Data Processing Agreement

Last updated: 27 June 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Skopos ("Processor") and the Customer ("Controller") and regulates the processing of personal data carried out on behalf of the Controller in accordance with Article 28 of the GDPR.

Note for B2B customers: if you process personal data of your end users via our Service (Controller), this DPA is automatically applicable upon acceptance of the Terms. For signed copies on company letterhead, contact support@skopos.ink.

1. Definitions

  • Personal data, Controller, Processor, Sub-processor: as defined in GDPR Article 4.
  • Service: the Skopos platform described in the Terms.
  • Customer data: personal data processed by Skopos on behalf of the Controller.

2. Subject and duration

Skopos processes Customer data only on documented instructions from the Controller, for the duration of the Service contract.

3. Nature and purpose of processing

  • Nature: storage, indexing, analysis, AI-generated insights of application logs.
  • Purpose: providing the log monitoring Service.
  • Data categories: log content (which may include user identifiers, IP addresses, technical metadata).
  • Data subjects: end users of the Controller's applications.

4. Obligations of the Processor

Skopos commits to:

  • Process data only on documented instructions from the Controller.
  • Ensure confidentiality of personnel authorized to process data.
  • Apply appropriate technical and organizational measures (Art. 32 GDPR).
  • Assist the Controller in fulfilling requests from data subjects (Art. 15–22 GDPR).
  • Notify the Controller of personal data breaches without undue delay (within 72 hours where possible).
  • Make available all information necessary to demonstrate compliance with Art. 28 GDPR.

5. Sub-processors

The Controller authorizes Skopos to use the sub-processors listed in our Privacy Policy (Hetzner, Vercel, Cloudflare, Anthropic, Resend, Lemon Squeezy). The full and current list is maintained on the Privacy Policy page; new sub-processors are notified by email at least 30 days in advance, giving the Controller the right to object.

Skopos remains liable to the Controller for any failure by sub-processors to fulfill their obligations.

Lemon Squeezy as Merchant of Record: for billing, payment, and tax data, Lemon Squeezy acts as an independent Controller under its own privacy policy, not as a sub-processor of Skopos. This DPA does not extend to that processing relationship.

6. International transfers

Non-EU transfers are based on Standard Contractual Clauses (SCC) approved by the European Commission, or on equivalent adequacy mechanisms (e.g., EU-US Data Privacy Framework).

7. Security measures

Skopos applies:

  • TLS 1.3 encryption for all data in transit.
  • Encrypted database with restricted access.
  • Bcrypt password hashing.
  • Network and application-level rate limiting.
  • Daily backups with 30-day retention.
  • Monitoring of unauthorized access.
  • Principle of least privilege for personnel access.

8. Data subject rights

Skopos provides the Controller with the technical tools to:

  • Export data (via API).
  • Delete data (via project deletion or account closure).
  • Rectify data (via dashboard).

9. Data return and deletion

Upon termination of the Service, the Controller has 30 days to export their data via API. After that period, data is permanently deleted, except where retention is required by law.

10. Audit

The Controller has the right to audit Skopos's compliance with this DPA by requesting documentation. On-site audits may be agreed upon for Business plans with at least 30 days' notice.

11. Liability

Limitations of liability are those set forth in the Terms of Service.

12. Contact

Data Protection Officer (DPO): support@skopos.ink