TUNDRÄ
Login Start for free

Legal

Data processing addendum

This DPA applies when a Business Customer is controller of personal data and TUNDRÄ processes that data only to perform the Customer’s documented website-development instructions.

Effective July 13, 2026 · Version 2026-07-13

Legal documents
Terms of serviceService scopeBilling & subscriptionsCancellation & refundsAcceptable usePrivacy noticeCookie noticeData processing addendumSeller informationSecurity
Execution. This DPA becomes binding when incorporated into an Order Form, accepted with the Business Terms, or signed by both parties. It does not by itself complete a restricted international-transfer assessment. Do not transfer regulated EEA or UK customer data until any required transfer addendum and assessment are complete.

1. Parties and scope

This Data Processing Addendum (“DPA”) is between the Customer identified in the applicable Order Form (“Customer”) and Individual Entrepreneur Grishechko Aleksei Sergeevich, trading as TUNDRÄ (“Processor”). It supplements the Terms of Service or other services agreement (“Agreement”).

It applies only to Personal Data for which Customer is Controller and which Processor processes on Customer’s behalf to provide the Service (“Customer Personal Data”). It does not apply to data TUNDRÄ processes independently for account management, billing, security, legal compliance or its own business relationship, which is covered by the Privacy Notice.

2. Definitions and precedence

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings in the applicable Data Protection Law. “Data Protection Law” means privacy and data-protection law applicable to the Processing, including where applicable the GDPR, UK GDPR, UK Data Protection Act 2018 and Russian Federal Law No. 152-FZ.

If this DPA conflicts with the Agreement on protection of Customer Personal Data, this DPA controls. An executed international-transfer addendum controls over this DPA solely for the restricted transfer it governs. Mandatory law always prevails.

3. Customer instructions

Processor will process Customer Personal Data only on documented instructions from Customer, including the Agreement, accepted tasks, configuration choices and written support directions, unless law requires other Processing. Where legally permitted, Processor will notify Customer before legally required Processing.

Processor will promptly inform Customer if, in its reasonable opinion, an instruction infringes applicable Data Protection Law. It may pause that instruction while the parties clarify a lawful alternative. Processor does not determine whether Customer’s collection or instruction is lawful.

4. Customer obligations

Customer warrants and is responsible for ensuring that:

  • it has a lawful basis and has provided required notices for the Processing and disclosure to Processor;
  • its instructions are lawful, accurate and limited to what is necessary;
  • it has obtained required consent for cookies, marketing, monitoring or special data;
  • it will not provide prohibited or highly sensitive data unless expressly authorised in an Order Form;
  • Data Subjects can exercise applicable rights and Customer can authenticate their requests; and
  • it completes any required transfer impact assessment and supplementary measures before a restricted transfer.

5. Confidentiality and personnel

Processor will ensure that persons authorised to process Customer Personal Data are bound by confidentiality, receive access only as necessary for assigned work, and process the data only under Customer instructions. Access will be withdrawn when no longer required.

6. Security measures

Taking account of the state of the art, implementation costs, scope, context and risks, Processor will maintain appropriate technical and organisational measures. Current baseline measures include those in Security Overview and Annex 2 below. Customer acknowledges that the standard Service is designed for ordinary website-project data, not unrestricted regulated workloads.

7. Subprocessors

Customer gives general written authorisation for Processor to engage subprocessors as necessary to provide the Service. Processor will impose data-protection duties materially equivalent to those relevant under this DPA and remains responsible for each subprocessor’s performance to the extent required by applicable law.

Processor will give at least 15 days’ notice of a new subprocessor with access to Customer Personal Data where reasonably possible. Customer may object during that period on specific, reasonable data-protection grounds. The parties will attempt mitigation or an alternative. If none is commercially reasonable, either party may terminate the affected Processing; Customer remains responsible for fees for Service already supplied.

8. Data Subject requests

Taking account of the nature of Processing, Processor will provide reasonable assistance for Customer to respond to requests for access, correction, deletion, restriction, objection or portability. If Processor receives a request relating to Customer Personal Data, it will direct the requester to Customer and not respond substantively unless authorised or legally required.

9. Personal Data Breach

Processor will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. As information becomes reasonably available, notice will describe the nature of the breach, categories and approximate number of affected subjects and records, likely consequences, mitigation taken and a contact point. Notice is not an admission of fault.

