Data Processing Agreement (DPA)

GDPR Art. 28 standard - required for B2B customers (installers) processing their clients' data through SmartHomeEntry

Version: v1.0-20260423 Effective date: 2026-04-23 You can print this page or save it as a PDF (Ctrl+P / Cmd+P) as a signed reference document.

This Data Processing Agreement ("DPA") sets out the rules for the processing of personal data by SmartHomeEntry (Processor) on behalf of the Customer (Controller) in connection with the provision of network tunneling services. The DPA forms an integral part of the Terms and is concluded upon its acceptance in the account panel.

Accept DPA in account panel

1. Parties to the Agreement

Controller (Data Controller) - the Customer using the SmartHomeEntry service, who decides on the purposes and means of processing personal data of their end clients (e.g. a smart home systems installer servicing 50 clients).

Processor (Data Processor) - SmartHomeEntry, operated by [TODO operator full name], [TODO address], [TODO VAT ID after JDG registration - currently Polish unregistered activity], providing network tunneling services.

The DPA applies when the Controller uses the SmartHomeEntry service to process personal data of third parties (e.g. their end clients). Hobbyists processing only their own and their family's data are not required to accept the DPA, but may do so voluntarily.

2. Subject matter, duration, nature and purpose of processing

Subject matter: tunneling network traffic between the Controller's infrastructure and the internet via a reverse SSH tunnel and the SmartHomeEntry relay server.

Duration: for the duration of the Controller's subscription to SmartHomeEntry.

Nature: technical - the Processor is a "mere conduit" within the meaning of the DSA. It does not initiate the transmission, does not select the recipient, and does not modify the content.

Purpose: enabling the Controller to remotely access IT services (Home Assistant, Nextcloud, Jellyfin, NAS, etc.) hosted in the infrastructure of the Controller's end clients.

3. Types of personal data and categories of data subjects

The Processor processes the following categories of personal data on behalf of the Controller:

Technical metadata (processed by the Processor): device IP addresses, connection timestamps, transfer size (bandwidth), subdomain names, tunnel identifiers.

Tunneled data (transparent to the Processor): any data transmitted through the SSH tunnel by the Controller - including potentially personal data of end clients (e.g. CCTV camera footage, audio recordings, smart home automations, files in Nextcloud).

Categories of data subjects: end clients of the Controller, members of their families, guests visiting their homes, possibly employees/subcontractors of the Controller.

The Processor does not decrypt, log, or analyze the content of the tunnel. Only the Controller and their authorized end clients have access to the content.

4. Controller's obligations

  • Maintaining a valid legal basis for processing personal data through the tunnel (end client consent, processing agreement, legitimate interest).
  • Informing end clients about entrusting the processing of their data to the Processor (SmartHomeEntry) and providing them with this DPA on request.
  • Ensuring that the configuration of services exposed via the tunnel complies with applicable regulations (GDPR, ePrivacy, national rules).
  • Not exposing through the tunnel services that require special consent (e.g. video recordings without the consent of those recorded).

5. Processor's obligations (GDPR Art. 28(3))

  • Processing personal data only on documented instructions from the Controller (Terms + DPA + account panel settings).
  • Ensuring confidentiality - the Processor's employees and subcontractors are bound by a duty of confidentiality.
  • Implementing appropriate technical and organizational measures in accordance with GDPR Art. 32 (SSH encryption, network isolation, RLS in the database, audit logs).
  • Using sub-processors only in accordance with section 6 of this DPA.
  • Assisting the Controller in fulfilling data subjects' rights (access, rectification, erasure, portability) to the extent of the metadata held by the Processor.
  • Notifying the Controller of a personal data breach within no more than 48 hours of detection.
  • Returning or deleting personal data after the end of service provision (section 9).
  • Making available to the Controller the information necessary to demonstrate compliance and enabling audits (section 8).

6. Sub-processors

The Controller grants general consent for the Processor to use the following sub-processors (category of data transferred in brackets):

  • Stripe, Inc. (payments, invoices) - Ireland/USA, Standard Contractual Clauses
  • Resend (transactional email) - EU
  • Supabase (database, authentication) - Frankfurt, EU
  • OVH Sp. z o.o. (application and relay hosting) - Warsaw, EU
  • PostHog (analytics, opt-in) - Frankfurt, EU
  • Cloudflare, Inc. (DNS, CDN, attack protection; terminates TLS for tunnel subdomains, therefore processes traffic passing through to your server) - USA/global, Standard Contractual Clauses

The Processor will notify the Controller by email of a planned change to the list of sub-processors with 30 days' notice. The Controller may raise a reasoned objection - in which case the Processor will propose an alternative solution or the Controller may terminate the agreement.

The Processor is responsible for the actions of sub-processors as for its own actions.

7. International transfers

The Processor's main infrastructure is located in the European Union (Warsaw). Transfers to the USA (Stripe) take place on the basis of Standard Contractual Clauses (SCC) approved by the European Commission and additional safeguards (Schrems II compliance). The Processor does not transfer personal data to third countries not designated as safe without SCC.

8. Security measures (Annex I)

The Processor implements and maintains the following technical and organizational measures:

Encryption: SSH (OpenSSH ≥ 8.0) for tunnels, TLS 1.2+ for HTTPS, bcrypt/argon2 for passwords, AES-256 at rest for Supabase databases.

Access control: Row-Level Security (RLS) in PostgreSQL, MFA for the Processor's administrators, role-based access (admin/user).

Isolation: SSH tunnels bound to 127.0.0.1 on the relay, no public exposure of dynamic ports, nginx as the sole public entrypoint.

Monitoring: immutable audit logs (insert-only), bandwidth anomaly detection, 24/7 alerts for critical incidents.

Backup: daily database snapshots with 30-day retention, encrypted at rest, restore tests quarterly.

Incident response: 4h for critical (CSAM, breach), 24h for high (malware), 24/7 on-call team.

The Controller may request audit documentation (SOC2/ISO27001-compatible) once a year, free of charge. On-site audits - at the Controller's expense, with 30 days' notice, during business hours.

9. Return or deletion of data

Upon the end of service provision (subscription cancellation, account ban) the Processor, within 30 days: deletes all personal data of the Controller from production databases; deletes tunnel metadata; retains only data required by law (invoices - 5 years pursuant to the Polish Accounting Act, metadata logs - 12 months pursuant to Polish telecommunications law). Backups expire naturally on day 30 after deletion from production.

10. Personal data breaches

The Processor will notify the Controller of a breach within no more than 48 hours of detection. The notification includes: the nature of the breach, the categories and approximate number of persons affected, the categories of data, the likely consequences, and the remedial measures taken. The Controller is responsible for reporting to the supervisory authority (Polish DPA (UODO)) within 72 hours and for informing data subjects where required.

11. Liability

The Processor's total liability towards the Controller for breach of the DPA is limited to the amount of fees paid by the Controller for the last 12 months of service provision. The limitation does not apply to wilful breaches or gross negligence. Each party bears its own liability towards supervisory authorities and data subjects for breaches attributable to it.

12. Termination

The DPA terminates upon the end of service provision to the Controller. Provisions on confidentiality, return/deletion of data, and liability remain in force after termination of the DPA.

13. Governing law and jurisdiction

This DPA is governed by Polish law and the GDPR. Competent court: the court competent for the Processor's registered office. Disputes may also be referred to mediation before the supervisory authorities (Polish DPA (UODO)).

14. Contact

Questions regarding the DPA, inspections, breach notifications - Processor's DPO: [email protected]

    Data Processing Agreement (DPA) | SmartHomeEntry