Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement ("DPA") forms part of the Dhub Terms and Conditions ("Terms") between Dhub, operated by MB Valdemaras Repsys, established in Lithuania ("Dhub", "we", "us"), and the customer identified by the applicable Dhub account ("Customer"). It applies where and to the extent Dhub processes personal data on the Customer's behalf as a processor within the meaning of the EU General Data Protection Regulation ("GDPR") in the course of providing the Service.

This DPA implements Article 28(3) GDPR and is aligned with the standard contractual clauses adopted by the European Commission under Implementing Decision (EU) 2021/915. It applies automatically to all customers subject to the GDPR and does not require a signature. If your organisation requires a countersigned copy, contact us at hello@dhub.dev.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR. "Service" means Dhub, a collaborative editor for Markdown/MDX documentation that connects to the Customer's GitHub repositories, as described in the Terms.

2. Scope and Roles

The Customer is the controller and Dhub is the processor of the personal data described in Annex 1, which Dhub processes on the Customer's behalf in the course of providing the Service. For payment and billing data processed by our payment provider (Stripe), Stripe acts as an independent controller under its own terms. This DPA applies for as long as Dhub processes personal data on behalf of the Customer.

3. Processing on Documented Instructions

Dhub shall process personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by EU or Member State law. In that case Dhub shall inform the Customer of the legal requirement before processing, unless the law prohibits this. The Terms, this DPA, and the Customer's use of the Service's settings and features constitute the Customer's complete documented instructions. Dhub shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection provisions.

4. Confidentiality

Dhub shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process the personal data only as needed to provide the Service.

5. Security

Dhub shall implement the technical and organisational measures described in Annex 2 and shall maintain a level of security appropriate to the risk (Article 32 GDPR). Dhub may update the measures in Annex 2 from time to time, provided the updates do not materially reduce the overall level of protection.

6. Subprocessors

The Customer grants Dhub general written authorisation to engage the subprocessors listed in Annex 3. Dhub shall inform the Customer (via the email address associated with the Customer's account) of any intended addition or replacement of a subprocessor at least 14 days before the change takes effect. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees. Dhub shall impose on each subprocessor, by way of contract, data protection obligations materially equivalent to those in this DPA, and remains fully liable to the Customer for the performance of each subprocessor's obligations.

7. International Transfers

Dhub is established in Lithuania (EU). The Service is hosted on infrastructure operated by subprocessors located in the United States, as listed in Annex 3. Where personal data is transferred to a subprocessor in a country without an EU adequacy decision, Dhub ensures an appropriate transfer mechanism is in place: certification under the EU-US Data Privacy Framework (which benefits from the European Commission's adequacy decision of 10 July 2023) and/or the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), as indicated in Annex 3.

8. Assistance to the Customer

Taking into account the nature of the processing, Dhub shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subjects' requests (Chapter III GDPR). If a data subject contacts Dhub directly regarding data processed under this DPA, Dhub shall forward the request to the Customer without undue delay. Dhub shall further assist the Customer, taking into account the nature of the processing and the information available to it, in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation).

9. Personal Data Breach

Upon becoming aware of a personal data breach affecting the Customer's personal data, Dhub shall notify the Customer without undue delay, and in any case within 48 hours, at the email address associated with the Customer's account. The notification shall include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach. Dhub shall provide further information as it becomes available and shall cooperate with the Customer in mitigating the breach.

10. Deletion and Return of Data

Upon termination of the Terms, Dhub shall, at the Customer's choice, delete or return all personal data processed on the Customer's behalf, and delete existing copies, unless EU or Member State law requires further storage. The Customer may export its content (documentation files) at any time via the Service's GitHub synchronisation. Absent a contrary instruction, Dhub shall delete the Customer's personal data within 30 days of termination. Data in automated backups is overwritten in the ordinary course within the backup retention cycle (currently 10 days) and is not restored except for disaster recovery.

11. Audits and Information

Dhub shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. The parties agree that audits shall in the first instance take the form of written information requests, which Dhub shall answer within a reasonable period. An on-site or remote inspection may be conducted no more than once per year (except following a personal data breach or where required by a supervisory authority), upon at least 30 days' written notice, during business hours, without disrupting Dhub's operations, and at the Customer's expense.

12. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms.

13. Final Provisions

In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. This DPA is governed by the law of the Republic of Lithuania. We may update this DPA from time to time by posting the updated version on this page and updating the "Last updated" date; updates shall not materially reduce the level of protection for personal data. We will notify customers of material changes by email.

Annex 1: Description of the Processing

Subject matter and nature of the processing. Provision of Dhub, a hosted collaborative editor for Markdown/MDX documentation. Processing consists of hosting, storage, transmission, display, real-time collaborative editing, synchronisation of content with the Customer's GitHub repositories, user authentication, product analytics, transactional email, and customer support.

Purpose. Providing and supporting the Service as described in the Terms.

Duration. The term of the Terms, plus the deletion period in Section 10.

Categories of data subjects.

Categories of personal data.

Special categories of data (Article 9 GDPR). None intended. The Customer agrees not to use the Service to process special categories of personal data.

Annex 2: Technical and Organisational Measures

Annex 3: Approved Subprocessors

SubprocessorPurposeLocationTransfer mechanism
Amazon Web Services, Inc.Cloud infrastructure hosting (compute, database, storage, CDN)USAEU-US Data Privacy Framework; AWS GDPR DPA
PostHog, Inc.Product usage analyticsUSAEU-US Data Privacy Framework and/or SCCs; provider DPA
ResendTransactional email deliveryUSASCCs and/or EU-US Data Privacy Framework; provider DPA
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing and billing (independent controller for payment data)Ireland / USAEU-US Data Privacy Framework (Stripe, Inc.)
Google LLC (Google Workspace)Business email and customer support communicationsUSA / EUEU-US Data Privacy Framework; Google Workspace DPA

Changes to this list are notified per Section 6. Questions about this DPA can be sent to hello@dhub.dev.