Data Processing Agreement
Effective date: 27 July 2026 · Last updated: 27 July 2026
This Data Processing Agreement (DPA) forms part of the contract between the customer and the operator of the BackProve service where the customer processes personal data through the service.
1. Parties
Processor: Jan Brožíček · IČO 08764832 · Rižská 1492/2, 102 00 Prague, Czech Republic · legal@backprove.com — the "Processor" or "BackProve".
Controller: the BackProve customer who uses the service to back up their database or files — the "Controller" or "Customer".
Where the Customer itself acts as a processor for another controller, this agreement applies accordingly so that the Customer can meet its obligations towards its own controller.
2. Subject of the agreement
This agreement governs the processing of personal data that may be contained in the Customer's databases, files, storage, or other data processed through the BackProve service.
BackProve processes personal data only to provide the service — in particular creating encrypted backups, storing backups, verifying restorability, alerting on failure, deleting data under retention, and assisted restore.
3. Duration of processing
Processing lasts for the duration of the contractual relationship between the Customer and BackProve.
After the contractual relationship ends, personal data contained in the Customer's backups will be deleted or returned according to the Customer's instructions, the service's retention policy, and BackProve's legal obligations. Specifically, after the paid period ends, data is retained for 30 days and then permanently deleted, unless the Customer requests earlier deletion or the law requires otherwise.
4. Nature and purpose of processing
The nature of the processing comprises automated technical operations on the Customer's data, in particular:
- accessing the Customer's source database and files;
- creating a backup;
- encrypting the backup;
- storing the encrypted backup;
- checking integrity and restorability;
- recording the result of the backup or restore test;
- sending operational alerts;
- deleting older backups under retention;
- assisted restore at the Customer's explicit request.
The purpose of processing is the provision of the BackProve service.
5. Categories of personal data
BackProve does not determine or actively monitor the content of Customer data. Customer data may contain any personal data the Customer stores in its database or file storage, in particular identification data, contact data, end-user accounts, end-user-generated content, technical data, and transactional or operational data.
The Customer is responsible for ensuring it does not process, through the service, categories of data requiring a special contractual, regulatory, or security regime, unless such a regime was agreed with BackProve in writing in advance.
6. Categories of data subjects
Processing may concern in particular the Customer's end users, the Customer's customers, the Customer's employees or collaborators, the Customer's suppliers, and other persons whose data the Customer stores in its database or files.
7. Controller's instructions
BackProve processes personal data only on the Customer's documented instructions. Instructions include in particular the Customer's configuration of the service, connecting the Customer's database and storage, choice of retention policy, starting or configuring backups, requesting assisted restore, requesting deletion/export/termination, and these Terms and this DPA.
BackProve performs no analytics, marketing, AI-training, or profiling operations of its own on Customer data.
8. BackProve's obligations
BackProve undertakes to:
- process personal data only on the Customer's instructions;
- ensure that persons authorised to process personal data are bound by confidentiality;
- adopt appropriate technical and organisational measures;
- engage further processors only in accordance with this agreement;
- assist the Customer in meeting its GDPR obligations to a reasonable extent;
- notify the Customer of a personal-data breach without undue delay after becoming aware of it;
- on termination of processing, delete or return personal data per the Customer's instructions, unless the law requires further retention;
- provide the Customer with information needed to demonstrate compliance with this agreement.
9. Customer's obligations
The Customer undertakes to:
- ensure the lawfulness of processing personal data in its database and files;
- have a legal basis for processing the personal data backed up through BackProve;
- inform data subjects of the processing where required;
- provide BackProve only necessary and proportionate access;
- use read-only access where technically possible;
- not use BackProve for unlawful processing;
- not give BackProve access to data whose processing is incompatible with these terms;
- handle data-subject requests where they concern the content of Customer data.
10. Technical and organisational measures
BackProve uses in particular:
- encryption of backups from the moment of creation;
- encrypted storage of the Customer's infrastructure access credentials;
- authenticated AES-256-GCM encryption of stored secrets;
- storage of backups in the European Union;
- separation of the public web application from the internal component that can access backup storage;
- restriction of administrator access;
- no ability to display stored Customer secrets in the administration in plain form;
- monitoring of backup and verification failures, with alerts to Customer and operator;
- encrypted backup of BackProve's own application database;
- deletion of backups under the retention policy.
