Legal

Data Processing Addendum

Article 28 GDPR terms for customers who entrust personal data to DRIVUNO. It incorporates the EU Standard Contractual Clauses (2021/914, Module Two), the UK International Data Transfer Addendum and the Swiss FADP, and includes the sub-processor register, the technical and organisational measures and the retention schedule as annexes.

Version 2.0 · Effective 2 August 2026

Generate your signable copy

Fill in your entity details and download a branded PDF, pre-filled and already signed on our side. Everything is generated in your browser — these details are never sent to DRIVUNO.

The fingerprint printed in the PDF footer is a SHA-256 of the canonical contract text. Re-open this page to confirm your copy matches the published version.

Contractual terms

1. Definitions and interpretation

“GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as incorporated into UK law by the Data Protection Act 2018. “FADP” means the Swiss Federal Act on Data Protection. “SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Personal Data Breach” have the meanings given in the GDPR. “Customer Data” means Personal Data that DRIVUNO processes on behalf of the Customer under the Agreement.

This Addendum forms part of, and is subject to, the DRIVUNO Terms of Service (the “Agreement”). In the event of a conflict, this Addendum prevails over the Agreement in respect of Processing of Customer Data, and the SCCs prevail over this Addendum.

2. Roles of the parties

The Customer is the Controller and DRIVUNO is the Processor in respect of Customer Data. Where the Customer is itself a processor acting for a third-party controller, DRIVUNO acts as sub-processor and the Customer warrants that it has the authority to enter into this Addendum on that controller’s behalf.

DRIVUNO is an independent controller only for a narrow set of account and operational data described in Annex I — account identity, billing records and security telemetry — which it processes to operate, secure and bill for the service.

Because Customer Data is encrypted on the Customer’s devices with keys DRIVUNO does not hold and cannot derive, DRIVUNO is structurally unable to read, scan, index, disclose or analyse file, message or folder content. This technical limitation supplements, and does not replace, the contractual commitments below.

3. Subject matter, duration and nature of processing

The subject matter is the provision of the DRIVUNO end-to-end encrypted storage, messaging and collaboration service. Processing continues for the term of the Agreement and for the deletion periods set out in Clause 12 and Annex IV.

The nature and purpose of the Processing, the categories of Data Subjects and the categories of Personal Data are described in Annex I.

4. Documented instructions

DRIVUNO processes Customer Data only on documented instructions from the Customer, including with regard to international transfers, unless required to do so by Union or Member State law. Where such a legal requirement applies, DRIVUNO informs the Customer before Processing unless the law prohibits that notice on important grounds of public interest.

The Agreement, this Addendum, and the Customer’s use of the service’s configuration options constitute the Customer’s complete documented instructions. DRIVUNO informs the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law.

DRIVUNO does not sell Customer Data, does not use it for advertising or profiling, and does not use it to train artificial-intelligence models.

5. Confidentiality of personnel

DRIVUNO ensures that persons authorised to process Customer Data are bound by written confidentiality obligations that survive the end of their engagement, receive data-protection and security training, and are granted access strictly on a need-to-know basis.

Administrative access to production systems requires multi-factor authentication and is recorded in an append-only audit trail. No level of internal privilege grants the ability to decrypt Customer content.

6. Security of processing (GDPR art. 32)

DRIVUNO implements and maintains the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing as well as the risk to Data Subjects.

DRIVUNO may update those measures over time provided the overall level of security is not reduced. Material changes are published in the security changelog.

7. Sub-processors

The Customer grants DRIVUNO general written authorisation to engage the sub-processors listed in Annex III. DRIVUNO imposes on each sub-processor data-protection obligations no less protective than those in this Addendum, and remains fully liable to the Customer for their performance.

DRIVUNO gives at least 30 days’ notice before adding or replacing a sub-processor that processes Customer Data. The Customer may object on reasonable, documented data-protection grounds within that period; if the parties cannot agree on a remedy, the Customer may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees.

No sub-processor receives decryption keys for Customer content. Sub-processors handling storage or transport receive ciphertext only.

8. Assistance with data subject rights

The service provides self-service tooling that allows the Customer to satisfy access, rectification, erasure, restriction and portability requests directly, without DRIVUNO intervention: a full structured export of all held data, per-item deletion, and irreversible account deletion.

Where a Data Subject contacts DRIVUNO directly, DRIVUNO refers them to the Customer and does not respond substantively unless legally obliged to. Where self-service tooling is insufficient, DRIVUNO provides reasonable assistance within 10 business days, taking into account the nature of the Processing and the information available to it.

9. Personal data breach notification

DRIVUNO notifies the Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Data.

The notification describes the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Where the information cannot be provided at once, it is supplied in phases without further undue delay.

DRIVUNO assists the Customer in meeting its own obligations under GDPR art. 33 and 34. Notification is not, and may not be construed as, an acknowledgement of fault or liability.

