Skip to content

Legal

Data Processing Agreement

Last updated: July 17, 2026

This Data Processing Agreement (DPA) forms part of our Terms of Service and governs how we process personal data on your behalf. Questions, or need a countersigned copy? privacy@alreadyback.com.

Scope and roles

This DPA applies whenever AlreadyBack LLC, a Wyoming (USA) limited liability company, processes personal data on your behalf in the course of providing the Services. For that data you are the controller and AlreadyBack is the processor. It forms part of, and is governed by, our Terms of Service. For the personal data in your own account (your email, name, organization, billing status), we act as controller, as described in our Privacy Policy.

Definitions

Capitalized data-protection terms — controller, processor, personal data, data subject, sub-processor, and personal data breach — have the meanings given in the data-protection laws that apply to you: the EU and UK GDPR, the Swiss FADP, and US state privacy laws including the CCPA/CPRA.

What we process, and why

We process the personal data contained in the third-party services you connect (each a Connected Service — for example, Airtable) for one purpose: to perform the automated backups, verification, and restore operations you configure and request. Nothing else. We process on your documented instructions — your in-product configuration and these terms — for as long as your subscription is active, plus the retention and deletion periods described below.

Categories of data subjects and personal data

Data subjects: your employees, contractors, and customers, and anyone else whose personal data you store in a Connected Service.

Categories of personal data: whatever personal data you choose to store in the Connected Services you back up — typically contact details, professional and employment data, customer records, and transaction histories. The Services are not built for regulated high-sensitivity data: the categories we refuse (health data, data of children under 13 (or under 16 where EU law applies), biometric identifiers, regulated financial data, and consumer health data) are listed in our Terms of Service and must not be backed up through the Services.

Frequency and duration: processing is continuous while your subscription is active and ends after the return-and-deletion periods below. Together with “What we process, and why” above, this section forms the description of the processing (Annex I) for the EU Standard Contractual Clauses incorporated by reference in this DPA.

Our obligations as processor

  • Process personal data only on your documented instructions, including for transfers, unless the law requires otherwise — in which case we tell you first, where permitted.
  • Tell you if, in our opinion, an instruction infringes applicable data-protection law.
  • Ensure the people authorized to process your data are bound by confidentiality.
  • Implement and maintain the technical and organizational measures set out below.
  • Engage sub-processors only under the conditions below, and remain responsible for them.
  • Assist you — taking into account the nature of the processing — with data-subject requests, security, breach notification, data-protection impact assessments, and prior consultations.
  • Return or delete your data at the end of the relationship, as described below.
  • Make available the information you reasonably need to demonstrate compliance.

Technical and organizational measures

We implement and maintain measures appropriate to the risk, across the categories below. These measures constitute Annex II (technical and organizational measures) of the EU Standard Contractual Clauses incorporated by reference in this DPA. They are reviewed as the Services evolve and summarized on our Security page; additional security documentation — architecture, controls, and risk assessments — is available to enterprise customers under NDA.

Summary of technical and organizational measures
AreaMeasure
Encryption in transitTLS 1.3
Encryption at restAES-256-GCM, applied before storage
Key managementPer-organization keys; BYOK on eligible plans
StorageCertified provider, in your chosen region (US or EU)
Access controlRole-based, least-privilege, logged
MonitoringContinuous, with threat detection
RecoverabilityMonthly Fire Drill; per-snapshot integrity checks
VerificationReport on every backup and restore
Secure developmentImmutable releases, scanned before deployment
Secondary useNone — no profiling, sale, or AI/ML processing

In detail

  • Encryption in transit: TLS 1.3 for data moving between you, us, and the Connected Services.
  • Encryption at rest: every backup is encrypted with AES-256-GCM before it is written to storage, using keys unique to your organization, so storage providers only ever hold ciphertext. On eligible plans you can supply and control your own key (BYOK).
  • Certified storage: encrypted backups are stored with our storage provider — currently Cloudflare R2, an ISO/IEC 27001 and SOC 2 Type II certified provider — in the region you choose (United States or European Union). Our current storage providers are listed on our Sub-processors page.
  • Certified facilities: the compute for the Services runs in a data-center facility certified to ISO/IEC 27001:2022, operated by NTT Global Data Centers Americas.
  • Access control: strict, role-based access following the principle of least privilege; administrative access is restricted and logged; plaintext keys are never logged, cached, or persisted server-side.
  • Infrastructure and network security: layered network segmentation and access controls, continuous security monitoring, and threat detection.
  • Integrity and recoverability: regular encrypted backups with per-snapshot integrity checks, a monthly Fire Drill that verifies your latest snapshot is recoverable, and a verification report on every backup and restore.
  • Secure development: immutable, integrity-verified production releases, with vulnerability scanning before deployment.
  • No secondary use: we never mine, profile, sell, or advertise with your data, and no AI or machine-learning system ever processes it.

