Detailed agreement on roles, responsibilities, and data protection compliance.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between **Braveware, operating as Serverfy** ("Data Processor", "we", "us") and the customer ("Data Controller", "you").
This agreement reflects the parties' commitment to abide by applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Brazilian General Data Protection Law (LGPD), concerning the processing of Personal Data.
Serverfy automates infrastructure management. To do this, we process:
Exclusion of Customer Content: Serverfy does not host your applications or databases. We do not download, store, or process the source code of your applications, nor do we access the end-user data stored within the databases on your managed servers. You remain fully responsible for the compliance and security of the data residing on your infrastructure.
Serverfy implements strict technical and organizational measures to ensure a level of security appropriate to the risk, including:
To deliver our services globally, Serverfy engages trusted third-party sub-processors. By accepting this DPA, the Data Controller grants general authorization for Serverfy to use sub-processors in the following categories:
We ensure that all sub-processors are bound by written agreements that require them to provide at least the same level of data protection as required under this DPA.
As the Data Processor, Serverfy will assist the Data Controller, insofar as possible, in fulfilling their obligation to respond to requests from individuals exercising their data privacy rights (e.g., the right to access, rectify, or erase data). If Serverfy receives a request directly from an end-user of the Data Controller, we will promptly redirect the request to the Data Controller.
In the event of a confirmed security breach that compromises Personal Data processed by Serverfy, we will notify the Data Controller without undue delay (and in any event within 48 hours of becoming aware of the breach). We will provide sufficient information to allow you to meet your reporting obligations under the GDPR or LGPD.
Upon termination of your Serverfy account, we will promptly and securely delete all OAuth tokens, API keys, and deployment metadata associated with your account from our active databases. Infrastructure logs and invoice records may be retained temporarily solely for legal and tax compliance purposes.
This DPA shall be governed by and construed in accordance with the laws applicable to the principal Terms of Service agreement.