Skip to content
Draft — not yet in force. Adetio is in closed pre-launch. The operating entity is not yet published, so this document names no company and creates no obligations. It is shown in full so you can read the terms we intend to launch under; every clause is confirmed with EU counsel before release.
LEGAL

Data Processing Agreement

This DPA applies when you process end users’ personal data through Adetio. You are the controller; the Adetio operating entity (to be published before launch) is your processor under Article 28 GDPR. It is incorporated into our Terms of Service.

Draft · operating entity to be published before launch

1. Roles & scope

You determine the purposes and means of processing (controller); Adetio processes personal data only to provide the platform on your documented instructions (processor). Subject matter is identity and authentication; data subjects are your end users; categories include identifiers, credentials, and authentication metadata.

2. Processing instructions

We process personal data only on your documented instructions, including this DPA and your configuration, unless EU or member-state law requires otherwise — in which case we will inform you first, where legally permitted.

3. Confidentiality & security

Personnel with access to personal data are bound by confidentiality. We implement the technical and organisational measures set out in our Security page, appropriate to the risk under Article 32 GDPR, including encryption, access control, and resilience.

4. Subprocessors

You authorise the subprocessors listed on our Subprocessors page, all located in the EU. We impose equivalent data-protection obligations on each, remain liable for their performance, and give at least 30 days’ notice of changes so you may object.

5. International transfers

We do not transfer personal data outside the EU/EEA. Should that ever change, we will rely on an adequacy decision or EU Standard Contractual Clauses and notify you in advance.

6. Data subject requests & breaches

We assist you in responding to data-subject requests and, taking account of the nature of processing, in meeting your security and impact-assessment obligations. We notify you without undue delay — and within 72 hours where feasible — of any personal-data breach affecting your data.

7. Return, deletion & audits

On termination, we return or delete personal data at your choice within 90 days, save where retention is legally required. We make available the information needed to demonstrate compliance and allow for audits, including inspections, on reasonable notice.