1. What a DPA is and why you need one
A Data Processing Agreement (DPA) is a contract between two roles:
- Controller — the party that decides what data to collect and why. For your website, the controller is you (or your company).
- Processor — the party that handles data on the controller's instructions. KVOKA acts as processor when we host your form, run Google Analytics on your domain, or manage your CRM inbox.
Under GDPR Article 28, the controller-processor relationship must be documented in a contract that meets a specific minimum bar. Without a DPA, the controller (you) is in breach of GDPR even if the processor (KVOKA) is doing everything correctly.
This page is that DPA. You can grab the PDF version at the bottom. Signing happens through e-signature (Telegram / WhatsApp / email confirmation) or by sending back a signed scan.
2. Scope (when this DPA applies)
This DPA applies automatically in any of these cases:
- KVOKA hosts your website on our Hostinger plan (e.g., after rebranding our landing-page domain to yours).
- KVOKA operates your lead-capture form (submissions flow through our email / Telegram bot).
- KVOKA runs Google Analytics on your domain from our GA account.
- KVOKA manages your CRM or inbox (e.g., replying to leads on your behalf).
- KVOKA has access to your client data as part of any other service (database migration, contact imports, etc.).
This DPA doesn't apply if:
- You filled out the form on kvoka.com as a prospective client (then KVOKA is the controller of your data, and the Privacy Policy applies).
- We built you a site and handed off complete ownership (domain, hosting in your name). In that case KVOKA has no operational data access, so no DPA needed.
3. Roles and responsibilities
3.1. Your responsibilities as controller
- Determine the lawful basis for processing (consent, contract, legitimate interest).
- Publish your own Privacy Policy and Cookie Policy on your site.
- Collect visitor consent (e.g., via a cookie banner).
- Handle data-subject requests (access, deletion, etc.) in the first instance.
- Notify the supervisory authority on a breach (we'll help on the technical side — see below).
3.2. Our responsibilities as processor
- Process data only on your documented instructions.
- Maintain confidentiality (NDAs with contractors, narrow access).
- Apply technical and organizational safeguards (see section 5).
- Not bring on new subprocessors without your general authorization and notification.
- Help you respond to data-subject requests within 5 business days.
- Delete or return data when the engagement ends.
- Provide information for audits and compliance documentation.
4. What data and whose data we process
4.1. Categories of data subjects
- Your site visitors — anyone who fills the form or shows up in analytics.
- Your customers — if you give us access to your CRM or inbox.
- Your staff — if they have admin access (we keep their logins and action logs).
4.2. Categories of data
- Name and contact info (phone, email, WhatsApp / Telegram).
- IP address, user agent, referrer.
- Form contents (service type, request description).
- Behavioral site data (page views, clicks) — anonymized via GA4.
4.3. What we do NOT process
By default KVOKA does not handle "special category data" under GDPR Art. 9:
- Racial or ethnic origin.
- Political opinions, religious beliefs.
- Biometric or genetic data.
- Health data or sexual orientation.
If your business needs to process any of that (a medical clinic, for example), we need a separate addendum to this DPA. Reach out to Maks.
5. Technical and organizational measures
Safeguards consistent with GDPR Art. 32 (state of the art, risks vs implementation cost):
5.1. Technical
- Encryption in transit — TLS 1.3 on every endpoint, HSTS preload.
- Encryption at rest — Hostinger disks are AES-256 encrypted.
- Backups — daily snapshot, 30-day retention, off-site copy weekly.
- Patching — critical OS / PHP / nginx patches applied within 7 days.
- WAF — Cloudflare WAF when protection is on.
- Rate limiting — on API endpoints and forms.
- Logging — all access events logged, 90-day retention.
5.2. Organizational
- Least privilege — only Maks has root access to the server.
- 2FA / MFA on every critical account (hosting, registrar, GitHub, Google).
- Contractor NDAs — every frontend / design contractor signs an NDA.
- Onboarding / offboarding — checklist for granting and revoking access.
- Incident response plan — kvoka.com/legal/security has the playbook.
More at Security Practices. Honest disclaimer: we don't have a SOC 2 audit (we don't pretend to be a big company). If SOC 2 is mission-critical for you, we're not the right fit — go with Squarespace Enterprise or a comparable shop.
6. Subprocessors
We use the following subprocessors to deliver the service. By signing this DPA you grant general authorization for these specific subprocessors. In return we:
- Notify you 14 days before adding a new subprocessor or replacing an existing one.
- Sign a contract with each subprocessor with data-protection terms at least as strict as those in this DPA.
- Stay accountable for the subprocessor's actions as if they were ours.
Current list:
- Hostinger International Ltd. (Lithuania, EU) — hosting, databases. Privacy + DPA available in their dashboard.
- Google LLC (US) — Google Analytics 4, Google Fonts. SCC + EU-US DPF certified.
- Telegram FZ-LLC (UAE) — bot API for lead delivery. Privacy.
- Meta Platforms Inc. (US) — WhatsApp Business for messaging. SCC + EU-US DPF.
