lathe

Data Processing Agreement

This DPA forms part of the Terms of Service between you ("Controller") and Your Company Ltd. ("Processor") and applies where you process personal data subject to the GDPR or UK GDPR in your instance.

1. Subject matter and duration

The Processor provides managed PostgreSQL hosting. Processing lasts for the term of the service plus the 7-day snapshot retention after deletion.

2. Nature and purpose

Storage, backup and availability of data the Controller writes to its database. The Processor does not determine the purposes of the data and does not access it except as described in section 7 of the Terms.

3. Categories of data and data subjects

Determined solely by the Controller. The Controller confirms it does not store special-category data without appropriate measures of its own (encryption at the application layer).

4. Processor obligations

  • Process personal data only on the Controller's documented instructions, which are the use of the service through the console and API.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures in section 6.
  • Assist the Controller with data-subject requests to the extent the service allows (you have full SQL access to your data).
  • Notify the Controller without undue delay, and within 72 hours, of a personal-data breach affecting its instance.
  • Delete all personal data on termination, subject to the 7-day snapshot retention, unless law requires retention.
  • Make available information necessary to demonstrate compliance and allow audits on reasonable notice, at the Controller's cost.

5. Subprocessors

The Controller authorises the following subprocessors. Changes are announced by email 30 days in advance; the Controller may object by terminating the service.

SubprocessorPurposeLocation
Hetzner Online GmbHVirtual machines, block storage, backupsGermany (Falkenstein) / Finland
Resend, Inc.Transactional email (sign-in links, notifications)USA (email metadata only)
HYP / Max (Israeli payment gateway and acquirer)Card payments; the Processor never sees card numbersIsrael

6. Security measures

  • One dedicated virtual machine per Controller; no shared database processes between customers.
  • TLS required for every database connection; SCRAM-SHA-256 password authentication; optional IP allowlist.
  • No shell or superuser access for customers; administrative access to machines limited to the Processor's control plane over SSH with key authentication from a single fixed address.
  • Daily disk-image backups retained 7 days; snapshot before every destructive action; monthly automated restore tests.
  • Weekly security patching; delete protection on every machine; audit log of every administrative action.

7. International transfers

Data at rest stays in the EU. The Processor's staff may administer the service from Israel, which benefits from an EU adequacy decision.

8. Liability

Liability under this DPA is subject to the limitations in the Terms of Service.

Contact for privacy matters: support@lathe.computer. Last updated 2026-09-02.

Are you sure?