Sub-processors

You authorize us to engage the sub-processors listed at /sub-processors to help deliver the Services. For each one, we:

  • impose data-protection obligations at least as protective as this DPA;
  • remain fully responsible for their performance;
  • give you at least 30 days’ notice before adding or replacing one.

You may object to a new sub-processor on reasonable data-protection grounds. If we cannot offer a workable alternative, you may terminate the affected Services without penalty. This list, as updated from time to time, is Annex III (list of sub-processors) for the EU Standard Contractual Clauses incorporated by reference in this DPA.

International transfers

You choose where your encrypted backups are stored — the United States or the European Union — and they stay in the region you choose. Our processing infrastructure and your account data operate in the United States. Where personal data protected by EU/EEA, UK, or Swiss law is processed in the United States, we rely on the appropriate transfer mechanism — the EU Standard Contractual Clauses (Module 2 where you are a controller, or Module 3 where you are a processor), the UK Addendum to the EU SCCs (International Data Transfer Addendum), and the Swiss addendum where applicable — together with the technical measures above, encryption before storage chief among them.

US state privacy laws

Where you disclose to us personal information subject to the California Consumer Privacy Act (as amended by the CPRA) or a comparable US state privacy law, AlreadyBack acts as your service provider. We process that information solely to provide the Services on your behalf under this DPA and your instructions, and we do not:

  • sell or share it, or accept anything of value in exchange for it;
  • retain, use, or disclose it for any purpose other than providing the Services, except as the law permits;
  • retain, use, or disclose it outside our direct business relationship with you; or
  • combine it with personal information from other sources, except as needed to provide the Services or as the law allows.

We certify that we understand and will comply with these restrictions, and will tell you if we can no longer meet them.

Assisting you with data-subject rights

Taking into account the nature of the processing, we help you respond to requests from data subjects exercising their rights — access, rectification, erasure, restriction, portability, and objection — within the applicable legal deadlines. If a data subject contacts us directly about data we process on your behalf, we refer them to you rather than responding ourselves, unless you instruct otherwise.

Personal data breach

If we become aware of a personal data breach affecting the data we process for you, we notify you without undue delay — and within 24 hours of confirming it — with an update within 72 hours. Our notification describes the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We assist you with your own notifications to supervisory authorities (within 72 hours under GDPR Article 33) and to affected data subjects where the law requires it.

Audit and compliance

Once per year, on at least 30 days’ written notice, you may verify our compliance with this DPA. On request we provide our current security documentation and a completed security questionnaire; where that is not sufficient for your regulatory obligations, you may conduct an on-site audit — at your cost, and subject to our confidentiality and operational-safety rules. We contribute to audits carried out by you or an auditor you mandate.

Return and deletion

  • When your subscription ends, your backups remain available for export for 60 days.
  • After that window, your backups are deleted from storage.
  • Security and access logs expire on their normal retention cycle (typically 90 days).
  • We delete or return your data on your verified written request, and can provide written confirmation for your records.
  • Where applicable law requires us to keep specific records longer, we retain only what the law requires, for only as long as it requires, and then delete it.
  • Where you use a customer-held key (BYOK), reverting or revoking it cryptographically renders the corresponding backups unrecoverable.

Changes to this DPA

We may update this DPA as the Services and the law evolve. Material changes get at least 30 days’ notice by email and in-app before they take effect, and you may object on reasonable data-protection grounds, consistent with the sub-processor objection right above.

Liability and precedence

This DPA forms part of the Terms of Service, and the liability provisions of the Terms apply to it. If we sign a separate written agreement with your organization that conflicts with this DPA, that agreement prevails to the extent of the conflict.

Governing law

This DPA is governed by the laws of the State of Wyoming, USA, consistent with the governing-law and dispute-resolution terms of our Terms of Service. The EU Standard Contractual Clauses and the UK Addendum are governed by the law they each specify; Wyoming law governs the remainder of this DPA except where data-protection law requires otherwise.

Need procurement documents?

For enterprise evaluations we can provide a countersigned DPA, completed security questionnaires, and additional security documentation — architecture, controls, and risk assessments — under NDA. Email privacy@alreadyback.com.

Contact

Data-protection questions and requests under this DPA: privacy@alreadyback.com · AlreadyBack LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA.