Legal

Data Processing Agreement

Version 1.0 · Effective 8 September 2025

This Data Processing Agreement ("DPA") forms part of, and is subject to, the AirStrings Terms of Service (the "Agreement") between Symbionix SL (Sociedad Limitada, CIF B-22937023, registered office Carrer de Pere IV 182, 08005 Barcelona, Spain) ("AirStrings", "Processor") and the customer identified in the Agreement ("Customer", "Controller"). It governs the processing of Personal Data by AirStrings on the Customer's behalf in connection with the Service.

Acceptance / deemed signature. By accepting the Agreement (by click-through or use of the Service), the Customer accepts this DPA on behalf of itself and, where applicable, its affiliates. No separate signature is required; acceptance of the Agreement has the same effect as signing this DPA and the Standard Contractual Clauses incorporated by reference in Section 8, and the parties are deemed to have signed the Annexes to those Clauses. If the individual accepting lacks authority to bind the Customer, this DPA is not valid.

Capitalized terms not defined here have the meaning given in the Agreement or in the GDPR.


1. Definitions

1.1 "GDPR" means Regulation (EU) 2016/679.

1.2 "Data Protection Law" means the GDPR and Spanish data-protection law (LOPDGDD), and any other applicable data-protection or privacy law.

1.3 "Personal Data", "processing", "controller", "processor", "data subject", "supervisory authority", and "personal data breach" have the meanings in the GDPR.

1.4 "Customer Personal Data" means Personal Data contained in Customer Content or otherwise processed by AirStrings on the Customer's behalf under the Agreement, as described in Annex I.

1.5 "Subprocessor" means a third party engaged by AirStrings to process Customer Personal Data.

1.6 "SCCs" means the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914.


2. Roles and scope

2.1 The Customer is the controller (or a processor acting on behalf of its own controller(s)) of Customer Personal Data. AirStrings is the processor (or sub-processor, respectively).

2.2 AirStrings processes Customer Personal Data only on the Customer's documented instructions, including as set out in the Agreement, this DPA, and the Customer's use of the Service, and as described in Annex I. AirStrings will inform the Customer if, in its opinion, an instruction infringes Data Protection Law (without obligation to actively monitor the Customer's compliance).

2.3 The Customer is responsible for the lawfulness of Customer Personal Data and of its instructions, including having a valid legal basis and providing required notices to data subjects. The Customer warrants that its instructions and the content it uploads comply with Data Protection Law.

2.4 AirStrings acts as an independent controller for account, billing, security, and aggregated/anonymized usage data as described in the Privacy Policy; that data is outside the scope of this DPA.


3. Processor obligations

AirStrings will:

3.1 process Customer Personal Data only per Section 2.2 and applicable law, and not for its own purposes;

3.2 ensure persons authorized to process Customer Personal Data are bound by confidentiality;

3.3 implement and maintain the technical and organizational measures described in Annex II (Art. 32 GDPR);

3.4 respect the conditions in Section 5 for engaging Subprocessors;

3.5 taking into account the nature of the processing, assist the Customer by appropriate measures, insofar as possible, to respond to data-subject requests (Chapter III GDPR) — see Section 6;

3.6 assist the Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to AirStrings;

3.7 at the Customer's choice, delete or return Customer Personal Data at the end of the provision of services, and delete existing copies, except where storage is required by EU or Member-State law — see Section 9; and

3.8 make available to the Customer information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as set out in Section 7.


4. Security and breach notification

4.1 AirStrings implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as set out in Annex II, and reviews them periodically.

4.2 Breach notification. AirStrings will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware of it. The notification will describe, to the extent known, the nature of the breach, likely consequences, and the measures taken or proposed, and will be supplemented as more information becomes available. AirStrings will reasonably assist the Customer with the Customer's own notification obligations under Articles 33–34 GDPR. Notification is not an acknowledgement of fault.


5. Subprocessors

5.1 General authorization. The Customer gives general written authorization for AirStrings to engage Subprocessors, within the categories described in Annex III, to process Customer Personal Data. The current list of Subprocessors, including the specific provider names, is available to the Customer on request at support@airstrings.com.

