This Data Processing Agreement (the "DPA") forms part of our Terms of Service and is entered into between you as customer (the "controller") and Melonslab, a trade name of Hypefox AB (org. no. 559570-6416), with its registered office at Hyllie Boulevard 34, 215 32 Malmö, Sweden (the "processor"). It implements Article 28(3) of the GDPR and applies whenever you store or process personal data on the Services. No signature is required — the DPA is accepted together with the Terms.
1. Roles and scope
For personal data contained in the content you store or process on the Services ("customer data"), you are the controller and we are your processor. If you process such data on behalf of someone else, you remain our sole counterpart and are responsible for ensuring that your instructions to us are lawful; in that case we act as your sub-processor.
For the personal data we process for our own purposes — your account, billing, support and security — we are the controller; that processing is described in our Privacy Policy, not in this DPA.
2. Subject matter, duration, nature and purpose
The processing consists of the storage, transmission and other technical operations needed to provide the cloud, hosting and related services you have ordered, for as long as you use them. You determine the types of personal data and the categories of data subjects contained in customer data — we do not inspect it and have no knowledge of its contents.
3. Instructions
We process customer data only on your documented instructions. The Terms, this DPA and the configuration choices you make in My Melonslab and on your services constitute those instructions. We will inform you if we consider that an instruction infringes the GDPR.
We may process customer data without instructions where EU or Swedish law requires it — for example under a binding order from a competent authority as described in section 11 of the Terms — in which case we inform you of the legal requirement before processing, unless the law prohibits it.
4. Confidentiality
We ensure that every person authorised to process customer data is bound by a contractual or statutory duty of confidentiality.
5. Security
We implement appropriate technical and organisational measures under Article 32 GDPR, including access controls, network security and physical security — see the Security section of our Privacy Policy. Our hardware is housed in secure, access-controlled data-centre facilities in Sweden; the facility operator has no logical access to customer data. You are responsible for the security of everything within your control: your applications, credentials, configurations and backups (see the Terms).
6. Sub-processors
You give us general written authorisation to engage sub-processors. No external sub-processors are currently engaged for the processing of customer data; all infrastructure with logical access to customer data is owned and operated by Hypefox AB. Should we engage a sub-processor in the future, we will update this page and notify you as described below.
We will inform you of any intended engagement, addition or replacement in advance, giving you the opportunity to object on reasonable, data-protection-related grounds. We impose the same data-protection obligations on every sub-processor and remain fully liable to you for their performance.
7. Assistance
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to data subjects' requests — in practice you can usually handle such requests yourself through direct access to your services — and, taking into account the information available to us, in ensuring compliance with your obligations under Articles 32 to 36 GDPR.
If a data subject contacts us directly about customer data, we forward the request to you without undue delay where we can identify you as the relevant customer.
8. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting customer data, and provide the information reasonably available to us to help you meet your obligations under Articles 33 and 34 GDPR.
9. Deletion and return
You can retrieve customer data yourself at any time while your service is active. On termination of a service, customer data is deleted in accordance with section 10 of the Terms — in the case of termination for non-payment, irrecoverably upon cancellation of the service, at the earliest 21 days after the invoice due date — unless EU or Swedish law requires continued storage. You are responsible for exporting any data you need before a service ends.
10. Audits
We make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits conducted by you or an auditor you mandate. Audits require reasonable prior written notice, take place at most once per year (unless a supervisory authority requires otherwise or a personal data breach has occurred), must not compromise the security or confidentiality of other customers, and are at your expense.
11. International transfers
Customer data is stored on infrastructure located in Sweden. We do not transfer customer data outside the EU/EEA unless you instruct or configure such a transfer yourself, or EU or Swedish law requires it.
12. Term, liability and precedence
This DPA applies for as long as we process customer data on your behalf. Liability under this DPA is subject to the limitations in section 12 of the Terms. If this DPA conflicts with the Terms regarding the processing of customer data, this DPA prevails.
13. Contact
Questions about this DPA can be sent to compliance@melonslab.com.