Customer is responsible for notices to Data Subjects and Supervisory Authorities, except where law directly requires Processor to notify. Processor will reasonably assist, taking account of the nature of Processing and information available.

10. Assessments and consultations

Processor will provide information reasonably necessary for Customer’s data-protection impact assessment or prior consultation concerning the Service. Assistance beyond standard documentation or caused by Customer’s unusual Processing may be charged at an agreed rate unless required due to Processor’s breach.

11. International transfers

Processor will not knowingly make a restricted transfer of Customer Personal Data without a lawful mechanism required by applicable law. Where Customer transfers EEA or UK Personal Data to a location without an applicable adequacy decision, the parties will execute the then-current appropriate European Commission standard clauses, UK International Data Transfer Addendum/Agreement, or another valid mechanism before the transfer, and document any required transfer assessment and supplementary measures.

The parties acknowledge that a mechanism must match the actual roles, territorial scope and destination. This DPA does not state that Russia or any other non-adequate jurisdiction has been deemed adequate. Customer must not use consent as a routine substitute for an appropriate Business-to-Business transfer mechanism.

12. Return and deletion

During the Service, Customer may request export of reasonably accessible Customer Personal Data. At termination or written instruction, Processor will delete or return Customer Personal Data, at Customer’s choice, unless law requires retention. Unless an Order Form states a shorter period, deletion from active systems will normally occur within 60 days after a valid termination request; isolated backup copies expire on their normal cycle and remain protected and unavailable for ordinary use.

13. Information and audits

Processor will provide information reasonably necessary to demonstrate compliance. Customer should first use current policies, responses and independent evidence made available by Processor. No more than once per year, unless required after a material incident or by an authority, Customer may conduct a proportionate audit on reasonable notice during business hours. Audits must protect other customers, security and confidentiality and may not include penetration testing without separate written scope. Customer bears its audit costs unless a material Processor breach is found.

14. Government requests

Where legally permitted, Processor will notify Customer of a binding request for Customer Personal Data, review its validity, challenge disproportionate requests where reasonable, and disclose only what is legally required. Processor will document requests as required by law.

15. Liability and term

This DPA begins with the Agreement and continues while Processor holds Customer Personal Data. Liability under this DPA is subject to the Agreement’s lawful limitations, without limiting Data Subject rights or liability that cannot be limited. Sections concerning confidentiality, deletion, audits, transfers and liability survive as necessary.

Annex 1 — Processing details

Subject matter
Web development, design, maintenance, QA, support and related portal collaboration.
Duration
For the Agreement and deletion period described above.
Nature
Access, consultation, hosting, organisation, retrieval, adaptation, troubleshooting, transmission and deletion as directed.
Purposes
To perform accepted tasks, communicate, test, secure, deploy and document Customer-requested work.
Data Subjects
Customer personnel, contractors, users, leads, prospects, customers and website visitors whose data is necessarily included.
Personal Data
Identifiers, contact details, account IDs, website events, communications, order/support data and task materials selected by Customer.
Sensitive data
Not permitted under the standard Service. Any exception requires express scope, necessity and additional safeguards.
Frequency
As needed during active tasks and support.

Annex 2 — Technical and organisational measures

  • encryption in transit for production website and account traffic;
  • one-way cryptographic protection for passwords and authentication credentials;
  • account, organisation and role-based access controls;
  • reasonable controls for authentication, sessions, requests and uploaded files;
  • logging of material activity for security and accountability;
  • least-privilege personnel access and confidentiality duties;
  • separation of complete card processing to Lava.top;
  • incident investigation and legally required notification procedures; and
  • data minimisation, retention controls and deletion on valid instruction.

Annex 3 — Contact and execution

Processor: Individual Entrepreneur Grishechko Aleksei Sergeevich, INN 550407078302, OGRNIP 312554328400091, Office 417A, Building 2, 67 Pushkina Street, Omsk, Omsk Region, 644024, Russian Federation, support@tundraa.dev.

Customer: as identified in the Order Form, account or signature block. Electronic acceptance of an Order Form that incorporates this DPA constitutes signature to the extent permitted by applicable law.

TUNDRÄ © 2026
Terms Privacy Security Cookies Refunds Legal notice