5.2 Flow-down. AirStrings will impose on each Subprocessor, by written contract, data-protection obligations that are substantially the same as those in this DPA (in particular the SCC obligations where relevant), and remains liable to the Customer for the Subprocessor's performance.

5.3 Change notice and objection. AirStrings will give the Customer at least 30 days' prior notice of the addition or replacement of a Subprocessor (by email and/or another notice mechanism we designate). The Customer may object on reasonable data-protection grounds within 30 days of the notice. The parties will work in good faith to resolve the objection. If it cannot be resolved, the Customer may, as its sole and exclusive remedy, terminate the affected part of the Service, and AirStrings will refund any prepaid, unused fees for the terminated portion.


6. Data-subject requests

6.1 Taking into account the nature of the processing, AirStrings will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to data-subject requests. Where AirStrings receives a request directly from a data subject relating to Customer Personal Data, it will not respond to the request itself (other than to direct the data subject to the Customer where appropriate) but will, without undue delay, notify the Customer, unless legally prohibited.


7. Audits

7.1 AirStrings will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR. This obligation is satisfied primarily by AirStrings providing relevant documentation and, where available, third-party audit reports or certifications on request.

7.2 Where such information is insufficient to demonstrate compliance, or following a personal data breach, the Customer may conduct an audit. On-site audits are limited to once per 12-month period, require at least four weeks' prior written notice, must be conducted during business hours without unreasonably disrupting AirStrings' operations, are subject to confidentiality, and are at the Customer's cost. AirStrings may require that a mutually agreed independent third party conduct the audit.


8. International transfers

8.1 The Customer authorizes AirStrings to transfer Customer Personal Data outside the EEA where necessary to provide the Service, subject to appropriate safeguards under Chapter V GDPR.

8.2 SCCs. Where AirStrings transfers Customer Personal Data from the EEA to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:

  • Module Two (controller-to-processor) applies where the Customer is a controller of the Customer Personal Data; and
  • Module Three (processor-to-processor) applies where the Customer is itself a processor acting on behalf of a third-party controller.

For the purposes of the SCCs:

  • (a) the Customer is the "data exporter" and AirStrings is the "data importer";
  • (b) the optional docking clause (Clause 7) does not apply;
  • (c) under Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 5.3;
  • (d) under Clause 11, the optional independent-dispute-resolution language does not apply;
  • (e) under Clause 17 (Option 1), the SCCs are governed by the law of Spain;
  • (f) under Clause 18, disputes are resolved before the courts of Spain (Barcelona);
  • (g) the competent supervisory authority is the Agencia Española de Protección de Datos (AEPD);
  • (h) Annex I.A/B is populated by Annex I of this DPA; Annex II of the SCCs is populated by Annex II of this DPA; and the list of Subprocessors in Annex III serves as the Clause 9 list.

8.3 Where AirStrings relies on a Subprocessor's own transfer safeguards (its SCCs and/or EU–US Data Privacy Framework certification) for onward transfers, those safeguards apply in addition to this Section, as described in the current Subprocessor list available to the Customer on request.

8.4 If the SCCs are invalidated or superseded, the parties will work in good faith to implement an alternative lawful transfer mechanism.


9. Return and deletion

9.1 On termination or expiry of the Agreement, AirStrings will, at the Customer's choice, make Customer Personal Data available for export for a 30-day Retention Window and then delete it from active systems, and will purge it from backups on AirStrings' normal backup-expiry cycle, except to the extent storage is required by EU or Member-State law. On request, AirStrings will confirm deletion in writing.


10. Liability and general

10.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, to the extent permitted by Data Protection Law. Nothing in the Agreement limits liability that cannot be limited under Data Protection Law.

10.2 This DPA is governed by the laws of Spain, with the courts of Barcelona having jurisdiction, consistent with the Agreement.

