This Data Processing Addendum ("DPA") forms an integral part of the Cloud Services Agreement ("Agreement") between Digipa S.R.L. (VAT No. / P.IVA 10745180967, registered office at Piazza Giuseppe Grandi 7, 20129 Milano, Italy), hereinafter referred to as "Processor," and the Customer identified in the Agreement or the applicable order form, hereinafter referred to as "Customer" or "Controller."
1. Scope and Definitions
This DPA applies whenever Processor processes Personal Data on behalf of Controller through the DroneDB Hub platform ("Hub"). Where this DPA and the Agreement are inconsistent, this DPA prevails with respect to the processing of Personal Data.
The following terms have the meanings set out below:
- "Applicable Data Protection Law" means Regulation (EU) 2016/679 ("GDPR"), applicable Italian data-protection law (Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018), and, to the extent applicable to the relevant processing, the UK GDPR, Data Protection Act 2018, and other binding data-protection laws identified in the Order Form or the Agreement.
- "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
- "Personal Data" means any information relating to an identified or identifiable natural person as defined in Article 4 of the GDPR.
- "Personal Data Breach" means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Personal Data.
- "Processor" means Digipa S.R.L., as the entity processing Personal Data on behalf of and under the instructions of the Controller.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
- "Special Category Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identifying a person, health data, or data concerning a person's sex life or sexual orientation, as defined in Article 9 of the GDPR.
- "Supervisory Authority" means the Garante per la protezione dei dati personali (Italian Data Protection Authority) in Italy and, where applicable, the Information Commissioner's Office (ICO) in the United Kingdom.
- "Subprocessor" means any third party engaged by Processor to process Personal Data on behalf of Controller under the terms of this DPA.
2. Subject Matter, Duration, Nature, and Purpose
The subject matter of this DPA is the processing of Personal Data by Processor on behalf of Controller for the provision of DroneDB Hub services, including but not limited to geospatial data storage, processing, visualization, analysis, and collaboration.
The processing shall continue for the duration of the Agreement and any renewal thereof, and until the completion of deletion or return of all Personal Data as specified in Section 12 of this DPA following termination or expiration of the Agreement.
The nature of the processing involves receiving, storing, organizing, and making available Controller's data through the Hub platform, including running geospatial computations, generating derivative products, and facilitating data sharing among authorized users.
The purpose of the processing is the provision and operation of DroneDB Hub services as described in the Cloud Services Agreement, including billing, customer support, platform maintenance, and service improvement.
3. Categories of Data and Data Subjects
The categories of Personal Data processed by Processor on behalf of Controller include those described in the service offering and may include, but are not limited to:
- Identification and contact data: Names, email addresses, telephone numbers, and contact details of authorized users and collaborators.
- Geospatial metadata: Metadata embedded in uploaded datasets (e.g., EXIF data, GPS coordinates) that may relate to identifiable individuals.
- Content data: Any Personal Data contained within datasets, images, orthophotos, point clouds, vector files, or other materials uploaded by Controller to the Hub.
The categories of Data Subjects include, where applicable:
- Employees, contractors, or representatives of the Controller's organization.
- Individuals who may appear in or be referenced by aerial imagery, geospatial data, or related content uploaded by Controller.
- Third parties named or identifiable through data shared via the Hub.
The precise categories of data and data subjects shall depend on the data Controller chooses to upload and process through the Hub. Processor does not independently determine what Personal Data is uploaded.
4. Controller Instructions
Processor shall process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country, unless Processor is required to process Personal Data by Applicable Data Protection Law applicable to the Processor. If Processor submits to such law, it shall inform Controller of that legal requirement before processing, except where that law prohibits such information on important grounds of public interest.
In the event that Processor, in its opinion, considers that an instruction from Controller infringes Applicable Data Protection Law, Processor shall without undue delay inform Controller and shall not carry out the instruction until Controller has provided appropriate clarification or legal basis, to the extent permitted by applicable law.
Processor shall comply with Controller's documented instructions regarding data retention periods, deletion schedules, specific processing operations, and any data protection impact assessments agreed upon by the parties.
5. Confidentiality
Processor shall ensure that all persons authorized to process Personal Data under the instructions of Processor have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Confidentiality obligations shall remain in effect during the term of the Agreement and following its termination, for so long as the Personal Data remains non-public.
Processor implements access controls ensuring that only personnel who need access to Personal Data in order to perform their duties are granted such access, consistent with the principle of least privilege.
