Skip to main content
ilveno
Buy now

Legal

Data Processing Addendum

Last updated: 16 September 2026
DRAFT — pending legal review. This document has been written to describe the Ilveno Cloud service as it actually operates, but it has not been reviewed by a qualified lawyer. Passages marked TODO still require a decision before this text is relied on as binding.

This Data Processing Addendum ("DPA") sets out the terms on which Ilveno processes personal data on behalf of a customer of Ilveno Cloud, as required by Article 28(3) of Regulation (EU) 2016/679 ("GDPR"). It forms part of the Terms of Service at https://ilveno.com/legal/terms and applies automatically to every Cloud subscription.

Parties, scope and precedence

The parties are the customer ("Controller") and Ege Bilge, sole proprietor, trading as "Ilveno" ("Processor", "we").

This DPA applies where we process personal data on the Controller's behalf in the course of providing Ilveno Cloud. It does not apply to an Enterprise on-premise installation: there the software runs on the Controller's own infrastructure, we never receive the workspace data, and we are not a processor of it.

In case of conflict, this DPA prevails over the Terms of Service in respect of the processing of personal data. A separately signed Enterprise agreement prevails over this DPA.

No signature is required: subscribing to Ilveno Cloud accepts this DPA. A countersigned copy can be requested at [email protected].

Subject matter and duration

Subject matter: the provision of the Ilveno Cloud hosted team workspace and the associated support, as described in the Terms of Service.

Duration: from the start of the subscription until the workspace and its backups are deleted in accordance with section 12.

Nature and purpose of the processing

We host, store, transmit, back up and make available the personal data that the Controller and its users place in the workspace, and we perform the technical operations needed to operate the service: provisioning the tenant, running and updating the application, database and cache, serving files, sending transactional email on the Controller's behalf, routing real-time media for meetings, taking backups, monitoring for faults, and providing support when asked.

The purpose is solely to provide the service to the Controller. We carry out no other processing of the workspace data — no profiling, no advertising, no analytics across customers, no model training.

Types of personal data

The Controller decides what goes into the workspace. Given the product's functionality, the processed data typically includes:

  • Identification and contact data of the Controller's users — name, email address, avatar, credentials in hashed form, two-factor secrets, role and permissions.
  • Usage and technical data — session records, IP address, user agent, device and login timestamps, activity and audit records.
  • Content submitted by users — notes, documents, task boards and cards, chat and direct messages, comments, calendar and booking entries, uploaded files of any type, and the contents of the optional modules in use (for example helpdesk tickets and correspondents, or HR records such as employment data and leave requests where the HR module is enabled).
  • Data of the Controller's own customers or contacts, where the Controller's use involves them — for example a person who books an appointment or writes to a helpdesk inbox.

Where the HR module is used, the data may include special categories of personal data within the meaning of GDPR art. 9 (for example health information related to sick leave). The Controller decides whether to place such data in the workspace and is responsible for the additional conditions that apply to it.

Categories of data subjects

  • The Controller's employees, contractors and other authorised users of the workspace.
  • The Controller's job applicants, where recruitment or HR functionality is used.
  • The Controller's customers, suppliers and other external contacts whose data the Controller's users record in the workspace, including people who submit a helpdesk request or book an appointment.
  • Any other data subject whose personal data the Controller chooses to place in the workspace.

Processing only on documented instructions

We process personal data only on the Controller's documented instructions, including as regards transfers to a third country. The Terms of Service, this DPA, the configuration the Controller chooses in the product, and the support requests it sends us, together constitute those instructions.

If we are required by Union or Member State law to process personal data beyond those instructions, we will inform the Controller of that legal requirement before processing, unless the law forbids us from doing so on important grounds of public interest.

We will inform the Controller if, in our opinion, an instruction infringes the GDPR or other applicable data-protection law.

Confidentiality

Every person authorised by us to process the Controller's personal data is bound by a duty of confidentiality, whether by contract or by statute, and that duty survives the end of their engagement. Access is granted only to the people who need it to operate the service or to answer a support request, and only to the extent needed.

Security of processing (GDPR art. 32)

The measures below are the measures we actually operate. We list no others, and we hold no security certification — we are not ISO 27001 certified and we have no SOC 2 report.

  • Tenant isolation at the container boundary. Each customer has its own application container, its own PostgreSQL database, its own Redis instance and its own storage volume, on its own private network. There is no shared application database and no reliance on a query condition to keep customers apart, so a missing filter in application code cannot expose another customer's data.
  • Per-tenant credentials. Database and cache passwords, the application signing secret and the media credentials are generated separately for each tenant and are not shared between customers.
  • Encryption in transit. Every workspace is served over HTTPS/TLS with certificates issued and renewed automatically. Real-time meeting media is carried over encrypted transport.
  • Authenticated datastores. The database and the cache require authentication and are not published on the host network; they are reachable only from the tenant's own private network.
  • Application-level access control. Sign-in, roles and per-resource permissions are enforced by the product; two-factor authentication (TOTP) is available to workspace users and can be required by the Controller.
  • Encryption of stored secrets. Sensitive values held by the application, such as user-supplied API keys, are encrypted with authenticated encryption (AES-256-GCM) before being written to the database.
  • Administrative access control. Our internal operations panel is restricted to an explicit allowlist of accounts and is reachable only through federated single sign-on, so multi-factor authentication is enforced by the identity provider.
  • Backups. We take regular database dumps of Cloud tenants so that we can restore a workspace after a failure.
  • Resilience and separation of environments. Tenant stacks restart automatically on failure, run with resource limits so that one tenant cannot starve another, and updates are built and released from a versioned image rather than changed in place.
  • REVIEW NEEDED — encryption at rest of the underlying volumes and of backup archives depends on the hosting provider's configuration and has not been verified for this draft. It must be confirmed, and stated accurately here, before this document is published. Do not assume it is in place.