10. Data protection impact assessment and prior consultation

DRIVUNO provides reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under GDPR art. 35 and 36, taking into account the nature of the Processing and the information available to DRIVUNO.

The published security architecture, threat model and this Addendum are designed to supply the substance of that assistance without bespoke work.

11. Audits and inspections

DRIVUNO makes available all information necessary to demonstrate compliance with GDPR art. 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.

The Customer’s audit right is satisfied in the first instance by DRIVUNO’s published documentation, the technical and organisational measures in Annex II, and any available third-party assessment summaries. Where those are insufficient, the Customer may request an audit no more than once in any 12-month period on 30 days’ written notice, during business hours, without unreasonably disrupting operations, and subject to confidentiality. This frequency limit does not apply following a confirmed Personal Data Breach or on the documented instruction of a supervisory authority.

The auditor may not be a competitor of DRIVUNO, and audits may not extend to other customers’ data or to information whose disclosure would itself create a security risk.

12. Return and deletion of customer data

The Customer may export its data at any time during the term. Encrypted content can be restored to local storage in its original folder structure through the client application; account and metadata records can be exported as a structured machine-readable file.

On expiry or termination of the Agreement, DRIVUNO deletes Customer Data within 30 days unless Union or Member State law requires continued storage. Encrypted objects are deleted from storage, sealed keys are destroyed, and audit records are anonymised. Backup snapshots containing residual ciphertext expire automatically within the rolling backup window set out in Annex IV.

DRIVUNO certifies deletion in writing on the Customer’s request.

13. International transfers

The Customer selects a data-residency region for its content at signup. DRIVUNO does not transfer Customer content outside the selected region except as strictly necessary to deliver the service the Customer has requested.

Where a transfer of Personal Data outside the EEA, the United Kingdom or Switzerland to a country without an adequacy decision is necessary, the parties incorporate the SCCs by reference: Module Two (Controller to Processor) applies, with Clause 7 (docking) included, Clause 9 option 2 (general written authorisation, 30 days’ notice), Clause 11 optional independent dispute body excluded, Clause 17 governed by the law of Ireland, and Clause 18 forum the courts of Ireland. Annexes I, II and III of this Addendum populate Annexes I, II and III of the SCCs.

For UK transfers the parties incorporate the UK International Data Transfer Addendum (version B1.0) to the SCCs. For Swiss transfers, references to the GDPR are read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

Because all Customer content is encrypted before it leaves the Customer’s device with keys retained solely by the Customer, any transferred content is unintelligible to any importer, sub-processor or public authority in the destination country — a supplementary measure within the meaning of the EDPB Recommendations 01/2020.

14. Government and law-enforcement requests

DRIVUNO notifies the Customer of any legally binding request for disclosure of Customer Data by a public authority unless prohibited by law, in which case it challenges the prohibition and seeks a waiver.

DRIVUNO challenges requests that appear unlawful, overbroad or inconsistent with the GDPR. It cannot produce plaintext content in response to any request, because it does not hold the keys. Requests received and their outcomes are recorded and reported in aggregate.

15. Liability, term and governing law

Each party’s liability under this Addendum is subject to the limitations and exclusions of liability in the Agreement.

This Addendum takes effect on the date of last signature, or on the Customer’s first use of the service if earlier, and continues for as long as DRIVUNO processes Customer Data.

This Addendum is governed by the law of Ireland and the parties submit to the exclusive jurisdiction of the courts of Ireland, without prejudice to the mandatory rights of Data Subjects and supervisory authorities.

Annex I — Description of the processing

Categories of data subjects
The Customer’s employees, contractors, clients and any individual whose personal data the Customer chooses to store, transmit or collaborate on using the service.
Categories of personal data (content)
Any personal data contained in files, folders, messages, notes, documents, whiteboards and calendar entries uploaded by the Customer. This data is end-to-end encrypted and is never available to DRIVUNO in plaintext.
Categories of personal data (operational)
Account email, chosen residency region, subscription and billing status, encrypted object sizes and timestamps, IP address and user agent in security audit records, and optional phone number where SMS recovery is enabled.
Special category data
Not requested and not required. If the Customer stores special category data, it remains encrypted under the Customer’s keys and is inaccessible to DRIVUNO.
Frequency of processing
Continuous, for the duration of the Agreement.
Nature and purpose
Storage, synchronisation, backup, encrypted transmission, sharing and collaboration; account authentication; abuse prevention; billing; and service support.
Duration of processing
For the term of the Agreement plus the deletion periods set out in Clause 12 and Annex IV.
Competent supervisory authority
The Data Protection Commission (Ireland), without prejudice to the competence of the Customer’s own lead authority.

