Data processing agreement
Last updated 1 October 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Corella Creations ("we", the "Processor") and the customer organisation using Proto Tracker ("you", the "Controller"). It applies when we process personal data on your behalf that is subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR or the Swiss Federal Act on Data Protection ("Data Protection Law"). By accepting the Terms you accept this DPA. If you need a countersigned copy for your records, email hello@proto-tracker.com.
1. Roles and scope
- You are the controller of the personal data in Customer Content: what your organisation records in Proto Tracker, including your members' names and email addresses as they appear on records and in the change history. We are its processor.
- We are a separate controller of account data (people's sign-in details and billing information), as described in our privacy policy. This DPA does not cover that data.
- The details of the processing are in Annex 1.
2. Our obligations
We will:
- process personal data only on your documented instructions, which are the Terms, this DPA and your use of the Service, unless the law requires otherwise (in which case we'll tell you first where the law allows). We'll tell you if we believe an instruction breaks Data Protection Law;
- ensure everyone authorised to process the data is bound by confidentiality;
- implement the technical and organisational measures in Annex 2;
- use sub-processors only as set out in section 3;
- taking into account the nature of the processing, help you respond to requests from people exercising their rights. Most requests can be handled in the app: admins can view, correct, export and delete records, and remove members. We'll pass on any request we receive directly;
- help you with security, breach notification, data protection impact assessments and prior consultation, as far as they relate to the Service;
- at the end of the Service, let you export your data, and delete it (section 6);
- make available the information reasonably needed to show compliance with this DPA, and allow for audits (section 7).
3. Sub-processors
You authorise us to use the sub-processors listed in Annex 3. We have written contracts with each that impose data protection obligations no less protective than this DPA, and we remain responsible for their performance.
We'll announce any new or replacement sub-processor at least 30 days in advance, by updating Annex 3 and emailing the owners of paying organisations. You can object on reasonable data protection grounds within that period. If we can't resolve the objection, you may end your subscription and receive a pro-rata refund of prepaid fees for the unused period.
4. International transfers
Customer Content is stored in Australia (Annex 1). Australia is not covered by an adequacy decision of the European Commission, so transfers of personal data to us from the European Economic Area are made under the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914). They are incorporated into this DPA by reference as follows:
- Module Two (controller to processor) applies. Where you are yourself a processor, Module Three (processor to processor) applies.
- Clause 7 (docking clause) applies. In Clause 9 we use Option 2 (general written authorisation), with the notice period in section 3. The optional wording in Clause 11 does not apply.
- Clause 17: the law of Ireland. Clause 18: the courts of Ireland.
- Annexes I to III of the Clauses are completed by Annexes 1 to 3 of this DPA. The competent supervisory authority is the one determined under Clause 13.
For transfers from the United Kingdom, the UK Information Commissioner's International Data Transfer Addendum (version B1.0) applies, with Table 1 to 3 completed by this DPA and either party able to end it under Section 19. For transfers from Switzerland, the Clauses apply with the Federal Data Protection and Information Commissioner as the competent authority and references to Member States read to include Switzerland.
If the Clauses conflict with this DPA or the Terms, the Clauses prevail. On request we'll provide the information you need for a transfer impact assessment.
5. Personal data breaches
We'll notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Content. We'll give you the information you need to meet your own obligations as it becomes available: what happened, the categories and approximate number of people and records affected, the likely consequences and the measures taken or proposed. Notification is not an admission of fault.
6. Return and deletion
Admins can export all Customer Content at any time (JSON, and the change history as CSV). When an owner deletes the organisation in the app (or asks us to), we delete its Customer Content from the live database immediately. Encrypted backups expire within 35 days. We keep nothing else, except where the law requires us to.
7. Audits
We'll answer reasonable security questionnaires once a year, and provide our security documentation and our sub-processors' certifications (such as AWS's SOC 2 and ISO 27001 reports). If this doesn't reasonably show compliance, or a supervisory authority requires it, you may audit us once a year, on at least 30 days' written notice, during business hours, at your cost, and subject to confidentiality.
8. General
Liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not allow this. This DPA lasts as long as we process Customer Content for you. If it conflicts with the Terms, this DPA prevails for the processing of personal data.
Annex 1: Details of the processing
| Data exporter | The customer organisation, as controller (or processor). Contact: the organisation's owners, as recorded in the Service. |
|---|---|
| Data importer | Corella Creations, Australia, as processor. Contact: hello@proto-tracker.com. |
| Subject matter and purpose | Providing the Proto Tracker service: storing and displaying records of hardware prototypes, and the change history of those records, for the organisation's members. |
| Nature of processing | Storage, retrieval, display, export and deletion, at the customer's instruction through the Service. |
| Data subjects | The organisation's members and invitees. Any other people the organisation chooses to mention in free-text fields (for example a customer contact in a note). |
| Categories of personal data | Names and email addresses of members and invitees; which member holds a prototype; who made each change and when; any personal data entered in notes, log entries or custom fields. |
| Special categories | None intended. The acceptable use policy does not allow them. |
| Frequency of transfer | Continuous, while the Service is used. |
| Retention | Until the customer deletes the records or the organisation; backups expire within 35 days (section 6). |
| Location | Amazon Web Services, Sydney, Australia (ap-southeast-2). |
Annex 2: Technical and organisational measures
- Encryption: TLS 1.2+ in transit with HSTS; AES-256 at rest using an AWS KMS customer-managed key dedicated to the Service and rotated automatically, including backups.
- Separation: every record is partitioned by organisation, and membership is checked on every request.
- Access control: owner, admin, editor and read-only viewer roles. Two-factor authentication is available to every user. Passwords are hashed with Argon2id. Sessions are short-lived and can be revoked on all devices.
- Operational access: production access is limited to the operator's engineering account, protected with multi-factor authentication, and used only to run and support the Service. There is no staff interface for browsing customer data.
- Least privilege: each infrastructure component has only the permissions it needs, and deployment uses short-lived credentials.
- Application security: a strict Content Security Policy with no third-party scripts in the app; rate limiting of sign-in, sign-up, resets and invitations; dependency updates and code scanning in continuous integration.
- Integrity and accountability: an append-only change history of every change to Customer Content, written in the same transaction as the change.
- Availability and resilience: managed, multi-availability-zone AWS services; point-in-time recovery for 35 days; monitoring and alerting.
- Incident response: a documented breach response procedure. Report suspected vulnerabilities to security@proto-tracker.com.
- Data minimisation: no advertising or third-party tracking in the app; application logs contain no request content or personal data.
Annex 3: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, database, encryption keys, content delivery and transactional email | Sydney, Australia (ap-southeast-2). Email may transit AWS global infrastructure. |
Stripe, Inc. processes billing details as our separate processor for account data, not Customer Content, so it isn't a sub-processor under this DPA. It's listed in our privacy policy.