Data Processing Agreement

Last updated: July 30, 2026

This Data Processing Agreement (“DPA”) applies between STA.SH Jakub Wilk, the operator of Elumre (the “Processor”, “we”), and the customer using Elumre (the “Customer”) whenever the Customer’s use of Elumre involves processing personal data protected by the GDPR on the Customer’s behalf — typically the data of the Customer’s own clients contained in estimates, proposals and proposal activity (“Customer Content”).

This DPA forms part of the agreement under which we provide Elumre to the Customer — normally our Terms of Service — and applies automatically; no signature is needed. If your procurement process requires a countersigned copy, email hello@elumre.com and we will provide one.

Roles

For Customer Content, the Customer is the controller and we act as the Customer’s processor under Article 28 GDPR. Where the Customer itself acts as a processor for its own client, we act as a subprocessor, and the obligations in this DPA apply accordingly.

This DPA does not cover data for which we are an independent controller — account, team, billing and usage data as described in our Privacy Policy.

Details of processing

Subject matterProvision of Elumre, an estimation and proposal service
DurationFor as long as the Customer uses Elumre, plus the deletion window below
Nature and purposeStoring, hosting, displaying and transmitting Customer Content — estimates, proposals, comments and attachments; sending proposal emails; reporting proposal engagement to the Customer
Data subjectsThe Customer’s clients, prospects and business contacts; other persons whose data the Customer includes in Customer Content
Personal dataNames, email addresses, business contact details, project details, comments and commenter display names, proposal engagement events, personal data contained in uploaded files
Special categoriesNone. The Customer agrees not to submit special-category data (Article 9 GDPR) through Elumre

Our obligations as processor

  1. Instructions. We process Customer Content only on the Customer’s documented instructions — given through the features of the service, this DPA and reasonable written instructions consistent with them — including with regard to international transfers, unless EU or Member State law requires otherwise. We will inform the Customer if, in our view, an instruction infringes data protection law.

  2. Confidentiality. Persons authorized to process Customer Content are committed to confidentiality.

  3. Security (Article 32). We maintain appropriate technical and organizational measures, including: encryption in transit (TLS) everywhere; passwords stored only as salted hashes; per-team isolation enforced at the database layer (row-level security); access rules enforced on the server for every request; hosting in EU data centers; production access limited to what operating the service requires; backups. We may improve these measures over time and will not materially lower the level of protection.

  4. Subprocessors. The Customer gives general authorization to the subprocessors listed below. We will give at least 30 days’ notice (by email or in the app) before adding or replacing a subprocessor; the Customer may object on reasonable data-protection grounds, and if we cannot offer a workaround, the Customer may terminate the use of Elumre. We impose data-protection obligations on subprocessors equivalent to this DPA and remain liable for their performance.

  5. Data subject requests. Taking into account the nature of the processing, we assist the Customer with appropriate technical and organizational measures in fulfilling data subject requests (Articles 12–23 GDPR). If a data subject contacts us directly about Customer Content, we forward the request to the Customer without undue delay.

  6. Assistance (Articles 32–36). We provide reasonable assistance with the Customer’s security, breach-notification, data-protection-impact-assessment and prior-consultation obligations, taking into account the information available to us.

  7. Personal data breaches. We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and provide the information reasonably available to us as it emerges.

  8. Deletion and return. During the term, the Customer can export Customer Content through the service and its API. Upon deletion of content, a team, or termination, we delete Customer Content within 30 days, and residual copies expire from backups within a further 30 days, unless EU or Member State law requires further retention.

  9. Information and audits. We make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits. Audit requests are normally satisfied in writing (documentation and descriptions of measures); on-site audits are limited to once per 12 months, on 30 days’ notice, at the Customer’s expense, and must not give access to other customers’ data.

Subprocessors

SubprocessorRoleLocation and transfer safeguard
Hetzner Online GmbHCloud infrastructure — application servers, database, file storageGermany / Finland (EU)
Cloudflare, Inc.Content delivery and network security for our websites and servicesGlobal edge network; EU–US DPF and SCCs
Resend, Inc.Delivery of transactional email, including proposal and invitation emailsUS; SCCs
PostHog, Inc.Usage analytics (may incidentally process Customer Content displayed in the product)Data stored in the EU; EU–US DPF and SCCs

Providers that process data only for our own controller purposes (for example Google sign-in or Polar billing) are not subprocessors of Customer Content; they are listed in the Privacy Policy.

International transfers

Customer Content is hosted in the EU. Where a subprocessor processes personal data outside the European Economic Area, the transfer is protected by European Commission adequacy decisions — including the EU–US Data Privacy Framework for certified providers — and/or Standard Contractual Clauses.

Liability and precedence

Liability under this DPA follows the agreement governing the use of Elumre. If this DPA conflicts with any other term regarding the processing of personal data, this DPA prevails.

Term and governing law

This DPA applies for as long as we process Customer Content and survives termination until deletion is complete. It is governed by the law governing the agreement under which we provide Elumre; absent such a choice, by Polish law.

Contact

Questions, objections to subprocessor changes, and requests for a countersigned copy: hello@elumre.com.