Data Processing Addendum
Last updated: 11 October 2026
This Data Processing Addendum ("DPA") is part of the Terms of Service between you (the website owner, "Customer") and [Business name], [Address], company/registration number [Company/registration number] ("Ginta"). It applies automatically whenever Ginta processes personal data on your behalf, in particular messages that visitors send through the forms on your websites. It meets the requirements of Article 28 of the GDPR.
1. Roles
You are the controller of the personal data of your websites' visitors. Ginta is your processor and processes that data only to provide the service.
2. What is processed
| Subject matter and purpose | Hosting your websites; receiving, storing and showing you (and, if you turn it on, emailing you) messages sent through your websites' forms; running the ready-made parts you add (online bookings, shop orders and product questions, quote requests with photos, event sign-ups): storing them, showing them to you, and sending the confirmation, reminder and change emails your customers asked for; protecting your websites against abuse |
| Duration | As long as you use Ginta; then deletion as in section 8 |
| Types of data | What your forms and ready-made parts ask for (typically name, email, phone, message, address, the booked service and time, what was ordered, the event and number of places, photos added to a quote request); whether an online payment succeeded (never card details: those stay with Stripe); technical data of requests (IP address, kept only as a keyed hash for rate limits) |
| Data subjects | Visitors of your websites who use a form, book, order, ask for a quote, sign up for an event or open a page |
| Nature | Collection, storage, display, sending by email, deletion |
Page views are counted per website and day only, without personal data. Bookings, orders, quote requests and event sign-ups are deleted automatically two years after the appointment, order, request or event (earlier if you delete them or the website).
3. Ginta's obligations
Ginta will:
- process the data only on your documented instructions, which are these terms and how you set up your websites and forms, unless the law requires otherwise (we'll tell you if so, where allowed);
- make sure everyone who can access the data is bound to confidentiality;
- keep the data secure with the measures in section 6;
- help you, as far as possible, to answer requests from data subjects (you can see, export and delete messages in Ginta yourself) and with data protection impact assessments and consultations with authorities;
- tell you without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own duties;
- delete or return the data at the end of the service (section 8);
- give you the information needed to show compliance with Article 28 and allow audits, by giving you our documentation first and, if that isn't enough, a reasonable audit with 30 days' notice at your cost, at most once a year.
4. Sub-processors
You allow Ginta to use these sub-processors:
| Sub-processor | Service | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, storage, network, email delivery | Worldwide; USA |
| Cloudflare Email Service | Sending form-message emails to you, if turned on | Worldwide; USA |
Ginta's AI provider (Anthropic) never receives your visitors' form messages. Ginta binds each sub-processor to data protection duties at least as protective as this DPA and remains responsible for them. We'll tell you at least 30 days before adding or replacing a sub-processor (by email or in Ginta); you may object for good reason, and if we can't solve it you may end the service.
5. Transfers outside the EU/EEA
Where data is transferred outside the EU/EEA, Ginta makes sure the transfer is protected by an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.
6. Security measures
- Encryption in transit (HTTPS everywhere) and encryption at rest by our hosting provider.
- Each website runs on its own address, separated from Ginta's app and from your account.
- Access to production data only for authorised staff, with strong authentication; access only when needed for support, security or the law.
- Visitors' IP addresses are stored only as keyed one-way hashes; form contents are never written to logs.
- Rate limits and spam protection on forms; automatic checks that stop forms posting to other websites and password fields.
- Regular automated tests of the service.
7. Your obligations
You make sure you may collect the data your forms ask for, tell your visitors about it (Ginta can add a privacy page to your website) and only ask for what you need. Don't use forms for special categories of data (health, religion, etc.) unless you have a legal basis and have told us.
8. Deletion
When you delete a website, its messages are deleted at once. When you delete your account, all messages are deleted. You can export messages before that. Backups by our hosting provider are overwritten in the normal course.
9. Order of precedence
If this DPA conflicts with the Terms of Service about personal data, this DPA applies.
Questions: [Email].