Data Processing Agreement
Last updated: April 23, 2026
This Data Processing Agreement ("DPA") applies to the processing of personal data by EasySchema ("Processor") on behalf of Customer ("Controller") when using EasySchema's services. It supplements our Terms of Service and Privacy Policy.
Note: Customers who require a signed data processing agreement should email legal@easyschema.xyz.
1. Definitions
Terms used in this DPA have the meanings given in the GDPR (Regulation (EU) 2016/679) or equivalent local law. In particular:
- Controller — you, the Customer, who determines the purposes and means of processing personal data.
- Processor — EasySchema, which processes personal data on your behalf.
- Personal Data — any information relating to an identified or identifiable natural person.
- Sub-processor — a third party engaged by EasySchema to process personal data.
2. Scope and Roles
You are the Controller of personal data you submit to EasySchema (API request bodies, webhook payloads, workspace member information, etc.). EasySchema is the Processor, processing such data only on your documented instructions, which are set out in our Terms of Service and your configuration of the service.
3. Categories of Data
EasySchema may process the following categories of personal data on your behalf:
- Account data — email address, name, and authentication tokens of the account holder
- Request data — content of API requests you make through the proxy, including headers, bodies, and responses
- Webhook data — payloads sent to your webhook capture URLs
- Documentation data — content you publish in documentation sites
Data subjects are your end users, workspace members, and any individuals whose data is embedded in requests or webhooks you process.
4. Processor Obligations
EasySchema will:
- Process personal data only on your documented instructions
- Ensure personnel with access to data are bound by confidentiality
- Implement appropriate technical and organizational security measures (see Section 7)
- Assist you in responding to data subject requests
- Notify you without undue delay of any personal data breach
- At your choice, delete or return personal data at the end of the service
- Make available information necessary to demonstrate compliance
5. Sub-processors
You authorize EasySchema to engage the following sub-processors:
- Tringify Billing — payment processing (for paid plans)
- CockroachDB / database hosting — primary data storage
- CDN and infrastructure providers — asset delivery and compute
- Email service provider — transactional email delivery
We will provide 30 days' notice before engaging a new sub-processor. You may object by terminating your subscription before the new sub-processor begins processing your data.
6. International Transfers
Personal data may be transferred outside your jurisdiction. Where such transfers involve EU/UK/Swiss data to third countries, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms.
7. Security Measures
We implement the following technical and organizational measures:
- Encryption of data in transit (TLS 1.2+) and at rest
- Role-based access controls with least-privilege principles
- Identity verification through Tringify, with account security controls managed by the identity provider
- Regular security reviews and vulnerability management
- Incident response procedures
- Audit logging of administrative and data-access actions
- Secure software development lifecycle practices
For more detail, see our Security Policy.
8. Data Subject Rights
You are responsible for responding to data subject requests (access, rectification, erasure, portability). EasySchema provides tools to help: workspace owners can export, modify, and delete their data directly. For bulk requests, contact privacy@easyschema.xyz.
9. Data Breach Notification
In the event of a personal data breach affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware. Notification will include the nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed.
10. Audits
We make available to you information reasonably necessary to demonstrate compliance with this DPA. For Enterprise customers, we accommodate reasonable audit requests on mutually agreed terms, subject to confidentiality obligations.
11. Data Return and Deletion
On termination of the service:
- You can export your data through the application before your account is closed
- We delete personal data within 90 days of account closure unless legal obligations require longer retention
- Backups containing your data are overwritten in the normal rotation cycle
12. Liability
Each party's liability under this DPA is subject to the limitations of liability in our Terms of Service.
13. Governing Law
This DPA is governed by the laws specified in our Terms of Service.
14. Contact
For data protection inquiries: privacy@easyschema.xyz
For signed DPA requests: legal@easyschema.xyz