Version 1 · Effective October 9, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between CaskStack, LLC, 101 Cooper Street, Santa Cruz, CA 95062, United States ("Odden", "we", "us") and the customer that uses Odden Cloud ("Customer", "you") (the "Agreement"). It applies where we process Personal Data on your behalf when we provide Odden Cloud ("Customer Data"). If it conflicts with the Agreement about the processing of Personal Data, this DPA applies.
1. Definitions
"Applicable Data Protection Law" means the laws that apply to the processing of Customer Data, including, where they apply, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA"). "Personal Data", "controller", "processor", "processing", "data subject" and "personal data breach" have the meanings given in those laws; "Service Provider" and "Contractor" have the CCPA meanings.
"Workspace" means a customer environment in Odden Cloud. "Sub-processor" means a third party we engage to process Customer Data. "Standard Contractual Clauses" means the clauses adopted by European Commission Implementing Decision (EU) 2021/914, and "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner.
2. Roles
2.1 You are the controller (or, if you process on behalf of your own customers, the processor) of Customer Data, and we are your processor (or sub-processor).
2.2 We are an independent controller of the personal data we process for our own purposes: your users' account details, sign-in and security records, billing and support correspondence, and website visits. Our privacy policy applies to those.
2.3 You are responsible for having a lawful basis to put Customer Data into Odden Cloud, for the instructions you give, and for the content you send through hosted email.
3. Details of the processing
The subject matter, duration, nature and purpose, types of Personal Data and categories of data subjects are in Annex 1.
4. Our obligations
4.1 Instructions. We process Customer Data only on your documented instructions, which are this DPA, the Agreement and your use of the features of Odden Cloud, unless the law requires otherwise (in which case we tell you first, unless the law forbids it). We will tell you if we think an instruction breaks Applicable Data Protection Law.
4.2 Confidentiality and staff access. People we authorise to process Customer Data are bound by confidentiality. Within the product, our staff can open a Workspace only through a recorded support session started by a platform administrator who has two-factor authentication, for a stated reason, for a limited time (30 minutes by default, at most 60), read-only unless you have allowed changes (and even then without the owner-only functions of exporting and deleting the Workspace), with every session listed in the Workspace and in the audit log, and with the Workspace's owners notified when it starts. Separately, a limited number of named operators have access to the hosting and database tools used to run Odden Cloud. We restrict that access to what is necessary to operate, secure and support the service, protect it with the hosting provider's sign-in controls, and record it as described in Annex 2. We do not use it to read Customer Data except to carry out your instructions or a request for help that needs it.
4.3 Security. We apply the technical and organisational measures in Annex 2 and keep them appropriate to the risk.
4.4 Sub-processors. You give general authorisation for the Sub-processors in Annex 3. We bind each to data protection terms no less protective than this DPA and remain responsible for them. We will add or replace a Sub-processor only after listing it on our sub-processor page and emailing the owners of every Workspace at least 30 days before it starts to process Customer Data. If you object on reasonable data protection grounds within that period we will work with you to resolve it; if we cannot, you may stop using the affected part of Odden Cloud and we will refund what you paid for the period that remains.
4.5 Assistance. Taking into account the nature of the processing, we help you respond to data subject requests (a Workspace owner can export and delete Customer Data themselves, see section 6), and help you meet your obligations about security, breach notification, impact assessments and consulting regulators, to the extent they relate to our processing. We may charge reasonable costs for assistance that goes beyond the features of Odden Cloud. If a data subject contacts us about Customer Data, we pass the request to you and do not answer it ourselves unless the law requires.
4.6 Personal data breach. We notify you without undue delay after we become aware of a personal data breach affecting Customer Data, by email to the Workspace owners, with the information we have about what happened, the likely consequences and what we are doing; we add detail as we learn it.
4.7 Audits. We give you the information needed to show our compliance with this DPA and allow audits by you or an auditor you appoint, no more than once a year (unless a regulator or a breach requires more), on 30 days' written notice, during business hours, subject to confidentiality and without access to other customers' data.