BackProve technically holds the encryption keys necessary to provide the service. The service is not zero-knowledge or end-to-end encrypted in the sense that the Customer alone would hold the keys.
11. Access to the customer's production database
For backups, BackProve uses access to the Customer's production database only for reading and creating backups. BackProve does not write to, edit, or delete the Customer's production database.
The exception is assisted restore at the Customer's explicit request. In that case BackProve may write data into a new, empty project or environment designated by the Customer. If the target project is not empty, the service may refuse the restore.
Access credentials for the target project used for assisted restore are encrypted, used once, and then permanently deleted. They are not logged or retained in plain form.
12. Further processors
The Customer grants BackProve general authorisation to engage further processors necessary to provide the service. A current list of sub-processors is available at backprove.com/sub-processors. As at the last update, the following are engaged in particular:
- Hetzner Online GmbH — hosting and backup storage, Germany / EU;
- Resend — sending transactional and operational emails;
- Stripe — payment services and subscription management, where it processes personal data in connection with the service.
BackProve will ensure that further processors are bound by obligations corresponding to this agreement. BackProve will inform the Customer of an intended change of sub-processor by a reasonable means, such as updating the sub-processor list or by email. The Customer may object to a change on data-protection grounds.
13. Transfers outside the EEA
Customer backups are stored on infrastructure in the European Union.
If a further processor processes personal data outside the European Economic Area, BackProve will ensure an appropriate transfer mechanism, such as an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, standard contractual clauses, or another GDPR mechanism. BackProve will use supplementary measures where required and will not intentionally transfer Customer backup artifacts outside EU-based storage unless instructed by the Customer or required by law.
14. Personal-data breach
BackProve will notify the Customer of a personal-data breach without undue delay after becoming aware of it. The notification will contain the available information about the nature of the incident, the data affected, likely consequences, and measures taken or proposed.
The Customer is responsible for assessing whether the incident must be reported to the supervisory authority or to data subjects, where it is the controller of the data affected.
15. Assistance
BackProve will provide the Customer with reasonable assistance with data-subject requests, data-protection impact assessments, communication with the supervisory authority, resolving security incidents, and exporting or deleting data. Assistance may be charged where it exceeds the ordinary scope of support or requires extraordinary technical or legal effort.
16. Audits
BackProve will provide the Customer with information necessary to demonstrate compliance with this agreement, in particular in the form of security documentation, a description of technical and organisational measures, the list of sub-processors, and answers to reasonable security questions.
A physical or technical audit is possible only by prior agreement, to a reasonable extent, under conditions protecting the security of the service, trade secrets, and the data of other customers.
17. Deletion or return of data
After the service ends, BackProve will, at the Customer's request, delete or make available for export the Customer's data, where technically possible and where the law does not require further retention.
Automatic backups are deleted under the retention policy. Deletion covers database records, encrypted artifacts in storage, and related files where under BackProve's control. Under the 30-day retention model, all Customer backup data and stored credentials are permanently deleted 30 days after the paid period ends unless earlier deletion is requested.
18. Data Act and portability
Where obligations under laws on data access, portability, or switching of data-processing services apply to the service, BackProve will not impose unreasonable contractual, commercial, technical, or organisational obstacles to switching, export, or deletion of exportable data.
To the extent required by applicable law, BackProve will enable the Customer to export Customer data and reasonably available metadata generated by the Customer's use of the service, provide reasonable switching assistance, and maintain continuity during the applicable switching period. Specific export capabilities, formats, and limitations are described in the service or documentation.
BackProve may exclude data that is not exportable under applicable law, including provider trade secrets or data specific to the internal functioning of the service, where such exclusion is permitted and does not unlawfully impede switching.
19. Duration of the agreement
This DPA lasts for as long as BackProve processes the Customer's personal data. Provisions on confidentiality, security, liability, and deletion survive termination where their nature so requires.
20. Final provisions
This agreement is governed by the law of the Czech Republic. In the event of conflict between this DPA and the Terms of Service, this DPA prevails in matters of personal-data processing. Contact for data-protection matters: legal@backprove.com.