Legal
Data Processing Agreement
This Data Processing Agreement (DPA) applies only to Store mode (account, login, published workflows) described in the Privacy Policy. In local mode there is no processing of your personal data, and this DPA does not apply. By enabling the Store and using the Service, you and Freddy Encinas ("the Processor") accept this DPA as part of the Terms.
01Definitions
"Personal Data", "Controller", "Processor", "Sub-processor" and "Data Transfer" have the meaning given by the EU General Data Protection Regulation (GDPR). Under this Agreement, you are the Controller of your own users' data (if you publish workflows involving third-party data) and Freddy Encinas is the Processor that processes account data on your behalf through the Store's infrastructure.
02Purpose of agreement
This DPA clarifies the Processor's obligations regarding the processing of Personal Data within the Skuade Store. In case of conflict between this DPA and the Terms, this DPA prevails solely with respect to the processing of personal data.
03Categories of data & data subjects
Data subjects: users who enable the Store and sign in. Data categories: email address, Google profile name and avatar (if applicable), Google identifier (sub), hashed session token, and the content of published workflows. No special categories of data (Art. 9 GDPR) are processed.
04Processing only on documented instructions
The Processor processes Personal Data solely to provide the Store (creating accounts, authenticating sessions, publishing and distributing workflows) as described in the Privacy Policy, and does not use it for any other purpose of its own.
05Duration
Processing lasts as long as you have an active Store account. Upon account deletion, the Processor deletes or anonymizes Personal Data pursuant to Section 12.
06Processor's obligations
- Process Personal Data only on documented instructions (this Privacy Policy and this DPA).
- Provide reasonable assistance with data subject rights requests (access, deletion, portability).
- Ensure any international transfer meets a valid mechanism (Section 9).
- Notify the Controller if an instruction, in its judgment, violates the GDPR.
07Data secrecy
The Processor maintains appropriate technical and organizational measures to protect the confidentiality, integrity and availability of Personal Data, described in Section 13.
08Audit rights
The Controller may request reasonable information about compliance with this DPA in writing, with 15 days' notice. Since this is a single-developer project with no infrastructure of its own beyond Cloudflare, verification is limited to documentation (this DPA, Cloudflare's DPA, and public configuration) rather than on-site audits.
09Mechanism of data transfers
Any transfer of Personal Data outside the European Economic Area is covered by the Standard Contractual Clauses (SCCs) incorporated in Cloudflare's Data Processing Addendum, supplemented by the additional technical measures Cloudflare documents publicly.
10Sub-processors
The Processor uses a single sub-processor for the Store's infrastructure:
- Cloudflare, Inc. (Workers, D1, Email Routing) — database hosting, compute and email sending. United States, under SCCs.
Google acts as an identity provider, not a sub-processor, when you choose to sign in with Google. Any sub-processor change will be notified with 30 days' notice via an update to this page. The Processor remains liable for the sub-processor's compliance.
11Personal data breach notification
The Processor will notify without undue delay any security breach affecting Personal Data, and will provide reasonable assistance with any resulting notifications and remediation. Notification does not, by itself, constitute an admission of liability.
12Return & deletion of personal data
Upon account deletion, the Processor deletes Personal Data from the Store's database within 30 days. Published workflows already downloaded by other users may persist in their local copies, outside the Processor's control.
13Technical & organizational measures
- Session tokens stored as SHA-256 hashes, never in plaintext.
- OAuth secrets stored as Cloudflare secrets, never in code or on the client.
- Atomic single-use consumption for magic links (prevents race conditions).
- Store publishing subject to moderation before becoming publicly visible.
- Rate limiting on write and read routes to prevent abuse.
14Contact
For questions about this DPA: