Legal

Data Processing Agreement

Last updated: August 20, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer and Netrows Labs SL ("Netrows Labs", "we", "us", or "our") and reflects the parties' obligations under Article 28 of the GDPR (and equivalent provisions of other applicable data protection law) with respect to personal data that Netrows Labs processes on the Customer's behalf and instruction. This DPA does not apply to the third-party professional data made available through the API, since Netrows Labs is not a processor for that data on the Customer's behalf; that relationship is described in the Privacy Policy and the Terms of Service instead. Capitalized terms not defined here have the meaning given in the Terms of Service.

1. Purpose and incorporation

This DPA applies automatically to every Customer with an active account; no separate signature is required for it to take effect, in the same way the Terms of Service themselves take effect on account creation. A Customer that requires a countersigned copy for its own records can request one at support@kooperativa.io.

2. Definitions

  • "Customer Personal Data" means personal data that the Customer submits to, or that is generated within, the Services about the Customer's own workspace members, for example a member's name, email address, and role.
  • "Data Protection Law" means the GDPR and any other law applicable to the processing of Customer Personal Data under this DPA.
  • "Subprocessor" means a third party engaged by Netrows Labs to process Customer Personal Data in order to provide the Services, as listed in Section 6.
  • "Controller," "processor," "data subject," "personal data," and "processing" have the meanings given in the GDPR.

3. Roles of the parties

With respect to Customer Personal Data, the Customer is the controller and Netrows Labs is the processor, processing Customer Personal Data only on the Customer's documented instructions (which include the instructions embedded in the Terms of Service and this DPA, and any further instruction given through the dashboard, such as inviting a named member).

This DPA governs Customer Personal Data only. It does not govern the third-party professional Data made available through the API: for that Data, the Customer is an independent controller and Netrows Labs' role is described in Section 5 of the Privacy Policy, not in this document. That Data is limited to professional profile and firmographic information; Netrows Labs does not process personal contact details (email addresses or phone numbers) under this DPA or otherwise.

4. Details of the processing

  • Subject matter: provision of the Kooperativa API and dashboard to the Customer.
  • Duration: for as long as the Customer's account is active, and thereafter as described in Section 12.
  • Nature and purpose: account creation and authentication, workspace and license management, and delivery of the Services, as described in the Terms of Service.
  • Categories of data subjects: the Customer's workspace members (employees or contractors the Customer has invited).
  • Categories of Customer Personal Data: name, business email address, password (hashed), workspace role, and usage/log data tied to a member's account.

5. Netrows Labs' obligations as processor

Netrows Labs shall:

  • process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to do otherwise by law, in which case Netrows Labs will inform the Customer of that legal requirement first, unless prohibited from doing so;
  • ensure that personnel authorized to process Customer Personal Data are bound by a duty of confidentiality;
  • implement the security measures described in Section 7;
  • assist the Customer as described in Sections 8 and 9; and
  • make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA.

6. Subprocessors

The Customer provides general authorization for Netrows Labs to engage the following Subprocessors, each engaged under a written agreement imposing data protection obligations equivalent to those in this DPA:

  • Supabase — database and authentication (Zurich, Switzerland region);
  • Cloudflare — hosting, content delivery, and transactional email;
  • Stripe — payment processing (contracting entity: Stripe Payments Europe, Limited, Ireland).

Note on Hetzner. Netrows Labs also uses Hetzner to host the backend that stores and serves the professional data lake described in the Privacy Policy. Hetzner is intentionally not listed as a Subprocessor here: it never receives Customer Personal Data, since API requests to that backend carry only the search query itself (for example a profile identifier or company filter) and a platform-level credential, never the identity of the workspace member making the request. Hetzner is disclosed in Section 6 of the Privacy Policy, which is the correct place for a provider that only touches third-party professional data, not this DPA, which is scoped to Customer Personal Data as defined in Section 2.

Netrows Labs remains liable for a Subprocessor's acts and omissions to the same extent Netrows Labs would be liable if performing that Subprocessor's services directly. We will give the Customer reasonable advance notice, by email or through a notice on the Site or dashboard, before adding or replacing a Subprocessor that will process Customer Personal Data, and the Customer may object on reasonable data protection grounds within 14 days of that notice by contacting support@kooperativa.io; if the parties cannot resolve the objection, the Customer's remedy is to terminate the affected Services.

7. Security measures

Netrows Labs implements the technical and organizational measures described in Section 9 of the Privacy Policy, including encryption in transit and at rest, hashed credential storage, row-level security, and access limited to personnel who need it. These measures are designed to ensure a level of security appropriate to the risk, consistent with Article 32 GDPR.

8. Assistance with data subject requests

Taking into account the nature of the processing, Netrows Labs shall assist the Customer, insofar as reasonably possible, in responding to a data subject request concerning Customer Personal Data (access, rectification, erasure, restriction, portability, or objection). Where a request is received directly by Netrows Labs and clearly relates to Customer Personal Data controlled by the Customer, Netrows Labs will promptly forward it to the Customer rather than act on it directly, since the Customer is the controller for that data.

9. Personal data breach notification

Netrows Labs will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available at the time (nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed), updating that information as it becomes available. This notification obligation is separate from, and does not replace, any direct notification obligation the Customer may itself have as controller.

10. Audit rights

Netrows Labs will make available the information described in Section 5 to allow the Customer to verify compliance with this DPA, primarily through documentation, written responses to reasonable questionnaires, and the published Privacy Policy and Terms of Service. Where documentation is not sufficient, the Customer may request an on-site or remote audit of the specific processing covered by this DPA, no more than once per twelve-month period absent a specific reason to believe a breach has occurred, on reasonable advance written notice, during business hours, and subject to a confidentiality agreement; the Customer bears its own costs of the audit, and Netrows Labs may charge for the reasonable time and cost it incurs facilitating it.

11. International transfers

Where Netrows Labs or a Subprocessor transfers Customer Personal Data outside the European Economic Area, it does so under the safeguards described in Section 7 of the Privacy Policy (an EU adequacy decision, the Standard Contractual Clauses, or an equivalent recognized transfer mechanism), which are incorporated into this DPA by reference and apply equally to Customer Personal Data.

12. Return and deletion of data

On termination of the Services, Netrows Labs will delete Customer Personal Data in accordance with the retention periods described in Section 8 of the Privacy Policy, except to the extent a longer retention is required by applicable law (for example, billing records kept for tax purposes). The Customer may request export of its workspace's data before termination by contacting support@kooperativa.io.

13. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions set out in Section 17 of the Terms of Service, to the extent permitted by applicable law.

14. Term

This DPA takes effect on the date the Customer's account is created and remains in effect for as long as Netrows Labs processes Customer Personal Data on the Customer's behalf, notwithstanding the termination of the Terms of Service to the extent necessary to complete the obligations in Section 12.

Questions about this document? Contact us at support@kooperativa.io.