Perfect Cut

Data Processing Agreement

Effective

1. Parties, precedence and scope

This Data Processing Agreement (DPA) is between the Perfect Cut business customer as controller (Customer) and Andreas Ehrhardt, trading as PurePortal, Hohenzollernstraße 17, 72172 Sulz am Neckar, Germany, as processor (PurePortal). It forms part of the Perfect Cut contract when accepted during account creation or checkout. It prevails over conflicting terms for processing customer personal data.

It applies only where PurePortal processes personal data contained in Customer-controlled teams, projects, imports, quotes, custom fields, catalogs or instructions on Customer’s behalf. PurePortal is a separate controller for accounts, security, service administration, billing, legal compliance and support as described in the Privacy Notice.

2. Processing details

2. Processing details
ItemDescription
Subject and durationHosting and operation of Perfect Cut for the contract term, plus export, retrieval, deletion and legally required retention periods
Nature and purposeCollection, storage, organisation, retrieval, calculation, display, export, sharing at Customer direction, support, security, backup/recovery and deletion for cutting-planning collaboration
Data subjectsCustomer personnel, invited users, business contacts, suppliers or customers referenced in project/quote/catalog data, and other persons whose data Customer submits
Data typesNames, business contact and account identifiers, team roles, project/customer references, labels, notes, custom metadata, quotes, catalog content, uploaded images, usage/audit data and any personal data Customer chooses to include

No special-category or criminal-offence data is required for Perfect Cut. Customer must not submit such data unless it is necessary, lawful and protected by documented additional instructions agreed with PurePortal.

3. Documented instructions

PurePortal processes customer personal data only on documented instructions, including the contract, Customer’s in-product configuration, authorised user actions and support requests, unless Union or Member State law requires otherwise. In that case PurePortal informs Customer before processing unless the law prohibits notice. PurePortal immediately informs Customer if it considers an instruction to infringe data-protection law and may pause that instruction pending clarification.

Customer is responsible for the lawfulness, accuracy and transparency of its instructions and data; data-subject notices; legal bases; access permissions; and responding to rights requests as controller.

4. Confidentiality and security

PurePortal ensures that persons authorised to process customer personal data are bound by confidentiality and receive access only as needed. Taking account of the state of the art, costs, scope, context and risk, PurePortal maintains appropriate technical and organisational measures under Article 32 GDPR.

  • TLS transport security; one-way hashing for passwords and one-time credentials; HTTP-only, same-site session cookies.
  • Role- and tenant-based access controls, team permissions, optional Enterprise OIDC, restricted administrative access and lifecycle controls.
  • Input validation, rate limiting, security/audit events, dependency and change controls, and protected secret handling.
  • Availability, recovery and incident-handling processes appropriate to the hosted service; encrypted storage for sensitive billing event payloads.
  • Account deletion/anonymisation, delayed team deletion controls and supported export processes.
  • Periodic review and improvement of measures based on risk and service changes.

5. Subprocessors

Customer gives general written authorisation for the subprocessors below. PurePortal remains responsible for their data-protection obligations and binds each subprocessor by requirements no less protective than this DPA for the relevant processing.

5. Subprocessors
SubprocessorLocationTask and data
Hetzner Online GmbHIndustriestraße 25, 91710 Gunzenhausen, GermanyApplication, database and server hosting; customer content, uploaded images and technical logs. The selected data-centre location must be confirmed in the deployment record
Cloudflare, Inc.101 Townsend Street, San Francisco, CA 94107, USA; global network with Chapter V transfer safeguardsDNS, reverse proxy, TLS, network delivery and security; IP addresses, request/security metadata and transient proxied content
Zoho Corporation B.V. and approved Zoho service affiliates/subprocessorsBeneluxlaan 4B, 3527 HT Utrecht, Netherlands; limited safeguarded third-country support/subprocessingTransactional email delivery; recipient, message content and delivery metadata

Stripe and Sold through Link provide Managed Payments and billing services and do not process Customer team content as subprocessors under this DPA. A Customer-configured identity provider is selected and instructed by Customer and is not appointed by PurePortal as a general subprocessor.

Backblaze and OpenAI are planned only and are not authorised or engaged as active subprocessors under this list. Before either receives Customer personal data, PurePortal must complete the applicable DPA and transfer/security assessment, add the service to this list and give the advance notice below. The PurePortal-operated Swetrix instance uses existing infrastructure and does not add a separate analytics-vendor recipient; any new hosting provider would be listed before use.

PurePortal will give reasonable advance notice of a new or replacement subprocessor by email or in-product notice. Customer may object on documented data-protection grounds before the change. The parties will seek a reasonable solution; if none is available, Customer may stop the affected processing or terminate the affected service without penalty before the change takes effect.

6. International transfers

PurePortal will not transfer customer personal data outside the EEA unless instructed by Customer or protected by an adequacy decision, the European Commission’s standard contractual clauses or another lawful Chapter V mechanism. PurePortal will assess supplementary measures where required and provide relevant safeguard information on request, subject to confidentiality and security limits.

7. Assistance

Taking account of the nature of processing, PurePortal assists Customer through service functions and reasonable support with data-subject requests, security under Articles 32–36 GDPR, data-protection impact assessments and prior consultation. If a data subject contacts PurePortal about Customer-controlled data, PurePortal forwards the request where it can identify Customer and does not respond substantively unless authorised or legally required.

8. Personal-data breaches

PurePortal notifies Customer without undue delay after becoming aware of a personal-data breach affecting customer personal data. As information becomes available, the notice describes the nature and likely consequences, categories and approximate numbers affected, measures taken or proposed, and a contact point. PurePortal investigates, mitigates and preserves appropriate evidence. Customer is responsible for notifications it must make as controller.

9. Return and deletion

During the contract Customer can use available exports. On termination or switching, and at Customer’s choice, PurePortal returns exportable customer data and then deletes it, or deletes it directly, in accordance with the Data Portability and Switching Register. PurePortal may retain data where Union or Member State law requires retention, solely for that purpose and isolated from ordinary use. Residual backup copies are protected and expire through the applicable backup cycle.

10. Information and audits

PurePortal makes information necessary to demonstrate Article 28 compliance available to Customer. Customer may audit no more than once per year, and additionally after a material incident or regulator request, on reasonable notice and during business hours. The parties first use current documentation and remote review. An on-site auditor must be independent, qualified and bound by confidentiality and must not access another customer’s data or compromise security. Customer bears its audit costs unless the audit identifies a material breach by PurePortal.

11. Duration and contact

This DPA lasts while PurePortal processes customer personal data. The obligations concerning confidentiality, security, deletion and evidence survive as required. Operational instructions and processor requests must be sent by an authorised Customer administrator to [email protected].