  • regular backups and tested restoration procedures for managed services;
  • timely security updates and vulnerability management;
  • physically secured data centres operated by certified infrastructure providers;
  • regular review and testing of the effectiveness of these measures.

6. Sub-processors

The Controller grants general authorisation to engage sub-processors. The main sub-processor for infrastructure services is OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France, with data centres in the European Union. The current list of sub-processors is available on request. The Processor informs the Controller at least 30 days before adding or replacing a sub-processor; the Controller may object on reasonable data protection grounds. The Processor imposes the same data protection obligations on each sub-processor and remains liable for their performance.

7. International transfers

Personal data is processed within the European Economic Area. Transfers to third countries take place only on the Controller's instructions and with appropriate safeguards under Chapter V of the GDPR.

8. Assistance

The Processor assists the Controller with appropriate technical and organisational measures in responding to data subject requests, and with security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing.

9. Personal data breaches

The Processor notifies the Controller without undue delay, and in any case within 48 hours after becoming aware of a personal data breach affecting the Controller's data, with the information available at that time, and provides further information as it becomes available.

10. Deletion and return

At the end of the services, the Processor deletes or returns all personal data at the Controller's choice and deletes existing copies, unless law requires storage. Backups are overwritten in their regular cycle.

11. Audits

The Processor makes available all information necessary to demonstrate compliance with this DPA and allows audits, including inspections, by the Controller or an auditor mandated by it, with reasonable prior notice, during business hours and subject to confidentiality. Audits may first be addressed through documentation and certifications.

12. Liability and precedence

Liability is governed by Article 82 GDPR and the contract. In case of conflict between this DPA and other contract documents regarding data protection, this DPA prevails.

Questions about this document?

MB Kodvalley · Laisvės pr. 60-1107, Vilnius, Lithuania

legal@kodvalley.com