Data Processing Agreement

Data Processing Agreement — Tortoise Hosted Service

This DPA governs the processing of personal data by Daniel Ospina (d/b/a Premise Labs) on behalf of the customer, in accordance with Article 28 of the GDPR.

Last updated 2026-08-08
Effective date Effective date: 2026-08-08
Version 1.0

Relationship to other documents. This Data Processing Agreement ("DPA") supplements the Terms of Service for the hosted Tortoise service and is incorporated into it by reference. In the event of any conflict between this DPA and the Terms of Service, this DPA controls with respect to the processing of Personal Data.

1. Parties and roles

Processor ("Provider"): Daniel Ospina (d/b/a Premise Labs), an individual resident in Mexico operating under the assumed business name "Premise Labs". Premise Labs is not a registered legal entity; this DPA is made with Daniel Ospina in his individual capacity.

Controller ("Customer"): the individual or entity that accepts this DPA and the Terms of Service, and that determines the purposes and means of the processing of Personal Data.

In situations where Customer is a Controller of the Personal Data, Provider is deemed a Processor that is processing Personal Data on behalf of Customer. In situations where Customer is a Processor of the Personal Data, Provider is deemed a Subprocessor.

2. Subject matter, nature, and purpose of processing

The subject matter of the processing is the provision of the hosted Tortoise service (tortoise.premiselabs.co) to Customer under the Terms of Service. The nature and purpose of the processing is to deliver, operate, maintain, secure, and support the Service for Customer, including authentication and account administration, usage measurement, and billing administration, as instructed through Customer's use of the Service and as described in the Privacy Policy.

3. Duration of processing

Personal Data is processed for the duration of the agreement between the parties, and is then retained only as long as needed to fulfill the purposes described in this DPA and the Privacy Policy, or as required by applicable law. On termination, Personal Data is deleted or returned in accordance with Section 11.

4. Categories of personal data and data subjects

Categories of data subjects: Customer's end users and account holders, including Customer's employees and other individuals authorized to use the Service.

Categories of personal data:

Special-category personal data is not processed: Customer must not submit sensitive personal data to the Service (see Section 3.3 of the Terms of Service), and such data is not requested or needed for any feature of the Service.

5. Processing instructions

Provider processes Personal Data only on documented instructions from Customer, unless required to do so by applicable law (in which case Provider informs Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest). Customer instructs Provider to process Personal Data (a) to provide and maintain the Service; (b) as further specified through Customer's use of the Service; and (c) as documented in the Terms of Service, the Privacy Policy, and this DPA. Provider immediately informs Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

6. Confidentiality

Provider ensures that persons authorized to process Personal Data on its behalf are committed to confidentiality or are under an appropriate statutory obligation of confidentiality (GDPR Art. 28(3)(b)). Provider limits access to Personal Data to what is necessary to operate and support the Service.

7. Security of processing

Provider implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk (GDPR Art. 28(3)(c) and Art. 32), including:

These measures are described in more detail in the Privacy Policy, Section 7. No security measures are absolute, and the security of the internet cannot be guaranteed.

8. Subprocessors

Customer generally authorizes Provider to engage the subprocessors listed below (GDPR Art. 28(2) and Art. 28(4)). Each subprocessor is engaged under a contract that imposes the same data-protection obligations as set out in this DPA, and subprocessors act only on documented instructions. Provider will notify Customer, through the contact channel in Section 15, of any intended changes to the list of subprocessors, so that Customer may object.

Subprocessor Processing task Status
Supabase Authentication and account records (email/login); database provider In use
Cloudflare Hosting and delivery of the website and API In use
GitHub OAuth sign-in; rights-request submissions In use
Google OAuth sign-in identity provider In use
Google Analytics (GA4) Audience and product analytics, delivered via Google Tag Manager In use (loaded only after consent)
Google Tag Manager Consent-gated tag container loading GA4 (and, when activated, the X and LinkedIn tags) In use (loaded only after consent)
Meta (Meta Pixel) Advertising measurement and conversion tracking When activated with consent
X (Twitter) Advertising and conversion tracking When activated with consent
LinkedIn Advertising and conversion tracking (Insight Tag) When activated with consent
PostHog Product analytics (data stored in the United States) In use (after consent)
Stripe Payment processing for paid plans When billing is live

9. Assistance with data subject rights

Provider assists Customer in fulfilling Customer's obligations to respond to requests from data subjects exercising their rights under the GDPR (GDPR Art. 28(3)(e)), taking into account the nature of the processing. This includes assistance with access, rectification, erasure, restriction, portability, and objection requests, as described in the Privacy Policy, Section 8 and Section 16.

10. Assistance with compliance obligations

Provider assists Customer in ensuring compliance with the obligations set out in GDPR Art. 32 (security of processing), Art. 33 and Art. 34 (personal data breach notification), Art. 35 (data protection impact assessments), and Art. 36 (prior consultation), taking into account the nature of the processing and the information available to Provider (GDPR Art. 28(3)(f)).

Personal data breaches. Provider notifies Customer without undue delay after becoming aware of a personal data breach affecting Personal Data processed under this DPA, providing the information available at that time (GDPR Art. 33(2)).

11. Deletion and return on termination

At the end of the provision of the services, and at Customer's choice, Provider deletes or returns all Personal Data processed under this DPA and deletes existing copies, unless applicable law requires retention (GDPR Art. 28(3)(g)). Deletion is carried out subject to the retention carve-outs described in the Privacy Policy, Section 6 (billing and transactional records retained as required by law; data in backups retained for a limited additional period to maintain integrity and not used for any other purpose).

12. Audits and information

Provider makes available to Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by Customer or another auditor mandated by Customer (GDPR Art. 28(3)(h)). Audit requests are made through the contact channel in Section 15 with reasonable prior notice and at a frequency that is proportionate to the processing.

13. International transfers

Where Personal Data is transferred from the EU/EEA, the UK, or Switzerland to a country outside those territories, the transfer is protected by appropriate safeguards, including the EU–US, UK Extension, or Swiss–US Data Privacy Framework certifications where the recipient participates, or Standard Contractual Clauses adopted by the European Commission or equivalent safeguards, as described in the Privacy Policy, Section 12. PostHog runs on the US Cloud; PostHog-processed analytics data is stored in the United States.

14. Liability

Each party is liable for damage caused by its processing that infringes the GDPR or this DPA, in accordance with GDPR Art. 82, taking into account the apportionment rules of Art. 82(3), (4), and (5). Nothing in this DPA limits or excludes liability to the extent it cannot be limited or excluded under applicable law.

15. Contact

To ask a question, send a notice, or make a request under this DPA, email [email protected]. This is the designated contact channel for all requests under this DPA, including subprocessor-change notices and audit requests.

16. Conflicts and governing law

This DPA is governed by the laws of the State of Delaware, without regard to its conflict-of-laws principles. In the event of any conflict between this DPA and the Terms of Service, this DPA controls with respect to the processing of Personal Data.