Version: 1.3
Last updated: 5 August 2026
Governing language: Dutch. In case of conflict, the Dutch version prevails.
This Data Processing Agreement (“DPA”) is entered into by and between:
the Customer (“Controller” or “you”), the organisation using Thalassa’s services;
and
Thalassa Cloud Services B.V., established in the Netherlands (“Processor”, “Thalassa”, or “we”).
This DPA forms part of the Terms of Service and related terms (“Terms”). It applies to the extent Thalassa processes Personal Data in Customer Content on behalf of the Customer.
By using the services, the Customer accepts this DPA. When terms are changed or new terms are introduced, the Customer receives a notification and must explicitly accept them when signing in to the console. Custom DPAs are available on request, for example for enterprise customers or via partners.
1. Definitions
- GDPR: Regulation (EU) 2016/679.
- Customer Content: data, content, workloads, snapshots, images, secrets, databases, log data and other resources that the Customer or its users place on the platform, or that are generated within the Customer’s workloads or directly derived therefrom.
- Account Data: organisation and billing data, (service) accounts, organisation IAM, support tickets, platform telemetry, platform-generated audit and access logs, and resource metadata (such as name and sizing). See the privacy policy.
- Personal Data, processing, data subject, personal data breach: as in the GDPR.
- Services: Thalassa’s public cloud services (IaaS/PaaS), including managed services.
- Sub-processor: another processor engaged by Thalassa that may process or affect Customer Content.
2. Scope and purpose
- This DPA applies only to Personal Data in Customer Content.
- Thalassa processes Customer Content solely to provide the Services — including managed services such as DBaaS, KMS and Secrets Manager. Processing is automated (storage, hosting and transmission).
- Thalassa has no access to Customer Content, unless the Customer explicitly grants it; typically only usage and resource metadata are visible.
- Thalassa does not make a standard backup of Customer Content. Data replication (such as zonal replication) serves platform continuity and is not a backup of Customer Content. Thalassa’s off-site backups contain only encrypted platform metadata.
- Types of data, data subjects and special categories are determined by what the Customer places in Customer Content.
- Processing lasts for as long as the Customer uses the Services. After deletion by the Customer, Customer Content is no longer available; actual destruction takes place asynchronously in the background.
3. Obligations of the Processor
Thalassa shall:
- Instructions. Process Personal Data in Customer Content only on documented instructions from the Customer, unless Thalassa is required to process by Union or Dutch law; in that case, Thalassa informs the Customer of that legal requirement before processing, unless the law prohibits this. Thalassa is a self-service platform: documented instructions consist of changes the Customer makes via the API. Those changes are processed automatically when valid credentials are used. The Customer may also request a change via a service desk ticket; Thalassa carries it out only after it has accepted the request. Thalassa immediately informs the Customer if, in its opinion, an instruction infringes the GDPR.
- Confidentiality. Ensure persons authorised to access Customer Content or Account Data are committed to confidentiality or under a statutory duty of confidentiality.
- Security. Implement appropriate measures under Article 32 GDPR, as in Annex A, without material degradation.
- 100% EU. Process Customer Content exclusively within the European Union. No transfers outside the EU.
- Access. Have no logical access to Customer Content, unless the Customer explicitly grants it (IAM invitation or written approval), for example for support.
- Disclosure. Not disclose Customer Content to third parties, unless disclosure is required by law or follows from a legally binding order of a court or authority. In case of a mandatory disclosure, Thalassa informs the Customer in advance, or otherwise as soon as possible thereafter, unless the law prohibits this, and limits the disclosure to what is strictly necessary.
- Sub-processors. Engage Sub-processors only under the conditions in Article 6 (including 100% EU and notice of changes).
- Assistance. Reasonably assist the Customer with data subject rights (GDPR Chapter III) and Articles 32–36 GDPR, insofar as possible given the nature of processing and available information.
- Audits. Make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR, and cooperate with audits by or on behalf of the Customer. To that end, Thalassa first provides available certifications, audit reports and documentation and answers additional questions. An on-site audit takes place at most once per twelve months, is announced at least 30 days in advance via the service desk, takes place at a mutually agreed time, is conducted under confidentiality, during business hours, at the Customer’s expense, without access to data of other customers and with minimal disruption to the services. Following a personal data breach affecting the Customer, or upon concrete indications of non-compliance, the frequency limitation does not apply.
4. Obligations of the Controller
The Customer shall:
- Comply with the GDPR in using the Services and in its own processing.
- Be responsible for the accuracy, quality and lawfulness of Customer Content and how it was obtained.
- Have a valid legal basis for Personal Data in Customer Content.
- Be responsible for all matters that fall to the Customer under the Shared responsibility model, including configuration, security, access management, secure handling of credentials (access tokens, API keys, passwords and the like), backup and continuity of its own workloads.
- Provide privacy notices to data subjects where that duty rests on the Customer.
- Export Customer Content before deletion or termination.
5. Security
- Thalassa ensures an appropriate level of security and continuity of the platform, in accordance with Article 32 GDPR. The measures are set out in Annex A and maintained via the ISMS. See also Platform security.
- Thalassa independently performs security testing on the platform.
- The Customer is responsible for security testing of its own workloads within its own organisation (Shared responsibility). Tests that could be seen as suspicious activity (such as penetration tests or vulnerability scans) must be reported in advance via the service desk. Scope, prohibited activities and Thalassa’s assistance are set out in Security assessments.
