Data Processing Agreement
Standard DPA · Version 2026-07-28 · GDPR Article 28
This standard DPA is part of the Terms for Business customers where Secretus acts as processor. It is not intended for consumer-only use. A customer that needs a negotiated DPA, order form, UK addendum, Swiss addendum, or specific transfer annex can contact legal@secretus.app before instructing processing.
1. Incorporation and roles
This Data Processing Agreement (DPA) is incorporated into the Secretus Terms of Service when a Business customer, acting through an authorised representative, uses Secretus as a controller or processor and Secretus processes Customer Personal Data only on that customer's documented instructions. The Business customer is the controller (or processor appointing Secretus as sub-processor); MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ, trading as Secretus, is the processor or sub-processor. It does not apply to processing for which Secretus is an independent controller, including its account administration, security, billing, legal compliance, and direct support, as described in the Privacy Policy.
2. Subject matter and instructions
Secretus processes Customer Personal Data for the duration of the customer’s use of the Services, solely to provide, secure, maintain, and support the configured Secretus services; follow documented instructions in the Terms, order, settings, and authorised user actions; and comply with applicable law. Customer Personal Data can include account, recipient, team, audit, network, and encrypted payload metadata and ciphertext. The customer is responsible for its lawful basis, notices, data-minimisation choices, and any special-category or regulated-data condition.
3. Confidentiality and security
Secretus limits access to authorised persons bound by confidentiality and applies the technical and organisational measures described in the Security Whitepaper, Privacy Policy, and applicable service documentation. Those measures include role-based access, EU-region hosting configuration, encryption in transit and at rest where applicable, client-side encryption in relevant workflows, authentication controls, logging, least privilege, and incident management. Measures are risk-based and are not a promise of invulnerability, certification, or a service-level agreement.
4. Sub-processors
The customer gives general written authorisation for the processors listed at secretus.app/subprocessors to the extent they process Customer Personal Data. Secretus will impose written data-protection obligations on sub-processors and remains responsible as required by law. For material additions or replacements, Business DPA customers receive the notice and reasonable documented-objection process described in the provider register and may stop the affected feature or terminate the affected prepaid service if no reasonable solution is available.
5. Assistance and incidents
Taking account of the nature of processing and information available, Secretus will provide reasonable assistance with data-subject requests, GDPR Articles 32–36, and regulator inquiries. Secretus will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, provide available information in phases, and reasonably assist the customer with its controller obligations. The customer remains responsible for assessing and making controller notifications.
6. Deletion and return
During the term, available product controls permit access to account and audit information. On termination or a documented request, Secretus deletes Customer Personal Data from active systems within 30 days unless law requires retention. Encrypted backup or point-in-time-recovery copies may remain isolated for up to 35 days. Standard-mode ciphertext follows its selected expiry, one-time claim, revocation, and lifecycle cleanup; P2P payloads and Team Split shares are not stored by Secretus through those workflows. Secretus cannot return plaintext or a decryption key it never receives.
7. Information and audits
Secretus makes available information reasonably needed to demonstrate compliance. The parties first use current policies, architecture documentation, questionnaires, test summaries, and provider reports that Secretus may lawfully share. If this is insufficient, the customer may conduct a proportionate remote audit through qualified personnel or an independent, confidential auditor with reasonable notice. This does not prevent an audit or inspection required by applicable law, a binding regulator request, or a material security incident; all audits must protect other customers, security-sensitive information, and service continuity.
8. International transfers
Primary processing is configured in AWS eu-central-1 (Frankfurt). Where a restricted transfer occurs, Secretus uses an adequacy decision, the applicable European Commission Standard Contractual Clauses with required supplementary measures, or another lawful transfer mechanism. Where the transfer SCCs are required, the relevant controller-to-processor or processor-to-sub-processor module and Annexes in the detailed DPA template apply.
9. Priority, liability, and contact
This DPA prevails over the Terms only for Customer Personal Data processing. It does not limit data-subject rights, supervisory-authority powers, or liability that cannot lawfully be limited. For a signed Enterprise arrangement, the signed DPA controls to its express scope. Send DPA, transfer, or privacy requests to legal@secretus.app or privacy@secretus.app.