Annex II — Technical and organisational measures

Pseudonymisation and encryption of personal data
Content is encrypted on the client device with XChaCha20-Poly1305 authenticated encryption before transmission. Per-file keys are sealed to the recipient with X25519. The master key is derived from the user passphrase with Argon2id (3 iterations, 64 MiB memory) and is never transmitted. TLS 1.3 protects all data in transit. Server-side storage holds ciphertext only.
Ability to ensure ongoing confidentiality
Row-level security on every database table, enforced by identity-anchored policies and immutability triggers. Least-privilege service roles. Mandatory multi-factor authentication for administrative access. No operator role can decrypt customer content.
Ability to ensure ongoing integrity
Authenticated encryption rejects any tampered ciphertext. SHA-256 verification on backup and restore paths. Append-only, tamper-evident audit logging of security-relevant events.
Ability to ensure availability and resilience
Multi-region edge delivery, automated provider failover checks, and encrypted off-site snapshots held under immutable object lock for a rolling window.
Restoring availability after an incident
Documented disaster-recovery procedure with a standby deployment and regularly exercised restore path from encrypted snapshots.
Regular testing and evaluation
Automated security regression and isolation test suite executed on every build, including randomised fuzzing of access-control predicates and a network gate that fails the build if any plaintext secret would leave the browser. Dependency vulnerability scanning. Public vulnerability disclosure programme.
User identification and authorisation
Passphrase authentication with WebAuthn passkeys and TOTP step-up. Session inventory with instant revocation. Geo-anomaly detection on new sessions. Rate limiting and lockout on authentication and recovery endpoints.
Protection of data during transmission
TLS 1.3 with HSTS preload; strict Content Security Policy; subresource integrity on third-party scripts. Payload confidentiality does not depend on transport security, since payloads are already encrypted.
Protection of data during storage
Ciphertext at rest, additionally covered by provider-level disk encryption. Keys required to read content exist only on customer devices.
Physical security of processing locations
Processing takes place in the certified data centres of the infrastructure sub-processors listed in Annex III; DRIVUNO operates no physical facility that holds customer data.
Events logging
Authentication, key operations, sharing, administrative actions and deletions are recorded with actor, timestamp and source, in an append-only store with a defined retention period.
System configuration and governance
Infrastructure and schema changes are version-controlled and peer-reviewed. Security headers and access policies are asserted by automated tests. Published security changelog and release transparency records.
Data minimisation
No advertising identifiers, no behavioural profiling, no content scanning, no AI training on customer data. Analytics is cookieless and does not collect personal data.
Accountability
Named privacy contact and data protection officer, maintained record of processing activities, and a published subprocessor register with advance-notice commitment.
Measures for sub-processors
Written data-protection terms no less protective than this Addendum, transfer mechanisms in place, and ciphertext-only exposure for storage and transport providers.

Annex III — Authorised sub-processors

CloudflareEdge runtime, DDoS protection, CDNEncrypted request bodies, IP addresses (logs)Global (Anycast)
Supabase Inc. (managed Postgres & object storage)Production database and object storage holding ciphertext only. Provisioned and administered through our managed cloud control plane.Account records, ciphertext, sealed key envelopes, audit logsEU (Ireland)
Backblaze B2Immutable off-site backup snapshots (encrypted before upload)Encrypted snapshot archives onlyEU (Amsterdam)
ResendTransactional email deliveryEmail addresses, message bodies we generateEU / US
TwilioSMS for 2FA and recovery (opt-in)Phone numbers, SMS bodyGlobal
StripeCard and SEPA paymentsBilling identity, card metadataEU / US
MollieEU payments fallbackBilling identity, payment metadataEU
AdyenGlobal payments fallbackBilling identity, payment metadataEU / Global
PlausiblePrivacy-preserving site analytics (no cookies, no PII)Anonymized request URL, user agent, referrerEU

Full detail and change notifications: /security/subprocessors.

Annex IV — Retention and deletion schedule

Encrypted file content (ciphertext)Until the user deletes it, or 30 days after account closurePerformance of contract (art. 6(1)(b))
Trash (soft-deleted items)30 days, then permanent purgePerformance of contract — accidental deletion protection
File and folder metadata (encrypted names, sizes, versions)Same lifecycle as the object it describesPerformance of contract
Account record (email, region, plan)Life of the account + 30-day grace periodPerformance of contract
Security audit log (action, timestamp, IP, user agent)12 monthsLegitimate interest — fraud and intrusion detection (art. 6(1)(f))
Session and device recordsUntil revoked, or 90 days of inactivityLegitimate interest — account security
Billing and invoice records10 yearsLegal obligation — accounting and tax law (art. 6(1)(c))
Off-site backup snapshots30 days rolling (immutable object lock)Legitimate interest — disaster recovery
Transactional email delivery logs30 daysLegitimate interest — deliverability troubleshooting
Support correspondence24 months after the ticket is closedLegitimate interest — service quality and dispute handling

Deletion mechanisms are detailed at /security/retention.

Contact

Privacy: privacy@drivuno.com · Data Protection Officer: dpo@drivuno.com

This Addendum is app-owned contractual content maintained by DRIVUNO. It is not an independent certification or audit report.

End-to-end encrypted