This Data Processing Agreement (hereinafter, the "DPA") forms an integral part of the Furx subscription agreement (Team / Enterprise / Compliance Pack) entered into between the Customer (acting as Controller) and INVERSO HUB S.R.L. (acting as Processor), pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR).
No DPA applies to Free and individual Pro plans — Furx does not process personal data of the User on behalf of a Customer (the User is the data subject of their own account data). This DPA applies where the Customer (an organization) subscribes to Team plans or above.
1. Definitions
- Personal Data: as defined in GDPR Art. 4(1).
- Processing: as defined in GDPR Art. 4(2).
- Sub-processor: a third party engaged by the Processor to process the Customer's Personal Data.
- Breach: a security incident affecting the confidentiality, integrity, or availability of Personal Data.
2. Nature, purpose, and duration of processing
- Purpose: providing the Furx service (local orchestration, opt-in audit log sync, Team seat management, customer dashboard).
- Nature: storage, transmission, logical access.
- Categories of data subjects: employees / contractors of the Customer who use Furx.
- Categories of data: email, name, access IP, audit log metadata (timestamps, event types, LLM model names — never prompt/response bodies), usage data (logins, linked devices).
- Duration: term of the agreement + a 30-day grace period + legal retention pursuant to policy.
3. Processor obligations
INVERSO HUB undertakes to:
- Process Personal Data only on documented instructions from the Controller (Art. 28(3)(a)).
- Ensure the confidentiality of authorized personnel (Art. 28(3)(b)).
- Implement appropriate technical and organizational measures (Art. 32) — detailed in Section 6.
- Assist the Controller in fulfilling data subjects' rights (Art. 28(3)(e)).
- Assist the Controller with breach notifications and DPIAs where applicable (Art. 28(3)(f), Art. 33/34/35).
- Return or delete all Personal Data upon termination of the agreement (Art. 28(3)(g)), except where legal retention applies.
- Make available the information necessary to demonstrate compliance and allow for audits (Art. 28(3)(h)).
4. Sub-processors
The Customer authorizes the use of sub-processors as listed at /subprocessors. INVERSO HUB will notify the Customer by email + RSS at least 30 days in advance before adding or replacing a sub-processor, allowing the Customer to object on reasonable grounds.
5. International transfers
INVERSO HUB applies the Standard Contractual Clauses (SCC) 2021/914 Module 2 for transfers from the EEA to its sub-processors. The Customer accedes to those clauses as data exporter, and INVERSO HUB executes them with each sub-processor as data importer.
6. Technical and organizational measures (SCC Annex II)
Pseudonymization / encryption
- TLS 1.3 for all communications in transit.
- AES-256 encryption at rest (PostgreSQL, backups).
- HMAC-SHA256 on Paddle webhooks.
- License tokens and magic links: JWTs signed with Ed25519, short expiration.
Confidentiality, integrity, availability, resilience
- Append-only audit log with DDL triggers blocking UPDATE/DELETE.
- Daily encrypted backups to Cloudflare R2 (Frankfurt), retained for 30 days.
- PostgreSQL streaming replication to a Hetzner EU standby.
- 24/7 monitoring (Better Stack), alerts to on-call.
Restoration after an incident
- RPO: 1 hour (backups + WAL streaming).
- RTO: 4 hours (manual failover to standby).
- Monthly restore test.
Regular testing and evaluation
- SAST with Bandit + Ruff + Semgrep + Gitleaks on every commit.
- Weekly DAST with OWASP ZAP.
- Annual external pen-test.
- Weekly Renovate + osv-scanner in CI.
Identification and authentication
- Passwordless magic link (default).
- TOTP 2FA opt-in (Pro+), mandatory for Team+ admins.
- Single-use tokens, 10-minute expiry.
- Rate limit of 3/min/IP.
Access control
- Least-privilege principle across Inverso infrastructure (operational admins ≤ 2 people).
- Append-only, tamper-evident audit log of all admin actions.
Vendor management
- GDPR due diligence before onboarding (CF, Paddle, GitHub, Sentry).
- DPA / SCCs executed with each vendor.
- Annual review.
7. Breach notification
INVERSO HUB will notify the Customer of any security breach affecting their Personal Data within 72 hours of detection, including:
- Nature of the breach + categories and approximate volume of data subjects / records affected.
- Likely consequences.
- Measures taken and proposed.
- DPO contact details.
8. Audit
The Customer may request a documentation audit (review of the SOC2 evidence pack, most recent pen-test report, sub-processor list). On-site audits are subject to 60 days' notice, costs borne by the Customer, and a mutual NDA.
9. Termination and return
Upon termination of the agreement, INVERSO HUB:
- Exports the Customer's Personal Data in structured JSON format.
- Deletes active copies within 30 days, except where legal retention applies.
- Encrypted backups are automatically purged 30 days after generation.
10. Liability
The limitations of liability in the main agreement apply to this DPA, without prejudice to non-derogable obligations under the GDPR.
11. Signed PDF download
For Team/Enterprise: a signed PDF is available upon request to legal@furx.cloud (delivered within 48 business hours).