- Cloudflare Inc. (US) — CDN, DDoS protection. Cloudflare DPA signed.
The live full list with regular updates lives at Subprocessors.
7. Cross-border data transfers
Several subprocessors sit outside the EU/EEA (mostly in the US). For transfers we rely on EU-recognized mechanisms:
- EU-US Data Privacy Framework — for Google and Meta (both self-certified).
- Standard Contractual Clauses (SCCs) 2021/914 — for everyone else, plus supplementary measures (post-Schrems II safeguards).
- UK IDTA and Swiss-US DPF — for those jurisdictions.
We re-run a Transfer Impact Assessment (TIA) every 12 months or whenever we add a new subprocessor. If you're an EU resident and want a copy of the TIA, just ask.
8. Breach notification
If despite our safeguards a personal-data breach occurs:
8.1. What we do
- Detect and contain the incident — automated monitoring usually catches anomalies within hours.
- Notify you without undue delay and in any case within 72 hours of detection (GDPR Art. 33(2)).
- Give you the following info: nature of the breach, categories and approximate number of affected subjects, likely consequences, measures taken.
- Help you communicate with the regulator and with affected data subjects on our side.
- Publish a post-mortem on Security Practices within 30 days.
8.2. What you do
- Decide whether to notify the regulator (GDPR Art. 33) and the data subjects (Art. 34) — usually yes, if there's a risk to subjects' rights.
- Submit the notification to the supervisory authority within 72 hours of becoming aware.
- Coordinate with us on messaging (we'll supply all the technical detail you need).
9. Audit rights
Under GDPR Art. 28(3)(h) you have the right to verify how the processor performs. Our setup:
- Once every 12 months — free remote audit. You send a security questionnaire (SIG / CAIQ / DDQ), we complete it within 10 business days.
- Zoom call with Maks for follow-up — free.
- Onsite audit — possible at the Hostinger facility in Kaunas, Lithuania, but at your cost (including our hourly rate for time spent).
- Third-party auditor — fine if you have a compliance program (HIPAA, etc.). NDA required.
- Between audits we share subprocessor SOC 2 reports on request, under NDA.
Unscheduled audits — only on suspicion of a breach or DPA violation. Standard 14 business days' notice.
10. Helping with data-subject requests
When a visitor sends you a request for access / deletion / correction / portability of their data:
- Forward the request to us within 3 business days via WhatsApp / Telegram / email.
- We'll handle the technical work (find, export, delete) within 5 business days.
- We'll help you draft the response to the subject if needed.
- Cost — included in your plan for a reasonable volume (up to 10 requests / month). Beyond that, we'll talk separately.
A request template lives at Data Deletion Request.
11. End of engagement and data fate
When our engagement ends for any reason (project complete, termination, you switch providers), we:
- Stop active processing immediately.
- Within 30 days either return all your data in a machine-readable format (CSV / SQL dump / API export) or delete it from our servers — your choice.
- Delete all copies within 90 days (including backups, which rotate out naturally).
- Send you a certificate of deletion via email confirming the date and systems involved.
- The only carve-out: data we're legally required to keep (tax records on payments — 7 years).
12. Liability
Each party is liable for damage caused by its own actions or inactions in breach of GDPR or this DPA. If a regulator imposes a fine or a subject sues:
- Either party may pursue contribution from the other in proportion to fault.
- KVOKA's aggregate liability cap under this DPA is the annual fees paid for our services (trailing 12 months).
- Cap exclusions — willful breach, gross negligence, NDA violations, IP infringement.
- Force majeure — standard carve-outs (natural disasters, war, regulatory actions making performance impossible).
For a small studio like KVOKA, a liability cap is a survival question. If you need higher limits, we can talk individually (insurance, escrow).
13. How to sign the DPA
You can execute this DPA in a few ways — pick whatever is easiest:
13.1. E-signature
Send a message via WhatsApp / Telegram saying "I'd like to sign the DPA." I'll send the PDF with both parties' details. You sign through DocuSign / HelloSign / Adobe Sign and send it back. I countersign. Effective on the date of the last signature.
13.2. Signed scan
Ask us for the DPA PDF, sign it, scan it, and email it back to hi@kvoka.com.
13.3. Click-through (small-ticket services only)
If the service fee is under $500/mo, you can agree by clicking in Telegram ("I agree to the DPA at kvoka.com/legal/data-processing-agreement, date X"). The confirmation lives in our chat history. Legally valid in most jurisdictions.
13.4. Included in the master agreement
If you're signing a master SOW / MSA with us, the DPA folds in as Exhibit A. No separate signature needed.
14. DPA contact
For DPA questions, change requests, and incident notifications:
- 📱 WhatsApp: wa.me/37120469306
- 💬 Telegram: @maks_kvoka
- ✉️ Email: hi@kvoka.com
For formal DPO requests, use email with the subject line "[DPA] description" — that's how I guarantee handling within 1 business day.
Ready to sign the DPA?
Write to Maks — I'll send the PDF with details within an hour. Real human, not a bot.