6. Technical and Organisational Measures
TOMs Schedule - Version 1.0, dated 2026-08-13
This schedule is incorporated by reference into the Data Processing Addendum. Processor may update these measures over time and will notify Controller of material changes that could affect the security of processing.
Update Log
| Version | Date | Summary of Changes |
|---|---|---|
| 1.0 | 2026-08-13 | Initial publication |
In accordance with Article 32 of the GDPR, Processor has implemented appropriate technical and organizational measures ("TOMs") designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purpose of processing, as well as the probability and severity of the risk to the rights and freedoms of natural persons.
The following measures are in place as of the date of this DPA:
Network Security
- Firewalls and network segmentation: The production environment is protected by network firewalls with rules limiting inbound and outbound traffic to what is necessary for service operation. Internal network segmentation isolates the application tier from the database and storage layers.
- TLS encryption for data in transit: All communications between client applications and the Hub are encrypted using TLS (Transport Layer Security). Data in transit between internal components and subprocessors is also encrypted where supported.
Access Controls
- Role-based access control: Access to Hub systems is governed by role-based access controls ensuring that users can only access data and functions appropriate to their role and authorization level.
- Principle of least privilege: Administrator and operator access to infrastructure and application systems is granted on a need-to-know basis and follows the principle of least privilege.
- Multi-factor authentication: Multi-factor authentication (MFA) is planned for administrative accounts and privileged access to infrastructure but is not yet implemented.
Infrastructure Security
- Data center location: The Hub production infrastructure is hosted at Hetzner Cloud data centers in Germany (Falkenstein, Nuremberg) under EU jurisdiction. Both DroneDB Hub (hub.dronedb.app) and the DroneDB website (dronedb.app) are hosted in Falkenstein, Germany. Processor takes reasonable measures to ensure that data is not stored or processed in jurisdictions outside the EU/EEA without appropriate transfer mechanisms in place.
- Physical access controls: The hosting provider maintains physical security controls, including restricted physical access to data center facilities, surveillance, and environmental monitoring.
- Monitoring and logging: System activity and access to critical infrastructure components are monitored and logged. Logs are reviewed as part of routine security operations and incident investigation.
Data Encryption - Current Status
Processor is transparent about the current state of data encryption:
- Encryption in transit: All data transmitted between the client and the Hub is encrypted using TLS.
- Encryption at rest: Processor acknowledges that, as of the date of this DPA, data stored on the production server is not currently encrypted at rest. Processor is treating this as a priority improvement item and is actively working to implement encryption at rest for stored data. Processor will update this DPA or notify Controller when encryption at rest has been deployed.
- Backups: Processor performs daily incremental backups of production data using BorgBackup software with client-side encryption (repokey mode: AES-256-CTR for encryption, HMAC-SHA256 for authentication). Encryption keys are derived from a passphrase stored securely and access is restricted to authorized personnel. Backup data is encrypted before transmission to and while at rest in storage.
Backup and Recovery
- Daily incremental backups: Production data is backed up on a daily incremental basis using Borg backup, providing efficient deduplication and versioned recovery points.
- Tested restore procedures: Backup restoration is periodically tested to verify data recoverability.
- Backup retention: Daily incremental backups are retained for a minimum of 30 days. Backup retention periods and rotation schedules are documented and available to Controller upon request. Residual backup copies of deleted content are not accessible for regular processing purposes and age out within the documented retention period.
Incident Response
- Incident detection and response procedures: Processor maintains procedures for the detection, assessment, and containment of security incidents. The incident response process includes identification, containment, eradication, recovery, and post-incident review.
- Notifications: Security incidents affecting Controller's Personal Data are addressed in accordance with Section 10 of this DPA.
Vulnerability Management
- Processor keeps system software, operating systems, and application components reasonably updated with available security patches and updates.
- Processor addresses identified vulnerabilities on a priority basis according to their severity and the risk they pose to the confidentiality, integrity, and availability of Personal Data.
Processor reviews and, where necessary, updates these measures regularly to account for changes in technology, processing activities, and the evolving threat landscape.