10.3 In case of conflict between this DPA and the Agreement on the processing of Personal Data, this DPA prevails. In case of conflict between this DPA and the SCCs, the SCCs prevail.

10.4 This DPA remains in effect for as long as AirStrings processes Customer Personal Data.


Annex I — Description of processing

A. List of parties

  • Data exporter / controller: the Customer (as identified in the Agreement account), acting as controller or as processor on behalf of its own controller(s). Contact: the Customer's account/admin contact.
  • Data importer / processor: Symbionix SL, Carrer de Pere IV 182, 08005 Barcelona, Spain. Contact: support@airstrings.com.

B. Nature and purpose of processing. Hosting, storage, transmission, caching, signing (Ed25519), bundling, and CDN delivery of Customer Content, and provision of the AirStrings string-management and localization Service (dashboard, API, SDK delivery), including related support and security.

C. Duration. For the term of the Agreement, plus the 30-day Retention Window and backup-expiry cycle described in Section 9.

D. Categories of data subjects. The Customer's authorized users and administrators; and any individuals whose Personal Data the Customer chooses to include in Customer Content (the Service is not intended to store personal data as content — see Terms §5.5).

E. Categories of Personal Data. Account and authentication data of the Customer's users (names, work emails, roles, API-key metadata, IP addresses, logs); and any Personal Data the Customer chooses to place in Customer Content (strings/locale data are not intended to contain Personal Data).

F. Special categories. None intended or expected. The Customer must not include special-category data in Customer Content.

G. Frequency. Continuous, for the duration of the Service.

H. Retention. As described in Section 9 and the Privacy Policy.


Annex II — Technical and organizational measures (TOMs)

AirStrings maintains the following measures (Art. 32 GDPR), reviewed periodically and updated as the Service evolves:

1. Encryption. TLS 1.2+ for data in transit; encryption at rest for stored data and object storage (signed bundles). Passwords hashed with bcrypt; API keys stored hashed. 2. Integrity of delivery. All delivered bundles are signed with Ed25519; SDKs verify signatures, and verification failure is a hard error — protecting content integrity and authenticity end to end. 3. Access control. Role-based, least-privilege access to production systems; unique accounts; multi-factor authentication for administrative access; access is reviewed periodically and revoked within 24 hours of a staff member's departure or role change. 4. Network & tenant isolation. Logical isolation between customers/tenants; production access restricted and segregated from other environments. 5. Secrets management. Secrets held in environment variables or a secrets manager, never in source code, logs, or error messages. 6. Logging & monitoring. Structured security and access logging with correlation IDs; monitoring and alerting for anomalous activity. 7. Secure development. Version-controlled, reviewed changes; pinned and verified dependencies; no dependency with known critical/high vulnerabilities; validation of external input at trust boundaries. 8. Resilience & backups. Regular backups of metadata with a defined expiry cycle; recovery procedures. 9. Incident response. Documented incident-response process, including breach assessment and the 48-hour customer-notification commitment in Section 4.2. 10. Vendor management. Subprocessors bound by written data-protection terms with obligations substantially equivalent to this DPA. 11. Data minimization by design. The Service is designed for application strings, not personal data; customers are instructed not to include personal data in Customer Content.


Annex III — Subprocessors

AirStrings engages Subprocessors within the following categories to process Customer Personal Data:

CategoryPurposeLocationTransfer mechanism
Application hosting / computeRunning the AirStrings backendEU / United StatesSCCs (adequacy where applicable)
Managed databaseStoring Service metadataEU / United StatesSCCs (adequacy where applicable)
CDN + object storageDelivery and storage of signed bundlesEU / United States (global edge)SCCs (adequacy where applicable)
Payment processingSubscriptions, invoicing, taxEU / United StatesSCCs (adequacy where applicable)
Transactional emailAccount, security, and team notificationsEU / United StatesSCCs (adequacy where applicable)

The current list of Subprocessors, including the specific provider names and the transfer mechanism relied on for each, is available to the Customer on request at support@airstrings.com and serves as the Clause 9 list referenced in Section 8.2.