5. Your obligations
You will give only lawful instructions, make sure you have the rights and notices needed for Customer Data, keep the credentials of your users secure, and assess whether Odden Cloud's security fits the data you store. You must not store in a Workspace data that Odden Cloud is not designed for: payment card numbers, government identity numbers, health information and other special categories of personal data, or children's data.
6. Return and deletion
6.1 Export. A Workspace owner can export everything in the Workspace at any time: records as CSV files, structured data as JSON, and uploaded files. The export is built in the background and is available to the owners for 7 days. It does not include passwords, two-factor secrets, API keys, tokens or other credentials.
6.2 Deletion. A Workspace owner can delete the Workspace. It is switched off at once and kept for 30 days so that an accidental deletion can be undone. Owners can cancel during that time and can still export. After 30 days we delete Customer Data permanently from our systems, including uploaded files, exports, custom domains and sending identities. Copies in our database backups are overwritten within 7 days after that. Records the law requires us to keep, and the audit log (up to 400 days), are not Customer Data and are handled under our privacy policy.
6.3 Ending the Agreement. When the Agreement ends, for any reason, we switch the Workspace off and keep it for 30 days with export available to its owners, and then delete it under section 6.2, unless you tell us otherwise.
7. International transfers
7.1 We process Customer Data in the United States. Where Applicable Data Protection Law restricts a transfer of Personal Data to us, the Standard Contractual Clauses (Module Two, controller to processor, and Module Three, processor to processor, where you act as a processor) apply and are incorporated by reference, with the details in Annex 4, together with the UK Addendum for transfers from the United Kingdom and the Swiss adjustments for transfers from Switzerland.
7.2 For transfers to Sub-processors outside the EEA, UK and Switzerland we rely on the safeguards in Annex 3.
8. California
To the extent the CCPA applies, we are your Service Provider (Contractor). We process Customer Data only for the business purposes in Annex 1 and as you instruct; we do not sell or share it, and we do not retain, use or disclose it outside our direct business relationship with you or for any purpose other than those business purposes; we do not combine it with other data except as the CCPA allows; we will tell you if we can no longer meet our CCPA obligations; and you may take reasonable steps to stop and remedy unauthorised use. We certify that we understand and will comply with these restrictions.
9. Liability and general
Each party's liability under this DPA is subject to the limits in the Agreement, but nothing in this DPA limits liability to data subjects that the Standard Contractual Clauses or Applicable Data Protection Law do not allow to be limited. This DPA is governed by the law that governs the Agreement, except where the Standard Contractual Clauses or Applicable Data Protection Law require otherwise. We may update this DPA to keep up with the law or the service; material changes are announced to Workspace owners by email at least 30 days before they apply.
Annex 1: Details of the processing
- Subject matter and nature. Hosting, storing, organising, displaying, transmitting, exporting and deleting Customer Data to provide Odden Cloud; sending email on your behalf (hosted email); and security, support and backups.
- Purpose (business purposes). To provide Odden Cloud to you, under the Agreement and your instructions.
- Duration. For as long as the Workspace exists, plus the 30-day deletion period and the 7-day backup period in section 6.
- Types of Personal Data. What you or your users put in: names, email addresses, phone numbers, postal addresses, job titles and employers; records of deals, quotes, support tickets and messages; notes, activity history, preferences and consent records; the content, recipients and delivery results of emails you send; submissions to forms and pages you publish; the IP address and browser of people who visit pages you publish or open and click your emails; uploaded files; and custom fields you define.
- Special categories. Not intended. See section 5.
- Categories of data subjects. Your contacts, leads, customers and prospects; people who submit your forms or write to your support address; visitors to your published pages; and your own staff and members.
- Frequency. Continuous, for the term.
Annex 2: Technical and organisational measures
- Access control and separation. Every Workspace's data is kept separate from every other Workspace's in the application's data layer, and the separation is covered by automated tests; users reach a Workspace only through a membership with a role (owner, admin, manager, member or viewer) that limits what they can do.