Technical and Organisational Measures — Control Status Table (Version 1.0, August 2026)
The following table provides a structured overview of current Technical and Organisational Measures and their implementation status:
| Control Category | Control Description | Status | Phase for Resolution |
|---|---|---|---|
| Network Security | TLS encryption for data in transit | Implemented | — |
| Data Encryption | At-rest encryption for stored data | Not implemented | Phase 3 |
| Access Controls | MFA for administrative accounts | Planned | Phase 2 |
| Network Security | IDS/IPS deployment | Not deployed | Phase 3 |
| Vulnerability Management | Third-party penetration testing | Not performed | Phase 4 |
| Backup Security | Backup data encryption (BorgBackup AES-256-CTR / HMAC-SHA256) | Implemented | — |
| Backup and Recovery | Point-in-time recovery capability | Not confirmed | Phase 3 |
| Infrastructure | Redundant infrastructure across regions | To be verified | Phase 3 |
| Organisational | Personnel background checks | To be verified | Phase 4 |
Statuses marked "To be verified" indicate measures where Processor has not yet completed formal verification. Phase references correspond to DroneDB's internal security improvement roadmap: Phase 2 (Days 7–30: legal foundations), Phase 3 (Days 30–90: security infrastructure), Phase 4 (Days 90–180: assurance and governance).
7. Special Category Data
Unless expressly authorized by Controller in writing in the order form or a separate agreement, and unless Processor has documented that the service supports such processing with appropriate safeguards:
- Controller shall not upload, store, or process through the Hub Special Category Data as defined in Article 9 of the GDPR, criminal-conviction and offense data as defined in Article 10 of the GDPR, or other categories of particularly sensitive Personal Data.
- If Controller requires the processing of such data through the Hub, Controller shall inform Processor in advance, and the parties shall agree upon additional technical and organizational measures as necessary before such processing commences.
If Controller becomes aware that Special Category Data or criminal-conviction data has been inadvertently processed through the Hub, Controller shall notify Processor without undue delay, and the parties shall cooperate to address the situation in accordance with Applicable Data Protection Law.
8. Subprocessors
Processor may engage one or more Subprocessors to perform certain processing activities on behalf of Processor. Any such engagement is subject to the following conditions:
Authorization
Processor engages Subprocessors with the prior specific or general written authorization of Controller. Where general written authorization has been granted, Controller may object to any new Subprocessor designated by Processor by providing Processor with notice of such objection. Processor shall not designate the new Subprocessor if Controller objects.
Subprocessor Obligations
Processor ensures that each Subprocessor is bound by written data processing terms that are no less protective than those set out in this DPA, including appropriate technical and organizational measures. Processor remains fully liable to Controller for the performance of each Subprocessor's obligations under this DPA.
List of Subprocessors
The current list of Subprocessors, including the processing activities they perform and the jurisdiction in which processing occurs, is as follows:
- Hetzner Cloud (Hetzner Online GmbH, Germany) - Infrastructure hosting: compute, storage, networking, physical data center security (data centers in Falkenstein and Nuremberg, Germany). Hetzner DPA: https://www.hetzner.com/AV/DPA_en.pdf
- Amazon SES (Amazon Web Services, Inc., USA) - Email delivery service for transactional and service-related emails. Personal data transferred to Amazon SES is protected by the EU Standard Contractual Clauses (SCCs). AWS DPA: https://docs.aws.amazon.com/whitepapers/latest/navigating-gdpr-compliance/aws-data-processing-addendum-dpa.html
- Stripe (Stripe Payments Europe, Limited, Ireland and Stripe, Inc., USA) - Payment processing for subscription payments and billing. Stripe acts as a data processor for payment transactions and as an independent controller for fraud prevention and fraud-related analytics. Transfers to Stripe's US operations (where applicable) are protected by the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Stripe DPA: https://stripe.com/legal/dpa
- PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg) - Payment processing for subscription payments and billing. PayPal acts as a data processor for payment transactions and as an independent controller for fraud prevention and compliance-related activities. PayPal DPA: https://www.paypal.com/us/legalhub/paypal/data-protection
The list may also be provided upon request to Controller at support@dronedb.app. An up-to-date public list of subprocessors is available at https://dronedb.app/subprocessors
Changes to Subprocessors
Processor shall provide Controller with at least 30 days' prior notice of any intended changes concerning the addition or replacement of Subprocessors, such as new services to be added, changes in the nature of processing, or the addition of additional Subprocessors. Controller shall have the right to object to such changes. If Controller objects, Controller may terminate the data processing services at the end of the notice period without penalty, or the parties may negotiate alternative arrangements.