6. Sub-processors
- The Customer grants general written authorisation for the Sub-processors in Annex B.
- Thalassa engages only Sub-processors established in the European Union that process Customer Content exclusively within the EU (100% EU).
- Material changes of Sub-processors: notification at least 30 days in advance. The Customer may submit a reasoned objection via the service desk within that period. In urgent security or continuity cases, Thalassa informs as soon as reasonably possible.
- Sub-processors are bound by obligations at least equivalent to this DPA. Thalassa remains liable to the Customer for their performance to the extent required by the GDPR.
7. Personal data breaches
- After becoming aware of a breach affecting Customer Content, Thalassa will notify the Customer without undue delay and at the latest within 72 hours.
- The notification will include, where available: nature; categories and approximate numbers; likely consequences; measures taken or proposed. Missing information follows as soon as possible.
- The Customer is responsible for its own notification duties to authorities and data subjects.
8. Term, return and deletion
- This DPA applies for as long as the Customer uses the Services and ends when that service ends. Confidentiality continues to apply thereafter.
- Return. Return of Customer Content takes place by the Customer exporting it before deletion or termination (Article 4.6). On request via the service desk, Thalassa provides reasonable assistance with export and termination.
- Deletion. After termination of the services, Thalassa deletes all remaining Customer Content within 30 days, unless storage is required by Union or Dutch law. Thalassa does not independently keep copies or backups of Customer Content (Article 2.4). Account Data — including billing and usage data subject to a statutory retention duty of 7 years, and encrypted platform backups (approximately 28 days) — falls outside this DPA and is retained in accordance with the privacy policy.
- Liability under or in connection with this DPA is limited to the limitations in the Terms of Service.
9. Miscellaneous
- Notices. Notices under this DPA follow the notice provisions in the Terms of Service. Notices to Thalassa concerning this DPA should be sent to support@thalassa.cloud.
- Severability. If any provision of this DPA is found by a court or competent authority to be invalid, unenforceable or illegal, the other provisions remain in force.
- Entire agreement. This DPA, together with the Terms of Service and the privacy policy, constitutes the standard agreement between the Parties on this subject, subject to written additional agreements (custom DPAs).
- Precedence. Written additional agreements prevail over this standard DPA. On conflict between this DPA and the other Terms regarding processing of Customer Content, this DPA prevails, except liability (which follows the Terms of Service).
- Amendments. Thalassa may amend this DPA. The Customer receives prior notification and must explicitly accept the change within 30 days when signing in to the console, or submit a reasoned objection within that period via the service desk. In case of a timely objection, the Parties will consult; until a resolution is reached, the most recently accepted version continues to apply. If the consultation does not lead to a resolution, both the Customer and Thalassa may terminate the services in accordance with the Terms of Service. If the Customer neither accepts nor objects, continued use of the Services after expiry of the period constitutes acceptance of the amended DPA.
- Governing law. This DPA is governed by Dutch law. Disputes are submitted to the competent court in Arnhem.
Annex A — Technical and organisational measures
This Annex forms part of the DPA and describes the measures Thalassa implements.
Thalassa implements and maintains appropriate technical and organisational measures to protect Customer Content against unauthorised or unlawful destruction, loss, alteration, disclosure or access. The measures ensure a level of security appropriate to the risk.
| Domain | Measures |
|---|
| Access control | - Personal accounts, least privilege and periodic access review
- MFA required for privileged access, where technically possible
- No logical access to Customer Content, unless explicitly granted by the Customer (IAM invitation or written approval)
|
| Encryption | - Encryption in transit (TLS) for data over public networks
- Encryption at rest (AES-256 or better) for platform-managed storage, services and platform backups
- Controlled key management
|
| Network and isolation | - Tenant isolation (VPC) and network segmentation, including environment separation
- Edge DDoS mitigation and rate limiting
- Private management paths; multi-zone for platform resilience
|
| Logging and monitoring | - Logging of authentication, privileged use and security-relevant events
- Central logging with protection against unauthorised alteration
- Monitoring and alerting linked to the incident process
|
| Physical security and media | - Netherlands datacentre colocation with physical access control
- Colocation provider without standard logical access to Customer Content
- Secure destruction or wiping of media on disposal
|
| Personnel | - Screening (including certificates of conduct where applicable) and confidentiality obligations
- Periodic security and privacy awareness
- Controlled onboarding and offboarding
|
| Suppliers and Sub-processors | - Risk-based selection and assessment
- Contractual safeguards (including DPAs) where needed
- Processing of Customer Content exclusively within the EU; periodic reassessment of critical suppliers
|
| Incidents and personal data breaches | - Formal incident and breach process
- Notification to the Customer if Customer Content is affected
|
| Availability and continuity | - Multi-zone data replication for platform continuity (no standard backup of Customer Content)
- Encrypted platform backups (metadata/control plane)
- Business continuity and recovery arrangements, exercised periodically
|
| Secure development and change | - Security-by-design in development and architecture
- Change management with review before production
- Vulnerability and dependency management; SBOM’s
- Separated development, test and production environments
|
| Governance | - ISO 27001-aligned ISMS and risk management
- Periodic reviews and continual improvement
|
See also: Platform security.
Annex B — Sub-processors
| Party | Location | Service |
|---|
| BIT B.V. | Netherlands | Colocation, datacentre facilities and network connectivity |
All listed Sub-processors process within the European Union.