Data Processing Agreement

Effective: 22 September 2026 · Last updated: 22 September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and Strimium S.R.L. (IDNO 1019600057092, Republic of Moldova) ("Processor", "legivel"). It applies whenever documents the Controller submits to the service contain personal data subject to the GDPR, the UK GDPR or Moldovan Law No. 195/2024 on personal data protection (together, "Data Protection Law"). The DPA is accepted electronically together with the Terms and applies automatically to every customer; no signature is required. The Processor records the version accepted and the time of acceptance.

1. Subject matter, nature, purpose and duration

The Processor converts Markdown documents submitted by the Controller into PDF documents, on the Controller's instruction, through the web editor, the REST API and the MCP server. The sole purpose of processing is to serve the Controller's conversion requests. Processing of document content is transient: each document is processed in memory for the duration of the request — typically seconds — and is not stored. The DPA applies for the duration of the service contract.

2. Type of personal data and data subjects

The documents may contain any categories of personal data, including special categories (Art 9 GDPR), and concern any categories of data subjects — both are determined solely by the Controller. The Processor does not inspect, analyse or profile document content. The Controller is responsible for the lawfulness of the personal data contained in submitted documents and, where it submits special categories of data or other high-risk data, for assessing whether the service is appropriate for that use, including by a data protection impact assessment where required.

3. Instructions

The Processor processes document content only on the Controller's documented instructions, including with regard to transfers to third countries, unless required to do so by law to which the Processor is subject; in that case the Processor informs the Controller before processing, unless the law prohibits it. The conversion request itself — including its parameters (delivery mode, sealing instruction, remote resource fetching) — together with this DPA constitutes the instruction. The Processor informs the Controller without delay if, in its opinion, an instruction infringes Data Protection Law.

4. Confidentiality

Persons authorised to operate the service are bound by confidentiality obligations. Document content is not accessible to operations staff in the ordinary course: it exists only in process memory during a request and appears in no logs, database records or backups.

5. Security (Art 32)

The Processor implements the technical and organisational measures in the Annex. Given the transient processing model, the central measure is architectural: document content is never persisted. The Processor may update the measures, provided that the overall level of security is not reduced.

6. Sub-processors

  1. The Controller grants general authorisation for the sub-processors listed at /sub-processors. Document content reaches only the hosting provider (Hetzner), in the memory of the Processor's server, and the network provider (Cloudflare), in transit, where the encrypted connection is terminated at its edge and re-encrypted to the Processor's server. Neither stores document content. The other sub-processors handle account, billing, delivery and telemetry data.
  2. The Processor notifies account holders by email at least 30 days before a new sub-processor begins processing personal data. The Controller may object on reasonable data-protection grounds within that period and, if the parties cannot resolve the objection, terminate the affected service before the change takes effect.
  3. The Processor imposes on each sub-processor, by contract, data protection obligations that provide at least the same level of protection as this DPA, and remains liable to the Controller for the performance of each sub-processor's obligations.

7. Assistance

  1. Data subject requests. Taking into account the nature of the processing — no document content is retained — requests by data subjects concerning document content cannot be served by the Processor after a request completes, and the Controller is the correct addressee. The Processor assists the Controller with reasonable measures where assistance is possible (for example, records about a stored seal certificate), and forwards without undue delay any data-subject request it receives that identifies the Controller.
  2. Security, impact assessments and consultation. Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in ensuring compliance with Articles 32 to 36 GDPR, including by making available the information in this DPA, the Annex and the security page for the Controller's data protection impact assessments and any prior consultation with a supervisory authority.

8. Personal data breach

The Processor notifies the Controller without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information required by Art 33(3) GDPR as it becomes available, and cooperates with the Controller in addressing the breach.

9. Deletion and return

Document content is deleted automatically when a request completes; there is nothing to return or delete at contract end. Data the Processor holds about the account (including stored seal certificates, which the Controller can delete at any time) is deleted per the retention terms of the Privacy Policy when the account is deleted, unless law requires its retention.

10. Audit and information

  1. The Processor makes available the information necessary to demonstrate compliance with Art 28 GDPR: this DPA, the Annex, the Privacy Policy, the security page and, on request to support@legivel.com, written answers to reasonable audit questionnaires, at most once per year unless a supervisory authority requires otherwise or a breach has occurred.
  2. Where this information is insufficient to demonstrate compliance, where a supervisory authority requires it, or after a personal data breach, the Processor allows for and contributes to audits, including inspections, by the Controller or an independent auditor mandated by it and bound by confidentiality — at the Controller's cost, with 30 days' notice, during business hours, and without access to other customers' data.

11. International transfers

  1. Production processing takes place in Falkenstein, Germany (Hetzner). The Processor is established in the Republic of Moldova, which is not the subject of an EU or UK adequacy decision.
  2. EU. To the extent that processing under this DPA involves a transfer of personal data subject to the GDPR from the Controller to the Processor, the parties incorporate by reference the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 ("SCCs"): Module Two (controller to processor) or, where the Controller is itself a processor, Module Three (processor to processor), with the following choices: Clause 7 does not apply; Clause 9(a) Option 2 applies, with the notice period in section 6.2; the optional wording in Clause 11 does not apply; the competent supervisory authority under Clause 13 is determined in accordance with Clause 13(a); Clause 17 Option 1 applies, with the law of Ireland; the courts of Ireland are chosen under Clause 18. Annex I of the SCCs is completed by the parties as identified in the Terms and the Controller's account and by sections 1 to 3 of this DPA; Annex II by the Annex to this DPA; Annex III by the sub-processor list.
  3. UK. For transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) is incorporated, completed with the information in section 11.2; either party may end it as provided in its Table 4.
  4. Onward transfers. The Processor transfers personal data to sub-processors outside the EEA or the UK only under an adequacy decision (including the EU–US Data Privacy Framework where the sub-processor is certified) or the SCCs.
  5. Transfer assessment. The Processor has assessed the laws and practices of the Republic of Moldova applicable to its processing and provides a summary of that assessment on request.
  6. In case of conflict, the SCCs and the UK Addendum prevail over this DPA.

12. Liability, precedence and counter-signed copies

Liability under this DPA follows the Terms of Service. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. On request, the Processor provides enterprise customers with a copy of this DPA counter-signed by the Processor; the counter-signed copy has the same content as the version published here.


Annex — Technical and organisational measures (Art 32)