Last updated: July 2026
This Data Processing Agreement ("DPA") forms part of the Dhub Terms and Conditions ("Terms") between Dhub, operated by MB Valdemaras Repsys, established in Lithuania ("Dhub", "we", "us"), and the customer identified by the applicable Dhub account ("Customer"). It applies where and to the extent Dhub processes personal data on the Customer's behalf as a processor within the meaning of the EU General Data Protection Regulation ("GDPR") in the course of providing the Service.
This DPA implements Article 28(3) GDPR and is aligned with the standard contractual clauses adopted by the European Commission under Implementing Decision (EU) 2021/915. It applies automatically to all customers subject to the GDPR and does not require a signature. If your organisation requires a countersigned copy, contact us at hello@dhub.dev.
Terms such as "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR. "Service" means Dhub, a collaborative editor for Markdown/MDX documentation that connects to the Customer's GitHub repositories, as described in the Terms.
The Customer is the controller and Dhub is the processor of the personal data described in Annex 1, which Dhub processes on the Customer's behalf in the course of providing the Service. For payment and billing data processed by our payment provider (Stripe), Stripe acts as an independent controller under its own terms. This DPA applies for as long as Dhub processes personal data on behalf of the Customer.
Dhub shall process personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by EU or Member State law. In that case Dhub shall inform the Customer of the legal requirement before processing, unless the law prohibits this. The Terms, this DPA, and the Customer's use of the Service's settings and features constitute the Customer's complete documented instructions. Dhub shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection provisions.
Dhub shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process the personal data only as needed to provide the Service.
Dhub shall implement the technical and organisational measures described in Annex 2 and shall maintain a level of security appropriate to the risk (Article 32 GDPR). Dhub may update the measures in Annex 2 from time to time, provided the updates do not materially reduce the overall level of protection.
The Customer grants Dhub general written authorisation to engage the subprocessors listed in Annex 3. Dhub shall inform the Customer (via the email address associated with the Customer's account) of any intended addition or replacement of a subprocessor at least 14 days before the change takes effect. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees. Dhub shall impose on each subprocessor, by way of contract, data protection obligations materially equivalent to those in this DPA, and remains fully liable to the Customer for the performance of each subprocessor's obligations.
Dhub is established in Lithuania (EU). The Service is hosted on infrastructure operated by subprocessors located in the United States, as listed in Annex 3. Where personal data is transferred to a subprocessor in a country without an EU adequacy decision, Dhub ensures an appropriate transfer mechanism is in place: certification under the EU-US Data Privacy Framework (which benefits from the European Commission's adequacy decision of 10 July 2023) and/or the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), as indicated in Annex 3.
Taking into account the nature of the processing, Dhub shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subjects' requests (Chapter III GDPR). If a data subject contacts Dhub directly regarding data processed under this DPA, Dhub shall forward the request to the Customer without undue delay. Dhub shall further assist the Customer, taking into account the nature of the processing and the information available to it, in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation).
Upon becoming aware of a personal data breach affecting the Customer's personal data, Dhub shall notify the Customer without undue delay, and in any case within 48 hours, at the email address associated with the Customer's account. The notification shall include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach. Dhub shall provide further information as it becomes available and shall cooperate with the Customer in mitigating the breach.
Upon termination of the Terms, Dhub shall, at the Customer's choice, delete or return all personal data processed on the Customer's behalf, and delete existing copies, unless EU or Member State law requires further storage. The Customer may export its content (documentation files) at any time via the Service's GitHub synchronisation. Absent a contrary instruction, Dhub shall delete the Customer's personal data within 30 days of termination. Data in automated backups is overwritten in the ordinary course within the backup retention cycle (currently 10 days) and is not restored except for disaster recovery.
Dhub shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. The parties agree that audits shall in the first instance take the form of written information requests, which Dhub shall answer within a reasonable period. An on-site or remote inspection may be conducted no more than once per year (except following a personal data breach or where required by a supervisory authority), upon at least 30 days' written notice, during business hours, without disrupting Dhub's operations, and at the Customer's expense.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms.
In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. This DPA is governed by the law of the Republic of Lithuania. We may update this DPA from time to time by posting the updated version on this page and updating the "Last updated" date; updates shall not materially reduce the level of protection for personal data. We will notify customers of material changes by email.
Subject matter and nature of the processing. Provision of Dhub, a hosted collaborative editor for Markdown/MDX documentation. Processing consists of hosting, storage, transmission, display, real-time collaborative editing, synchronisation of content with the Customer's GitHub repositories, user authentication, product analytics, transactional email, and customer support.
Purpose. Providing and supporting the Service as described in the Terms.
Duration. The term of the Terms, plus the deletion period in Section 10.
Categories of data subjects.
Categories of personal data.
Special categories of data (Article 9 GDPR). None intended. The Customer agrees not to use the Service to process special categories of personal data.
| Subprocessor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure hosting (compute, database, storage, CDN) | USA | EU-US Data Privacy Framework; AWS GDPR DPA |
| PostHog, Inc. | Product usage analytics | USA | EU-US Data Privacy Framework and/or SCCs; provider DPA |
| Resend | Transactional email delivery | USA | SCCs and/or EU-US Data Privacy Framework; provider DPA |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing and billing (independent controller for payment data) | Ireland / USA | EU-US Data Privacy Framework (Stripe, Inc.) |
| Google LLC (Google Workspace) | Business email and customer support communications | USA / EU | EU-US Data Privacy Framework; Google Workspace DPA |
Changes to this list are notified per Section 6. Questions about this DPA can be sent to hello@dhub.dev.