We keep these measures under review and may replace a measure with an equivalent or better one. We will not reduce the overall level of security during a subscription term.

Subprocessors

The Controller gives a general authorisation for us to engage subprocessors. We impose on every subprocessor, by contract, data-protection obligations at least as protective as those in this DPA, and we remain fully liable to the Controller for a subprocessor's performance.

Our current subprocessors are listed in the Annex at the end of this document.

We will give the Controller at least thirty (30) days' notice by email before adding or replacing a subprocessor. The Controller may object on reasonable data-protection grounds within that period. If we cannot resolve the objection, the Controller may terminate the affected subscription and receive a pro-rata refund of the unused remainder of the current billing period.

Assistance with data subject requests

The product gives the Controller direct access to the personal data in its workspace, so most requests for access, rectification, erasure, restriction, portability or objection can be handled by the Controller itself.

Where they cannot, we will assist the Controller by appropriate technical and organisational measures, insofar as this is possible, taking into account the nature of the processing.

If a data subject contacts us directly about data in a Controller's workspace, we will not answer the substance of the request. We will tell them to contact the Controller and, where we can identify the Controller, pass the request on without undue delay.

Assistance with security, breach notification and impact assessments

Taking into account the nature of the processing and the information available to us, we will assist the Controller in complying with its obligations under GDPR arts. 32 to 36 — security of processing, notification of a personal data breach to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation.

We will notify the Controller of a personal data breach affecting its personal data without undue delay and in any event within seventy-two (72) hours of becoming aware of it, by email to the Controller's registered contact address. The notification will describe, as far as it is known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not yet available, we will provide it in phases as it emerges.

Notifying the supervisory authority and the affected data subjects is the Controller's obligation, not ours; we will provide the information the Controller reasonably needs to do it.

Deletion and return of data

The Controller can export its data at any time while the workspace exists. On request during the subscription, or at its end, we will provide a copy of the workspace database and of the stored files.

When a subscription ends the workspace is suspended, not deleted: the application stops and the data is retained unchanged, so that resubscribing restores it. After the retention window stated in the Terms of Service the workspace, its database and its files are permanently deleted, along with its backups in the ordinary backup rotation.

There is no deletion timer. A suspended workspace is retained until the controller asks for deletion, or until the processor gives at least thirty (30) days' written notice of its intention to delete a long-suspended workspace. This mirrors section 8 of the Terms of Service.

We will delete the data sooner on the Controller's written instruction, unless Union or Member State law requires us to keep it, in which case we will tell the Controller what we must keep and why. We will confirm deletion in writing on request.

Audits and information

We will make available to the Controller all information necessary to demonstrate compliance with the obligations in GDPR art. 28 and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.

In practice: we answer security questionnaires and information requests at [email protected]. An on-site or remote inspection may be carried out at most once in any twelve-month period, on thirty (30) days' written notice, during business hours, subject to confidentiality, without disrupting the service and without giving access to another customer's data. The Controller bears its own costs; we may charge a reasonable fee for the time we spend where an audit goes beyond a reasonable scope. An audit may be carried out more frequently following a personal data breach or at the requirement of a supervisory authority.

We hold no third-party audit report and cannot substitute one for an inspection. If that matters to you, raise it before subscribing.

International transfers

We will not transfer the Controller's personal data outside the European Economic Area except under a transfer mechanism permitted by Chapter V of the GDPR.

Where a transfer takes place to a country without an adequacy decision, it is made under the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Three (processor to sub-processor) or Module Two (controller to processor) as applicable, together with supplementary measures where a transfer impact assessment requires them. For Türkiye, the corresponding mechanisms under KVKK art. 9 apply.

REVIEW NEEDED — this draft states the intended mechanism, not a verified one. Which of our providers transfer data outside the EEA, under which clauses, and with which module, has not been confirmed provider by provider. This section must be checked, and the hosting region fixed, before this document is published or relied on.

Liability and changes

The limitations of liability in the Terms of Service apply to this DPA, to the extent permitted by law. They do not limit any liability that cannot be limited under the GDPR or other mandatory law.

We may update this DPA to reflect a change in the service, in the subprocessor list, or in the law. Material changes are notified by email to active customers at least thirty (30) days in advance, and the "Last updated" date above always reflects the current version.

Annex — subprocessors

The following subprocessors process personal data on behalf of Ilveno Cloud customers:

  • Polar Software Inc. (polar.sh) — merchant of record. Purpose: payment, invoicing, tax, customer portal. Data: customer name, billing email, billing address, subscription and transaction records. Not workspace content.
  • Resend — transactional email. Purpose: delivering email the service sends, such as invitations, notifications and licence delivery. Data: recipient email addresses and the content of the message sent.
  • TODO — hosting and infrastructure provider. Purpose: running the servers on which the tenant containers, databases and storage volumes operate. Data: all workspace content, at rest and in transit. The provider's legal name, country and data-centre region must be entered here before publication; this draft deliberately does not guess them.
  • LiveKit is not listed as a subprocessor because it is not one: meeting media is routed by a LiveKit server the processor operates itself, on the hosting provider above. No meeting content is stored.
  • OpenAI — optional, and only where an API key has been configured, either by an individual user for their own account or by the operator for the installation. Purpose: the optional AI assistant. Data: the text the user submits to the assistant. If no key is configured the feature is unavailable and nothing is sent.

Questions about this list, and requests for the safeguards in place with any provider, go to [email protected].