- Authentication. Passwords are hashed; two-factor authentication is available to everyone and required for anyone who belongs to more than one Workspace and for our administrators; sessions use a host-only, secure, HTTP-only cookie; sign-in attempts are rate-limited; each user can end their other sessions.
- Staff access (product). Recorded, time-limited, read-only-by-default support sessions as in section 4.2; platform administrator accounts have no standing view of Workspace records.
- Staff access (infrastructure). Named operators only; the hosting provider's command history records the commands run through its tools; opening the application's console or database tools is recorded in our audit log (time, command, and the start of the code); commands that touch Customer Data on purpose (export, deletion, erasure) also record themselves in the Workspace's audit log. A connection directly to the database from outside the application is not visible to the application: it is limited to the same named operators.
- Encryption. Encrypted connections (TLS) for all access; Workspace settings that contain credentials are encrypted at rest in the application.
- Audit. An audit log of sign-ins, failed sign-ins, changes to settings, members and domains, support access, exports and deletions, with user and IP address, kept up to 400 days.
- Secrets handling. We take care that secrets are kept out of the audit log and monitoring (secret-looking fields are replaced before the audit log is written; addresses that carry secrets, and request bodies, are not sent to monitoring); outbound requests that Workspaces trigger (webhooks) are checked so they cannot reach internal systems.
- Availability and backups. Managed database with point-in-time backups kept for 7 days; deployments run automated tests, a static analysis check and a style check before release.
- Email safeguards. Domain verification (DKIM and SPF) before sending; bounce and complaint suppression; automatic pause on abnormal rates; per-workspace allowances.
- Data minimisation and retention. Records of each email sent are reduced to the recipient's address, unsubscribe reference and status after 13 months; usage totals are kept 24 months; exports are deleted after 7 days.
- Incident response. Errors are monitored, health checks alert our administrators, and breaches are handled under section 4.6.
- Review. Code and security changes are reviewed and tested automatically before release.
Annex 3: Sub-processors
As listed on our sub-processor page at the date of this DPA:
| Sub-processor | Function | Location | Transfer safeguard |
|---|---|---|---|
| Laravel Holdings Inc. (Laravel Cloud) | Application and database | United States (US East, Ohio) | The provider's data processing terms |
| Laravel Holdings Inc. (Laravel Object Storage on Cloudflare R2) | Private storage of files and exports | Location chosen automatically by the provider (Cloudflare R2); not limited to one region | The provider's data processing terms |
| Laravel Holdings Inc. (Laravel Nightwatch) | Application monitoring | United States (US East, Ohio) | The provider's data processing terms |
| Cloudflare, Inc. | Network protection and delivery | Global | The provider's data processing terms |
| Amazon Web Services, Inc. (SES, SNS) | Email delivery and notifications | United States (US East, Ohio) | The provider's data processing terms |
| Mailgun (Sinch) | Odden's platform emails | United States | The provider's data processing terms |
Annex 4: Standard Contractual Clauses details
- Parties. Data exporter: the Customer. Data importer: CaskStack, LLC.
- Module. Module Two (controller to processor); Module Three (processor to processor) where the Customer is a processor.
- Clause 7 (docking). Included. Clause 9(a) (sub-processors). Option 2, general written authorisation, 30 days' notice. Clause 11(a). The optional independent dispute resolution body is not used. Clause 17. The law of Ireland. Clause 18. The courts of Ireland.
- Annexes I to III. Annex 1 above for Annex I; Annex 2 above for Annex II; Annex 3 above for Annex III. Competent supervisory authority: the supervisory authority of the exporter's Member State or, where there is none, the Irish Data Protection Commission.
- UK Addendum. Tables 1 to 3 are completed by the information above; Table 4: neither party may end the Addendum except as it provides.
- Swiss transfers. References to the GDPR include the Swiss FADP; the Swiss Federal Data Protection and Information Commissioner is the competent authority for those transfers.