JawsDB Data Processing Agreement

DATA PROCESSING AGREEMENT

This Data Processing Agreement ("DPA") is incorporated into and forms part of the Jaws DB Terms of Service. By subscribing to, configuring, or using the Jaws DB add-on on Heroku, the individual or entity using the service ("Controller" or "Customer") agrees to the terms of this DPA.

*Scope and Applicability: This DPA applies exclusively to Customers located in the European Union (EU), European Economic Area (EEA), or United Kingdom (UK), or to the extent that Processor is strictly required by Applicable Data Protection Law to process Customer's data under these terms. For the avoidance of doubt, this DPA does not apply to Customers, accounts, or processing activities located in the United States or other non-EU/UK jurisdictions, and such users are not entitled to the rights, standard contractual clauses, or audit privileges established herein.*


1. Parties and Interpretation

  • "Processor" is Jaws DB, LLC, located at 2708 War Wagon Way, Leander, TX 78641.
  • "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including, where applicable, Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"), the UK Data Protection Act 2018, and the UK GDPR (collectively, "Data Protection Law").
  • "Controller," "Processor," "Data Subject," "Personal Data," and "Processing" shall have the meanings given in Applicable Data Protection Law.
  • "Services" means the RDBMS-as-a-service add-on provided by Processor via the Heroku platform.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914.
  • "UK Addendum" means the International Data Transfer Addendum (version B1.0) issued by the UK Information Commissioner's Office (ICO).

2. Details of Data Processing

  • Nature and Purpose of Processing: Processor provides a hosted relational database management system (RDBMS) add-on on the Heroku platform. Processor processes Personal Data solely to provide, maintain, secure, and support the Services in accordance with Controller’s instructions and the underlying Terms of Service. No personal information is intentionally saved by Processor in its own administrative databases.
  • Categories of Data Subjects: Controller's end-users, customers, employees, or other individuals whose data Controller stores within the database instances provisioned through the Services.
  • Types of Personal Data: Any categories of Personal Data that Controller chooses to store within its database instances provisioned via the Services (which may include names, contact details, account credentials, or transactional data).
  • Duration of Processing: The duration of the agreement between Controller and Processor, up to the point of service deprovisioning, following which data is permanently deleted.

3. Obligations of Processor

  • Compliance with Instructions: Processor shall process Personal Data only on documented instructions from Controller, including with regard to transfers of personal data to a third country, unless required to do so by applicable law to which Processor is subject.
  • Unlawful Instructions: Processor shall immediately inform Controller if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law.
  • Confidentiality: Processor ensures that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Only authenticated administrators of Processor can retrieve login information to the database servers.

4. Subprocessing

  • Authorization: Controller generally authorizes Processor to engage subprocessors (including Heroku and cloud infrastructure providers, specifically Amazon Web Services [AWS]) to provide the underlying infrastructure.
  • Infrastructure Location: Processor configures cloud servers in AWS regions matching the user's Heroku app region (e.g., EU customers with apps in EU regions get their databases created in the same AWS regions).
  • Changes to Subprocessors: Processor shall inform Controller of any intended changes concerning the addition or replacement of other subprocessors via email to the primary account administrative contact or by posting such updates on Processor's website or technical documentation. This notice gives Controller the opportunity to object to such changes. If Controller reasonably objects, Controller's sole remedy is to terminate the applicable Services.
  • Obligations: Processor shall impose data protection obligations on any approved subprocessor that are no less restrictive than those set out in this DPA.

5. Security Measures

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. This includes restricting database access to authenticated administrators and providing MySQL general logs only upon explicit request by the Controller.

6. Data Subject Rights and Incident Notification

  • Data Subject Rights: Processor shall, to the extent legally permitted, promptly notify Controller if it receives a request from a Data Subject to exercise their rights under Applicable Data Protection Law. Processor shall provide reasonable assistance to Controller to facilitate such requests.
  • Assistance: Processor shall provide reasonable assistance to Controller in ensuring compliance with Controller's obligations regarding data protection impact assessments and prior consultations with supervisory authorities.
  • Personal Data Breach Notification: Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller’s Personal Data. Processor shall provide reasonable information and cooperation to Controller so that Controller can fulfill its data breach reporting obligations.

7. Audits and Inspections

To satisfy Controller's audit rights under Article 28(3)(h) of the GDPR while reflecting the operational reality of Processor’s cloud-native architecture:

  • Infrastructure Compliance (AWS): Controller acknowledges that the Services operate entirely on third-party cloud infrastructure (Amazon Web Services). Controller’s audit rights concerning physical, network, and hardware security are fully satisfied by reviewing AWS’s independent third-party audit reports and certifications (e.g., SOC 2, ISO 27001), which Processor shall direct Controller to obtain (e.g., via AWS Artifact).
  • Service Layer Audit (Desk Audit): To verify Processor’s own administrative and configuration controls, Processor shall, upon written request (no more than once per twelve-month period), provide written documentation or respond to a reasonable security questionnaire demonstrating compliance with this DPA.
  • Exclusion of On-Site Audits: Because Processor operates strictly as a cloud-based software management service and does not own, maintain, or house physical data centers or server hardware, physical on-site inspections of Processor’s corporate premises are expressly excluded.
  • Protection of Proprietary Information: Any documentation or questionnaire responses provided are subject to a mutually agreed Non-Disclosure Agreement. Under no circumstances shall Controller or its auditors be granted access to Processor’s trade secrets, proprietary algorithms, underlying architectural designs, source code, financial records, or data belonging to other customers.

8. Deletion and Return of Data

  • Self-Service Return: Because Controller has direct and continuous access to export its database at any time prior to service deprovisioning, Controller is solely responsible for extracting and returning its data before termination.
  • Deletion: Upon termination of the Services or upon Controller's request, databases are deleted immediately upon service deprovisioning. Automated backups are retained for 24 to 48 hours depending on the selected plan (or longer for custom plans), after which they are permanently and irrecoverably purged.

9. International Transfers and Standard Contractual Clauses

  • EU Transfers: To the extent that Personal Data originating from the European Economic Area (EEA) is transferred to Processor in a third country not recognized as providing an adequate level of protection, the Parties incorporate by reference Module Two (Controller-to-Processor) of the Standard Contractual Clauses (EU) 2021/914. For the purposes of the SCCs:
  • Annex I.A & I.B (Parties and Processing Details): The information in Section 1 and Section 2 of this DPA serves as Annex I.
  • Annex II (Technical and Organizational Measures): The security measures outlined in Section 5 serve as Annex II.
  • Annex III (Subprocessors): Controller authorizes the use of Heroku and AWS as initial subprocessors as detailed in Section 4.
  • UK Transfers: To the extent that Personal Data originating from the United Kingdom is transferred, the UK Addendum is incorporated by reference. The tables are completed as follows: (i) Table 1: Parties identified above; (ii) Table 2: The approved EU SCCs, Module Two; (iii) Table 3: Annex Info as set out in Section 2 of this DPA; and (iv) Table 4: Importer may end the Addendum.

10. Limitation of Liability

Each Party’s liability, taken together in the aggregate, arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is strictly subject to the limitation of liability provisions of the underlying Terms of Service between the Parties.

11. Governing Law and Jurisdiction

  • DPA Governing Law: This DPA shall be governed by and construed in accordance with the laws of the State of Texas, United States, without regard to its conflict of laws principles.
  • SCC Governing Law: Notwithstanding the foregoing, the Standard Contractual Clauses (and any international data transfers governed by them) shall be governed by the laws of the Republic of Ireland. In the event of any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

Processor Contact: privacy@jawsdb.com