Data Processing Agreement
The Article 28 GDPR agreement under which NinetoSix GmbH processes personal data on your instructions.
- Version:
- 2026-08-15
- In force since:
- 2026-08-15
- Last updated:
- 2026-08-15
This agreement is concluded between you as the controller and NinetoSix GmbH as the processor. It forms part of the terms of service and applies whenever the content you place on Dropable contains personal data.
It is concluded together with the terms of service and requires no separate signature.
1. Parties and subject matter
- Controller
- You, the business operating the workspace
- Processor
- NinetoSix GmbH, Willy-Brandt-Platz 4, 90402 Nürnberg, Germany
- Contact
- legal@dropable.io
The subject matter is the processing of personal data that we carry out on your behalf when providing Dropable: storing the files you upload, generating previews and other derivatives, delivering content to the recipients you designate, and operating the access, review and notification functions you use.
Where you present the service to your own clients under your own brand or domain, you remain the controller toward those clients and we remain your processor.
2. Duration
This agreement begins when you accept the terms of service and continues for as long as we process personal data on your behalf. It ends with the end of the main agreement, subject to the deletion obligations in the section on deletion and return.
3. Nature, purpose and categories
Nature and purpose
Collection, storage, organisation, adaptation, retrieval, transmission and erasure of personal data, exclusively for the purpose of providing the contractually agreed service.
Categories of data subjects
- Your employees and other members of your workspace
- Your clients and their members whom you invite
- Recipients of share links you create
- Persons depicted or otherwise identifiable in the content you upload
Categories of personal data
- Contact and identification data: name, email address, profile picture
- Access and usage data: authentication events, access to files and share links, comments and review decisions
- Content data: the files you upload, including any personal data they contain
- Technical data: IP addresses processed briefly for rate limiting and abuse detection
4. Processing on instructions
We process personal data only on your documented instructions, including with regard to transfers to third countries, unless we are required to process by Union or Member State law. In that case we will inform you of that legal requirement before processing, unless the law prohibits it.
This agreement, the terms of service, and your use of the functions the service provides together constitute your initial and ongoing instructions. Further instructions must be issued in text form to legal@dropable.io.
We will inform you without undue delay if, in our opinion, an instruction infringes data protection law. We may suspend execution of that instruction until you confirm or amend it.
5. Confidentiality
We ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. That commitment survives the end of their engagement.
Access to personal data processed on your behalf is limited to those persons who need it to provide or maintain the service.
6. Security of processing
We implement appropriate technical and organisational measures under Article 32 GDPR. The measures in force are set out in the annex to this agreement.
We may change individual measures to reflect technical developments, provided the level of protection is not reduced.
7. Subprocessors
You grant general authorisation for the engagement of subprocessors. The subprocessors currently engaged are published at https://dropable.io/subprocessors, together with their purpose, processing location and transfer basis.
We will inform you at least 30 days before adding or replacing a subprocessor. You may object to the change on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the service with effect from the date the change would take effect.
We impose on every subprocessor, by contract, data protection obligations equivalent to those in this agreement, and we remain fully liable to you for their performance.
8. Assistance with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests for the exercise of data subject rights.
Where a data subject contacts us directly about data we process on your behalf, we will not act on the request ourselves. We will forward it to you without undue delay and refer the data subject to you.
The service provides functions for retrieving, correcting, exporting and deleting content, so that you can fulfil most requests yourself.
9. Further assistance
We assist you in complying with your obligations under Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to us.
We will notify you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf, and will provide the information you need to make your own notification under Article 33 GDPR.
10. Deletion and return
You may export your content at any time during the agreement using the functions provided in the service. This constitutes the return of the data.
After the end of the agreement we retain your content for 30 days so that you can still retrieve it, and then delete it irreversibly, including generated derivatives and video assets held with our subprocessors.
Data that we are required by Union or Member State law to retain is excluded from deletion. We restrict its processing to that legal purpose.
11. Audits and demonstration of compliance
We make available to you the information necessary to demonstrate compliance with Article 28 GDPR.
You may satisfy your audit right primarily by reviewing the documentation we provide, including this agreement, the annex of technical and organisational measures, the subprocessor list, and any certifications or audit reports available from our subprocessors.
Where that is not sufficient, you may conduct an on-site inspection during business hours, after reasonable advance notice, at most once per year unless there is specific cause. The inspection must not disrupt operations or compromise the confidentiality of other customers' data. You bear your own costs; we may charge for a disproportionate effort on our side.
12. Transfers to third countries
Personal data is processed within the European Union wherever possible. Where a subprocessor processes data in a third country, that transfer is based on an adequacy decision by the European Commission or on standard contractual clauses under Article 46(2)(c) GDPR together with additional safeguards.
The basis applying to each subprocessor is stated at https://dropable.io/subprocessors.
13. Final provisions
In the event of a conflict between this agreement and the terms of service, this agreement prevails in matters of data protection.
Should a provision of this agreement be or become invalid, the validity of the remaining provisions is unaffected.
German law applies, and the place of jurisdiction is the one agreed in the terms of service.
14. Annex: technical and organisational measures
The measures below are those in force under Article 32 GDPR. They are implemented partly by us and partly by our infrastructure subprocessors.
| Area | Measures |
|---|---|
| Access control (physical) | Operation exclusively in certified data centres of our infrastructure providers. We operate no own server hardware. |
| Access control (system) | Authentication by passkey and single-use email link; no passwords are used or stored. Access to production systems is limited to the persons who need it and uses separate credentials from the application. |
| Access control (data) | Separation of data by workspace enforced in the database itself through row-level security, so authorisation does not depend on application code being correct. Role-based permissions within a workspace. |
| Transmission control | Encrypted transport for all connections. Stored data encrypted at rest by the infrastructure providers. File access through short-lived signed links rather than public addresses. |
| Input control | Recording of security-relevant actions within a workspace, including membership and permission changes, attributable to the acting user. |
| Availability control | Managed, redundant infrastructure with automated backups by the database provider; content delivery through a distributed network. |
| Separation control | Every record carries its workspace, and cross-workspace access is denied by database policy rather than by filtering in the application. |
| Instruction control | Subprocessors bound by data processing agreements; this agreement and the service functions constitute the documented instructions. |
| Review and evaluation | Automated tenant isolation tests, security advisories from the database provider, and dependency and configuration checks as part of the release process. |