Legal

Data Processing Agreement

Effective 26 July 2026. All legal documents

Sovryk is operated ahead of company incorporation in Romania. The registered company name, address and registration number will be published here as soon as incorporation completes. Until then the operator is reachable at contact@sovryk.com.

This Agreement (the "DPA") governs the processing of personal data by Sovryk on behalf of the Customer in connection with the Sovryk encrypted communications service (the "Service"). It is signed together with, and forms an annex to, the Terms of Service.

---

The parties

The controller (the "Customer"):

________________, with registered office at ________________, registration number ________________, represented by ________________.

The processor ("Sovryk"):

Sovryk, with registered office at registered address to be published on incorporation, registration number registration number pending, represented by the Sovryk operator.

Effective date: 26 July 2026.

---

1. Subject matter and roles

1.1. The Customer is the controller; Sovryk is the processor and processes personal data only on the Customer's documented instructions (including this DPA and the Terms of Service).

1.2. Sovryk does not process the data for its own purposes and does not sell it.

1.3. If Sovryk receives an instruction it believes infringes the GDPR or other applicable law, it informs the Customer without delay.

2. Duration

2.1. This DPA applies for as long as the Service is provided and until the data is deleted or returned under §9.

3. Nature and purpose of processing (Annex 1)

Set out in Annex 1: the categories of data subjects, the types of data, the operations and the purpose.

4. Customer obligations (controller)

4.1. Ensures it has a valid legal basis for the data entered into the Service.

4.2. Gives lawful instructions and is responsible for the lawfulness of the data it uploads.

4.3. Handles information duties towards its own data subjects (staff, the firm's clients).

5. Sovryk obligations (processor)

Sovryk undertakes to:

5.1. Process the data only on the Customer's documented instructions.

5.2. Ensure confidentiality. Persons authorised to process the data are bound by confidentiality obligations.

5.3. Implement the technical and organisational measures in Annex 2 (Article 32 GDPR).

5.4. Comply with the conditions for engaging sub-processors (§6).

5.5. Assist the Customer, as far as possible given end-to-end encryption, with:

5.6. Delete or return the data on termination (§9).

5.7. Make available the information needed to demonstrate compliance and allow audits (§8).

5.8. Notify the Customer of any personal data breach without undue delay and within 72 hours of becoming aware of it (§10).

6. Sub-processors

6.1. The Customer gives general authorisation for the use of sub-processors to provide the Service. The current list is in Annex 3.

6.2. Sovryk imposes on each sub-processor, by contract, the same data protection obligations as in this DPA.

6.3. Sovryk informs the Customer of the replacement or addition of a sub-processor at least 15 days in advance; the Customer may object on reasonable data protection grounds.

6.4. Sovryk remains liable to the Customer for the acts of its sub-processors.

7. Data subject rights

7.1. Sovryk assists the Customer, through appropriate technical and organisational measures, in responding to requests for access, rectification, erasure, restriction, portability and objection.

7.2. An honest technical limitation: the content of communications is end-to-end encrypted. Sovryk does not hold the keys and cannot access the content. Assistance is therefore limited to the data Sovryk technically controls (for example minimal account data).

7.3. If a data subject contacts Sovryk directly, the request is redirected to the Customer.

8. Audit

8.1. Sovryk makes available the information needed to demonstrate compliance, including its published security posture and any reports or certifications that exist.

8.2. The Customer may request an audit (itself or through an independent auditor, under confidentiality) at most once a year, on reasonable notice, without disrupting operations and without exposing other customers' data.

9. Deletion or return on termination

9.1. On termination of the Service, at the Customer's choice, Sovryk deletes or returns all the data and deletes existing copies, unless retention is required by law.

9.2. Deadline: within 30 days of termination. Encrypted backups rotate and expire according to the retention cycle.

10. Personal data breaches

10.1. On becoming aware of a breach, Sovryk notifies the Customer without undue delay (within 72 hours), stating: the nature of the breach, the approximate categories and number of data subjects and records affected, the likely consequences and the measures taken.

10.2. Because of the minimal data plus end-to-end encryption design, in a server breach the content remains encrypted and inaccessible to the attacker.

11. International transfers

11.1. The server is hosted in Iceland (1984 Hosting, Reykjavik).

11.2. If processing involves a transfer outside the EEA to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (SCCs) or another valid mechanism apply, attached as Annex 4.

11.3. Iceland is part of the EEA and Switzerland benefits from an adequacy decision, so as a rule no SCCs are needed for those regions. This is confirmed for the region actually chosen.

12. Liability

12.1. Liability is governed by the Terms of Service and by Article 82 GDPR. Each party is liable for its own breaches.

13. Governing law

13.1. This DPA is governed by Romanian law. In case of conflict between this DPA and the Terms of Service on data protection matters, this DPA prevails.

---

Annex 1: Details of the processing

ItemDetail
Data subjectsThe Customer's staff and users; the people they communicate with through the Service
Categories of dataAccount data (username, optional email); minimal technical metadata (connection logs, IP addresses where applicable); the content of communications (end-to-end encrypted, inaccessible to Sovryk)
Special categories (Art. 9)Possible incidentally within content (for example case file data), but end-to-end encrypted, so Sovryk cannot access it
OperationsStorage, transmission, hosting and backup on the Service infrastructure
PurposeProviding the encrypted communications service
DurationFor the term of the contract plus the retention period in §9

Annex 2: Technical and organisational measures (Art. 32)

Summary:

Annex 3: Authorised sub-processors

Sub-processorRoleLocation
1984 Hosting ehf., IcelandInfrastructure hosting (VPS)Iceland (1984 Hosting, Reykjavik)
Payment processorPayment processing (B2B invoicing only)EU/US (with SCCs)

Annex 4: Standard Contractual Clauses (where applicable)

The European Commission's SCCs, controller-to-processor module, are attached where hosting sits outside the EEA without an adequacy decision.

---

Signatures

For the controller (Customer): _______________________ Date: __________

For Sovryk (processor): _______________________ Date: __________