← All legal documents

Data processing agreement

How Getyn processes personal data on your behalf, for customers who need a DPA for GDPR or UK GDPR compliance.

Last updated 19 July 2026

This is a working draft published for transparency. It has not yet completed legal review, so it should not be relied on as final contractual terms. Questions: legal@getyn.com.

This agreement applies where you use Getyn to process personal data and, in doing so, act as a controller while Getyn acts as your processor. It forms part of our general terms.

If you need a countersigned copy, or your own paper, contact legal@getyn.com.

1Roles

You are the controller of personal data you or your end users put into projects you build — the contents of a provisioned database, form submissions on a published site, and similar. You decide why and how it is processed.

Getyn is the processor of that data and acts on your documented instructions, which include your use of the product's features.

Separately, Getyn is a controller of your own account data — your name, email, billing details and usage records — which is covered by our privacy policy rather than this agreement.

2Scope of processing

Subject matter: provision of the Getyn Builder platform. Duration: for as long as your account is active, plus any retention period set out below.

  • Nature and purpose: hosting, storing, transmitting and displaying data so your projects function
  • Types of data: whatever you choose to put in. Typically account identifiers, contact details and application records
  • Categories of data subject: your end users, staff and customers

3Our obligations

Getyn will:

  • Process personal data only on your documented instructions, unless required otherwise by law — in which case we will tell you before processing, where we are permitted to
  • Ensure people authorised to process the data are bound by confidentiality
  • Implement appropriate technical and organisational security measures, including encryption in transit and at rest, row-level access controls, and least-privilege internal access
  • Assist you, taking account of the nature of processing, in responding to data subject requests and in meeting your obligations around security, breach notification and impact assessments
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data
  • Delete or return personal data at the end of the service, except where we must retain it by law
  • Make available the information needed to demonstrate compliance and allow for audits, on reasonable notice and subject to confidentiality

4Sub-processors

You give general authorisation for Getyn to engage sub-processors for hosting, database provisioning, email delivery, payment processing and error monitoring. We impose data protection terms on each one that are no less protective than these.

We will give you notice of any intended change to our sub-processors, and you may object on reasonable data protection grounds.

5International transfers

Where personal data is transferred out of the EEA or the UK to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses, together with the UK Addendum where the UK GDPR applies.

6Your obligations

You are responsible for having a lawful basis for the data you put into Getyn, for providing any required privacy notices to your end users, and for not uploading special-category data without appropriate safeguards in place.