Data processing agreement
Last updated: September 29, 2026
This Data Processing Agreement ("DPA") meets the requirements of article 28 of the General Data Protection Regulation (GDPR). It applies when you, as a customer, store or process personal data on your cornercase machines as a controller, or as a processor on behalf of your own clients. It is part of the Terms and applies automatically when you accept them. If you need a signed copy, write to [email protected].
1. Parties and roles
- Controller: the customer that holds the cornercase account ("you").
- Processor: [RAZÓN SOCIAL], NIF [NIF], with its registered address at [DIRECCIÓN] ("cornercase", "we").
For the data we process to run our own relationship with you (your account, billing and the technical metrics of your machines), we act as controller, as explained in the Privacy Policy. This DPA covers only the personal data you put on your machines or give us so that we process it for you.
2. Subject matter, duration, nature and purpose
- Subject matter: hosting the machines you contract, relaying the encrypted connections to them and, when a machine is deleted, keeping its final snapshot.
- Duration: while the Terms are in force, and until the final snapshots of your machines are deleted, 30 days after each machine is deleted.
- Nature: storage and hosting of data on virtual machines, and transmission of encrypted traffic. We do not access the content of your machines.
- Purpose: providing the service described in the Terms.
3. Types of data and data subjects
You decide which personal data you store on your machines and whose data it is. It can include, for example, identification and contact data of your employees, clients or users, and any other data that your code or your databases contain. You must not store special categories of personal data unless you have assessed that the security measures in this DPA are appropriate for them.
The email addresses of the people you give access to your machines are also processed.
4. Our obligations
We will:
- Process the personal data only on your documented instructions. The Terms, this DPA and the way you configure and use the service are your instructions. If we believe an instruction infringes data protection law, we will tell you.
- Make sure that the people authorised to process the data are bound by confidentiality.
- Apply the security measures described in section 9.
- Only use sub-processors as set out in section 5.
- Help you, as far as possible and taking into account the nature of the processing, to respond to requests from data subjects exercising their rights.
- Help you comply with your obligations on security, personal data breach notification, data protection impact assessments and prior consultation (articles 32 to 36 GDPR), taking into account the information available to us.
- At the end of the service, delete the personal data. You can copy your data before deleting your machines. The final snapshot of each machine is deleted 30 days after the machine is deleted, unless the law requires us to keep it.
- Make available to you the information necessary to demonstrate compliance with this DPA, and allow and contribute to audits, as set out in section 8.
5. Sub-processors
You give us a general authorisation to use sub-processors. These are the current ones:
- DigitalOcean: hosting of the machines and snapshots in its Frankfurt (Germany) data centre.
- Clerk: authentication of the people who use the machines.
- Resend: sending the emails of the service, including invitations to machines.
- Sentry and Better Stack: error reports and technical logs.
We impose on each sub-processor data protection obligations equivalent to those in this DPA, and we remain responsible to you for their compliance. We will tell you by email at least 30 days before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we cannot find a solution, you can delete your machines and terminate the service before the change takes effect.
6. International transfers
The machines and their snapshots are hosted in the European Union. If a sub-processor processes personal data outside the European Economic Area, the transfer is based on an adequacy decision, such as the EU–U.S. Data Privacy Framework, or on the European Commission's standard contractual clauses, with the additional safeguards required.
7. Personal data breaches
We will notify you without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach that affects the data covered by this DPA. We will give you the information we have so that you can meet your own notification obligations, and we will update it as we learn more.
8. Audits
You can ask us for information to verify our compliance once a year, or at any time after a personal data breach. If that information is not enough, you can carry out an audit, yourself or through an independent auditor bound by confidentiality, with at least 30 days' notice, during business hours and at your own cost, in a way that does not affect the security of the service or of other customers.
9. Security measures
- Machines have no open ports: the cloud firewall has no inbound rules, and the machine firewall denies all incoming traffic.
- Connections from your devices to your machines use SSH encrypted end to end through a relay that cannot decrypt the traffic.
- Device keys are generated on each device and never leave it. Only the devices of the person who uses a machine are authorised to connect to it, and the apps verify the identity of the machine (host key pinning).
- Our team has no access to connect to your machines.
- Machines run on a private network separated from the rest of our infrastructure.
- Access tokens are stored hashed, and all traffic with our servers is encrypted with TLS.
- Access to our infrastructure is limited to the people who need it, with individual credentials.
- The machine images are kept up to date, with automatic security updates.
10. Liability and precedence
Each party's liability under this DPA is subject to the limits set out in the Terms, except where the law does not allow them. If this DPA and the Terms conflict on data protection, this DPA prevails.
This DPA is available in English and Spanish. If they differ, the Spanish version prevails.