Data Processing Addendum
Last updated: 11 July 2026
Template for the MVP — not legal advice and not a signed agreement. Have counsel review and execute a binding DPA before relying on it in production.
1. Parties & roles
This Addendum forms part of the agreement between you (the “Controller”) and Zentrum24 LLC (the “Processor”, operating the SterileAtlas platform) where Zentrum24 LLC processes personal data on your behalf. Where Zentrum24 LLC determines the purposes and means of processing (e.g., its own account and security data), it acts as a controller — see the Privacy Policy.
2. Scope & instructions
Zentrum24 LLC processes personal data only to provide the Platform and on your documented instructions, including as set out in the Terms and Privacy Policy, unless required otherwise by law.
3. Confidentiality & security
Personnel authorized to process personal data are bound by confidentiality. We maintain technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and an audit trail of security-relevant actions.
4. Subprocessors
You authorize Zentrum24 LLC to engage the subprocessors below to run the Platform. Each is engaged under terms consistent with this Addendum. We will give reasonable notice of any intended addition or replacement so you can object.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Application hosting & CDN | Hosts and serves the Platform | Account & content data, request metadata | US / EU |
| Managed PostgreSQL database | Primary datastore for account & content data | Account & content data | US / EU |
| Supabase (object storage) | Stores uploaded files, documents & media | User-uploaded files & metadata | US / EU |
| Resend (email delivery) | Sends transactional email (verification, resets, notifications) | Email address, name, message content | US |
| Stripe (payments) | Processes subscription & payment transactions | Billing contact, payment token (card data handled by Stripe, not us) | US / EU |
[TODO: confirm the exact hosting and database vendors and their processing regions, and execute a signed DPA with each subprocessor before production.]
5. International transfers
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
6. Data subject requests & assistance
Taking into account the nature of processing, we assist you with data subject requests and with your obligations around security, breach notification, and data protection impact assessments.
7. Deletion & return
On termination, we delete or return personal data processed on your behalf, except where retention is required by law, then delete or anonymize it within a reasonable period.
8. Audits
We make available information reasonably necessary to demonstrate compliance with this Addendum and, on reasonable request and notice, allow for audits subject to confidentiality.
9. Contact
Data protection enquiries: privacy@zentrum24.com.