Data Processing Agreement

Last updated: September 2026

1. Scope and roles

This Data Processing Agreement applies when you use Embarko to run an app that handles personal data and you are subject to data protection law such as the UK GDPR or EU GDPR. In that arrangement you are the data controller and Embarko is your processor. It takes effect when you deploy such an app; no separate signature is needed.

Where the account belongs to a company, the company is the controller and its members act on its behalf. This DPA sits alongside our Terms of Service and Privacy Policy; if they conflict on the processing of personal data, this document wins. Embarko is operated by [legal entity name and registered address].

2. What we process, and why

Embarko runs the app you deploy. Any personal data inside it is processed only to provide that service:

  • App source and configuration — the archive you deploy, plus environment variables and secrets, stored so the app can be built and run.
  • App runtime data — whatever your app writes to its database or file storage while running. We store it, serve it back to your app, and include it in backups on the plans that have them.
  • Request metadata — paths, referrers, coarse geography, status codes, and user agent classes for requests to your live app, processed for your analytics and for abuse prevention and reliability.
  • Logs — build output and your app's own runtime output, retained for debugging for [retention window].
  • Account and membership data — the email addresses, roles, and join records of the people in your company, processed to operate access control.

We do not read, index, or analyse the contents of your app's data beyond what running, backing up, and serving it requires, and we do not use it to train AI models.

3. Duration and deletion

  • We process personal data for as long as your app exists on Embarko.
  • Deleting an app permanently removes its running instance, its stored data, and its backups. Deleting a company does the same for all of its apps.
  • Closing an account deletes its apps and their data within [deletion window]; backups age out within [backup window].
  • We delete or return personal data on your written instruction, subject to any legal retention duty.

4. Your responsibilities as controller

  • Having a lawful basis for the personal data your app processes.
  • Giving your own privacy notice to the people whose data your app holds.
  • Assessing the risk before putting special category data — health, financial, biometric, data about children — into an app you run here.
  • Configuring your app's own access controls correctly, and keeping your deploy tokens and secrets safe.
  • Deleting apps and data once you no longer need them.

5. Our obligations as processor

  • We process personal data only on your documented instructions — which, in practice, means running, serving, and backing up the app you deployed.
  • We do not sell it and we do not use it for our own purposes.
  • Our staff and contractors are bound by confidentiality obligations.
  • We maintain the technical and organisational measures in section 6.
  • We notify you without undue delay, and in any event within 72 hours, once we become aware of a personal data breach affecting your data, with what we know at the time.
  • We help you respond to data subject requests and to regulators where the information is within our control, and we make the information in this DPA available for your audits and assessments. Further audit rights: [audit terms, if any].

6. Security measures

  • All traffic is served over HTTPS, on both *.app.embarko.ai and connected custom domains.
  • Data is encrypted in transit, and encrypted at rest by our storage provider.
  • Environment variables and app secrets are encrypted at rest under a separate key.
  • Deploy tokens are stored hashed, are scoped to one company, and can be revoked individually.
  • Each app runs isolated from every other app, with its own persistent storage.
  • Access to production infrastructure is restricted to the people who need it and is logged.

Our security page describes these controls in more detail.

7. Sub-processors

We use the providers below to deliver Embarko. Each is bound by data processing terms with us. We will give you [notice period] notice before adding or replacing one, and you may object on reasonable data protection grounds.

Sub-processorPurposeLocation
MSG91Sign-in — one-time code delivery and verificationIndia
StripeCard payments and stored payment methodsUnited States
LagoSubscription and usage metering[region]
Google (Tag Manager)Website and console analyticsUnited States
[compute provider]Running and building customer apps[region]
[storage provider]App file storage and backups[region]
[email provider]Transactional email[region]

8. International transfers

Where personal data leaves the region it was collected in, we rely on [transfer mechanism — e.g. Standard Contractual Clauses and the UK Addendum], together with the measures in section 6.

9. Changes and contact

We update this DPA as the service changes, and the date at the top of the page changes with it. For questions, a signed copy, or a security review, email hello@embarko.ai.