• Home
  • Data Processing Agreement

Data Processing Agreement

Last updated: July 29, 2026

Summary : This Data Processing Agreement (DPA) specifies the terms under which Netcube, Inc., as processor, processes personal data on behalf of our customers (controllers) in compliance with Art. 28 GDPR. A signed, comprehensive DPA including annexes is available upon request.

  • 1. Parties, Scope and Purpose

    This DPA applies to the processing of personal data by Netcube, Inc., #608, 204 Gasan digital 1-ro, Geumcheon-gu, Seoul, Republic of Korea ("Processor"), on behalf of the customer ("Controller") through the npass.io service. It is concluded pursuant to Art. 28 GDPR and supplements our Terms of Service.

    EU Representative of the Processor (Art. 27 GDPR) : OBSECOM GmbH, Königstr. 40, 70173 Stuttgart, Germany — Email: netcube@obsecom.eu.

  • 2. Subject Matter and Duration

    Subject matter : processing of personal data including user identities, device information, authentication logs, network access requests, and audit trail data.

    Duration : effective for the duration of the service contract. Upon termination, personal data is handled per Section 9.

  • 3. Data Categories and Data Subjects

    Personal data : identification data (name, email, username); device information (device ID, MAC address, device name, OS type); network data (IP addresses, access logs); authentication data (login timestamps, session information); usage data (API calls, feature usage, configuration changes); audit trail data (security events, policy violations).

    Data subjects : end users, employees, and contractors of the Controller's organization; administrators and IT personnel.

  • 4. Obligations of the Processor

    4.1 Instructions. The Processor processes personal data only on documented instructions from the Controller; providing the npass.io service per the Terms of Service constitutes the Controller's general instruction.

    4.2 Confidentiality. All persons authorized to process personal data are bound to confidentiality by contract or statute.

    4.3 Security. The Processor implements the technical and organizational measures in Section 6.

    4.4 Sub-processors. See Section 5.

  • 5. Processing Locations and Sub-processors

    5.1 Processing locations. All customer data in the npass.io service is hosted exclusively in the European Union (AWS Frankfurt, eu-central-1). The Processor's operations and support personnel in Seoul, Republic of Korea may access personal data remotely for service operation, maintenance, and support. This constitutes a transfer to the Republic of Korea based on the European Commission's adequacy decision of 17 December 2021 (Art. 45 GDPR). Access is role-based, logged, and limited to what is necessary.

    5.2 Sub-processors.

    Sub-processor Purpose Location Safeguard
    Amazon Web Services (AWS) Infrastructure hosting, storage, compute Frankfurt, Germany (eu-central-1) Data Processing Addendum
    Google Cloud (optional) Identity provider federation relay (only if the Controller enables SSO) European Union DPA / Standard Contractual Clauses

    Note : Lemon Squeezy LLC (Merchant of Record, United States) processes payment and billing data as an independent controller, not as a sub-processor under this DPA. It does not access end-user data processed in the Service. See our Privacy Policy, Section 5.

    5.3 Changes. The Processor will notify the Controller of intended additions or replacements of sub-processors at least 30 days in advance. The Controller may object on reasonable data protection grounds; the parties will seek a solution, failing which the Controller may terminate the affected service.

  • 6. Technical and Organizational Measures (TOMs)

    Technical : AES-256 encryption at rest; TLS 1.3 in transit; firewalls, DDoS protection, and intrusion detection; role-based access control and MFA; per-tenant data isolation at application and database level; automated daily backups with geographic redundancy within the EU; comprehensive audit logging.

    Organizational : data protection training and confidentiality agreements; least-privilege access policies; background checks for employees with data access; incident response and business continuity plans; regular security assessments; compliance monitoring. Current TOMs documentation is provided to customers on request.

  • 7. Data Subject Rights

    Taking into account the nature of processing, the Processor assists the Controller with appropriate technical and organizational measures in fulfilling data subject requests under Arts. 15–21 GDPR. If a data subject contacts the Processor directly, the Processor will forward the request to the Controller without undue delay and will not respond on the Controller's behalf unless instructed.

  • 8. Data Breach Notification

    The Processor notifies the Controller of a personal data breach without undue delay after becoming aware of it, providing: the nature of the breach; categories and approximate number of affected data subjects and records; likely consequences; measures taken or proposed; and a contact point. The Processor provides reasonable assistance with the Controller's notifications to supervisory authorities (Art. 33) and data subjects (Art. 34).

  • 9. Return or Deletion of Data

    Upon termination, the Processor will, at the Controller's choice, return or securely delete all personal data processed under this DPA, unless statutory retention applies. The Controller may exercise this choice within 30 days of termination; thereafter, data is securely deleted no later than 90 days after termination, including from backups per backup rotation. Deletion is confirmed in writing on request.

  • 10. Audit Rights

    The Controller may verify the Processor's compliance by reviewing TOMs and processing documentation, requesting available audit reports and certifications, and — with at least 30 days' notice and under confidentiality — conducting audits directly or through an independent auditor. Audits must not unreasonably disrupt operations.

  • 11. International Transfers

    Transfers outside the EEA occur only as follows: (a) remote access from the Republic of Korea under the EU adequacy decision (Section 5.1); (b) to sub-processors under the safeguards listed in Section 5.2; (c) otherwise only on the Controller's documented instructions with appropriate safeguards under Chapter V GDPR.

  • 12. Full DPA

    This page summarizes key provisions. To receive the comprehensive, signable DPA with annexes (description of processing, TOMs, sub-processor list), contact dpo@netcube.com.

  • 13. Changes to This DPA

    The Processor may update this DPA to reflect changes in processing, security measures, or legal requirements, with at least 30 days' notice to the Controller. If a change materially reduces the level of protection, the Controller may object; the parties will seek a solution, failing which the Controller may terminate the affected service. Sub-processor changes follow Section 5.3.

  • 14. Governing Law

    This DPA is governed by the laws of Germany and the GDPR. Jurisdiction follows the Terms of Service.

    Contact for DPA inquiries: Data Protection Officer, Netcube, Inc. — dpo@netcube.com