Last updated: August 15, 2026
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between you ("Customer", the controller) and DefoAI UG (haftungsbeschränkt) ("Growomat", "we", the processor). You accept this DPA when you accept the Terms; no separate signature is required. It applies to every customer on every plan.
For personal data you send to the Service, or which the Service collects on your instructions, you are the controller and we are the processor. This includes, in particular, the conversion and customer data you send us for advertising measurement, and the data we retrieve from advertising platforms on your behalf.
For our own account, billing and security data we are the controller, and that processing is described in our Privacy Policy rather than here.
This DPA is written to satisfy Article 28 of the EU General Data Protection Regulation and of the UK GDPR as retained in UK law. Where this DPA and the Terms conflict on data protection, this DPA prevails.
We do not require or want special categories of personal data (Article 9) and you must not send them to the Service.
You give general authorization for us to engage the sub-processors listed below. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain liable to you for their performance.
We will give at least 30 days' notice, by email to your account address, before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate the affected part of the Service without penalty for the remainder of your paid term.
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting, edge compute, bot protection | EU / global edge | Standard Contractual Clauses / UK Addendum |
| Upstash, Inc. | Database (primary data store) | Ireland (EU) | Within EEA |
| Google (Firebase) | Authentication and analytics | USA | Standard Contractual Clauses / UK Addendum |
| Stripe, Inc. | Payment processing and billing records | USA | Standard Contractual Clauses / UK Addendum |
| EdenAI SAS | Routing of text and image generation requests | France (EU) | Within EEA |
| OpenAI, L.L.C. | Text generation, reached via EdenAI | USA | Standard Contractual Clauses / UK Addendum |
| Twilio Inc. | SMS delivery for phone verification | USA | Standard Contractual Clauses / UK Addendum |
| SendGrid (Twilio) | Transactional and reporting email delivery | USA | Standard Contractual Clauses / UK Addendum |
| Google Cloud Storage | Storage of images and creative assets you upload | EU / USA | Standard Contractual Clauses / UK Addendum |
| Google Places API | Business address lookup, where you use it | USA | Standard Contractual Clauses / UK Addendum |
| Datadog, Inc. | Application logging and monitoring | EU (datadoghq.eu) | Within EEA |
The advertising platforms you choose to connect — Google Ads, Microsoft Advertising, Meta Ads and Reddit Ads — are not our sub-processors. You have your own relationship and your own terms with each of them, and when the Service sends data to a platform on your instruction, that platform acts as an independent controller or as your processor under your agreement with it, not under this DPA.
Where a sub-processor listed above processes personal data outside the EEA or the UK, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the UK Information Commissioner's International Data Transfer Addendum where UK data is involved, and supplemented by the technical measures in section 6.
On reasonable written request, and no more than once in any twelve-month period unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate compliance with this DPA. Where an on-site audit is legally required, the parties will agree its scope and timing in advance, and you will bear its cost unless it reveals a material breach by us.
You may export your data from the Service at any time. On termination, we delete or return personal data processed on your behalf within 90 days, except where retention is required by law — for example billing records — in which case we retain only what the law requires and continue to protect it under this DPA.
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on your behalf, and will provide the information you need for your own notification obligations as it becomes available.
The limitations of liability in the Terms apply to this DPA, except where applicable data protection law does not permit them to.
Data protection enquiries, including sub-processor objections and audit requests:
DefoAI UG (haftungsbeschränkt)
Wiltinger Straße 11
13465 Berlin, Germany
[email protected]