9. Assistance with Data Subject Rights
Processor shall assist Controller, by appropriate technical and organizational measures, to fulfill Controller's obligation to respond to requests for exercising data subjects' rights under Articles 12 through 22 of the GDPR, to the extent that such assistance is within Processor's reasonable technical capability and feasible given the architecture of the Hub.
This assistance may include, where applicable and technically feasible:
- Providing access to Personal Data held in machine-readable format.
- Facilitating the correction of inaccurate Personal Data.
- Supporting the deletion or restriction of processing of Personal Data.
- Assisting with data portability requests where data is provided by the data subject or concerning the data subject and is processed by automated means.
Processor shall notify Controller without undue delay upon receiving any direct request from a data subject regarding their Personal Data. Processor shall forward such requests to Controller and shall not respond directly unless authorized by Controller or required by law.
Where a request is technically infeasible or would disproportionately impact other data subjects' rights, Processor shall inform Controller of the limitations and cooperate in finding alternative means of compliance.
Processor shall respond to Controller's requests for assistance with data subject rights within 5 business days of receipt, excluding time needed for requests that are manifestly unfounded or excessive.
10. Security Incidents
Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of Controller, or any other event that may have implications for the security of Personal Data held by or with Processor.
Notification Timeline
Where possible, Processor shall provide initial notification of a Personal Data Breach to Controller within 24 hours of confirmation that the breach has occurred and may affect Controller's Personal Data. Initial notification shall contain available information regarding the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences, and the measures taken or proposed to address the breach.
Supplemental Information
Processor shall communicate further details of the Personal Data Breach as they become available, including assessments of the likely consequences of the breach and measures taken or proposed to be taken to address it, including measures to mitigate its possible adverse effects.
Cooperation
Processor and Controller shall cooperate in good faith to investigate and contain any Personal Data Breach. Processor shall provide reasonable assistance to Controller to enable Controller to meet its notification and communication obligations under Applicable Data Protection Law. Without prejudice to Controller's rights under applicable law, Controller shall have the right to require Processor to take reasonable steps to mitigate the effects of a Personal Data Breach.
11. Data Protection Impact Assessment Assistance
Upon Controller's request, Processor shall provide reasonable and documented assistance to Controller in conducting Data Protection Impact Assessments ("DPIA") as required by Article 35 of the GDPR, to the extent such information is within Processor's possession and feasible to provide.
This assistance may include:
- Providing information about the processing activities performed by Processor, including the nature, purpose, and categories of Personal Data processed, as well as the technical and organizational measures implemented.
- Describing the risks to the rights and freedoms of data subjects arising from the processing.
- Outlining the measures envisaged to address the identified risks.
The scope of DPIA assistance shall be mutually agreed upon by the parties, taking into account the complexity of the requested assessment, the time required to compile the information, and any proprietary or security-sensitive aspects of Processor's infrastructure.
12. Deletion or Return of Data
At the end of the provision of services relating to the processing of Personal Data, and at Controller's choice, Processor shall delete or return all Personal Data to Controller and delete existing copies, unless Applicable Data Protection Law requires storage of the Personal Data.
Deletion Process
Upon termination or expiration of the Agreement, or upon Controller's written request for deletion:
- Processor shall observe the 30-day retrieval period described in the Agreement's Data Lifecycle section, after which Processor shall delete Personal Data from active production systems in accordance with the agreed deletion schedule.
- Controller may request return of data in a commonly used, machine-readable format prior to deletion.
- Processor shall provide written confirmation of deletion upon request within 10 business days of completion of the deletion process.
Backup Retention
Controller acknowledges that Personal Data may exist in Processor's backup systems beyond the completion of the deletion from active systems. Backup copies shall be deleted in accordance with Processor's backup retention and rotation schedule. Processor shall ensure that any Personal Data retained in backups is not accessible or usable for processing purposes other than disaster recovery, and shall be permanently deleted when the backup containing such data is rotated or expires.
Legal Retention
If Processor is required by Applicable Data Protection Law or other applicable law to retain certain Personal Data, such data shall be retained only to the extent required and shall not be processed for any other purpose. Processor shall inform Controller of any such legal retention obligations.
13. Compliance and Audit
Compliance Evidence
Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA, including, but not limited to, Processor's output-based audit results or certifications, if available.
Audit Rights
Processor shall allow for and contribute to audits, including inspections, conducted by Controller or by an independent auditor mandated by Controller, to verify Processor's compliance with the obligations under this DPA.
Audit Conditions
- Audits shall be conducted at least annually, if requested by Controller.
