Last updated: June 1, 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") supplements the Terms of Service and is entered into between the customer identified below ("Controller") and FairForge LLC ("Processor", "stored.ge") pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
Contents
- Definitions and Roles
- Processing Purposes
- Processor Obligations
- Security Measures
- Sub-processors
- Breach Notification
- Audit Rights
- Data Return and Deletion
- International Transfers
- Term and Termination
- Countersignature
Definitions and Roles
- Controller: The customer who determines the purposes and means of processing personal data by using the stored.ge service.
- Processor: FairForge LLC (stored.ge), which processes personal data on behalf of the Controller solely to provide the object storage service.
- Data Subjects: Individuals whose personal data is stored as objects or metadata within the Controller's stored.ge account.
Processing Purposes
The Processor processes personal data solely for the following purposes, as instructed by the Controller:
- Storage — persisting objects uploaded by the Controller via the S3-compatible API.
- Delivery — serving objects to authorized requesters via API or CDN.
- Caching — temporarily caching object metadata for performance optimization.
The Processor does not access, analyze, profile, or otherwise process the content of stored objects beyond the technical operations listed above.
Processor Obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller.
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures.
- Assist the Controller in responding to data subject requests (access, portability, erasure, rectification).
- Assist the Controller with data protection impact assessments where required.
- Delete or return all personal data upon termination of the service, at the Controller's choice.
- Make available all information necessary to demonstrate compliance with Article 28.
Security Measures
The Processor implements the following technical and organizational measures:
- Encryption in transit — all API and dashboard traffic is encrypted via TLS 1.2 or higher.
- Encryption at rest — objects are stored on encrypted storage volumes.
- Access controls — production access is limited to authorized personnel via SSH key authentication. Customer data access requires S3 credentials (access key + secret key) or authenticated dashboard session.
- Authentication — passwords hashed with bcrypt (cost 12), TOTP two-factor authentication available, session tokens are cryptographically random.
- Monitoring — access logs retained for 90 days, anomaly detection on API usage patterns.
- Backups — daily PostgreSQL backups with 7-day retention, stored in a separate location from production data.
Sub-processors
The Controller authorizes the Processor to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| iDrive Inc. | Object storage infrastructure | United States |
| Stripe Inc. | Payment processing | United States |
| Cloudflare Inc. | CDN and DDoS protection | Global (edge network) |
The Processor will notify the Controller at least 30 days before adding or replacing a sub-processor, giving the Controller the opportunity to object.
Breach Notification
In the event of a personal data breach, the Processor shall:
- Notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach.
- Provide details of the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to mitigate the breach.
- Cooperate with the Controller in notifying the relevant supervisory authority and affected data subjects where required.
Audit Rights
The Controller has the right to audit the Processor's compliance with this DPA. Audits may be conducted:
- No more than once per calendar year, with at least 30 days' written notice.
- During normal business hours, at the Controller's expense.
- By the Controller or a mutually agreed independent third-party auditor bound by confidentiality.
The Processor will provide reasonable cooperation, including access to relevant documentation, facilities, and personnel.
Data Return and Deletion
Upon termination of the service agreement:
- The Controller may export all stored data via the S3-compatible API or the data export feature in account settings.
- After a 30-day grace period following account deletion, the Processor will permanently delete all Controller data from production and backup systems within 90 days.
- The Processor will provide written confirmation of deletion upon request.
International Transfers
Where personal data is transferred outside the European Economic Area, the Processor ensures adequate protection through Standard Contractual Clauses (SCCs) as approved by the European Commission (Commission Implementing Decision (EU) 2021/914). The applicable SCCs are incorporated by reference into this DPA.
Term and Termination
This DPA takes effect when the Controller begins using the stored.ge service and remains in effect for the duration of the service agreement. The data protection obligations in this DPA survive termination of the service agreement until all personal data has been deleted or returned.
Countersignature
To execute this DPA, please complete the following and send a signed copy to privacy@stored.ge:
| Customer Name: | ________________________________________ |
| Customer Address: | ________________________________________ |
| Authorized Signatory: | ________________________________________ |
| Signature Date: | ________________________________________ |
For FairForge LLC:
| Entity: | FairForge LLC |
| Address: | Salt Lake City, Utah, United States |
| Contact: | privacy@stored.ge |