- Audits shall be performed in a manner that does not unreasonably interfere with Processor's normal business operations and shall be subject to reasonable advance notice.
- Audits may include review of documentation, systems, and processes relevant to the processing of Controller's Personal Data.
- Audits shall not grant access to Personal Data of other customers of Processor, or to Processor's proprietary systems, intellectual property, or trade secrets, unless such access is explicitly agreed upon by the parties and subject to appropriate confidentiality protections.
- Where an independent auditor is used, such auditor shall be bound by a confidentiality obligation and shall have the necessary expertise in data protection.
Costs
Where audits are routine compliance audits (i.e., not triggered by a suspected material breach), the costs of the audit shall be borne by Controller, unless the audit identifies a material breach by Processor or its Subprocessors, in which case the costs shall be borne by Processor.
Record of Processing Activities
Processor maintains a Record of Processing Activities (ROPA) in accordance with GDPR Article 30(1)(b). This record is available to Controller upon reasonable request and will be updated when processing activities change materially.
14. Data Act Switching and Portability Assistance
Processor shall provide reasonable assistance to Controller to switch to another data-processing service or to Controller's own infrastructure, in accordance with Regulation (EU) 2023/2854 (Data Act).
Switching Assistance
When Controller exercises its right to switch to another provider, Processor shall:
- Cooperate in good faith to meet the timeframes described in the Agreement's Data Portability section.
- Provide a minimum of 30 calendar days' transitional period during which Controller may operate both the DroneDB Hub platform and the switched-to provider concurrently.
- Provide reasonable technical assistance during the transition period to facilitate data transfer.
Data Export for Switching
In addition to the original file export described in the Agreement, Processor shall make available:
- Self-service export of original uploaded files in their original format.
- Export of metadata, dataset structure, organization membership, permissions, annotations, and measurements in commonly used formats (e.g., GeoJSON, STAC JSON, CSV).
- API documentation and manifests necessary for programmatic transfer of data.
- Checksums or integrity verification files where applicable.
Prior Consultation Assistance
Upon Controller's request, and where Controller concludes that a processing operation is likely to result in a high risk in accordance with Article 36 of the GDPR, Processor shall provide reasonable and documented assistance to Controller in engaging in prior consultation with the Supervisory Authority.
Switching Charges
In accordance with Article 29 of the EU Data Act (Regulation (EU) 2022/868), from 11 January 2024 until 12 January 2027 we may apply only reduced switching charges strictly limited to the direct costs of the switching process. From 12 January 2027, Processor will not impose any switching charges on Controller for switching to another provider or to its own infrastructure.
15. International Data Transfers
Where the processing of Personal Data involves a transfer outside the European Union or the European Economic Area:
- Processor shall ensure that such transfer is carried out in accordance with Applicable Data Protection Law and the provisions of Chapter V of the GDPR.
- Where required, Processor shall implement appropriate transfer mechanisms, including but not limited to the European Commission's Standard Contractual Clauses ("SCCs"), supplemented by a transfer impact assessment where necessary to ensure an adequate level of protection.
- Processor shall inform Controller of any international transfers of Personal Data and the safeguards in place.
- Controller shall have the right to require Processor to use contractual clauses approved by the European Commission for transfers of Personal Data to third countries.
Processor maintains its production infrastructure at Hetzner Cloud data centers in Germany and takes reasonable measures to avoid unintended transfers of Personal Data to jurisdictions outside the EU/EEA. Where subprocessors operate outside the EU/EEA, appropriate transfer mechanisms shall be in place as described in Section 8.
16. Form and Binding Nature
This DPA constitutes a binding agreement in writing, including by electronic means, between Controller and Processor as required by Article 28(9) of the GDPR. This DPA may be executed and governed electronically.
Electronic signatures, digital records, and acceptance through the Hub platform shall constitute sufficient evidence of the agreement of both parties to the terms of this DPA.
Contact Information
Processor: Digipa S.R.L.
Piazza Giuseppe Grandi 7, 20129 Milano, Italy
CF / P.IVA: 10745180967
Email: support@dronedb.app
Website: dronedb.app
For data protection inquiries, please contact: support@dronedb.app
This document is a Data Processing Addendum for purposes of Article 28 of the GDPR. It is intended for B2B customers of DroneDB Hub who act as Controllers with respect to Personal Data processed through the platform. If you are unsure whether this document applies to your use of DroneDB Hub, please contact us for clarification.