Data Processing Addendum

Effective date: 3 October 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer", controller) and Stanislav Sysoiev, sole trader (CEIDG), ul. Lwowska 6G/25, 61-131 Poznań, Poland, NIP 7822934324, REGON 527330815, operating BackupLatte ("BackupLatte", processor), and applies to personal data BackupLatte processes on the Customer's behalf where the Customer acts as a controller under the GDPR. Where the Customer is itself a processor acting for another controller (for example an agency managing a client's workspace), the Customer confirms that this controller has authorised it to use BackupLatte, BackupLatte acts as its subprocessor on the terms of this DPA, and the Customer passes on that controller's instructions. It is intended to meet Article 28 of the GDPR (EU 2016/679) and the UK GDPR.

It takes effect when the Customer accepts the Terms. A countersigned copy is available on request at [email protected].

1. Details of processing

Subject matterBackup of the Customer's Linear workspace and restore of that data into Linear at the Customer's request
DurationFor the term of the Terms, plus the deletion periods in section 9
Nature and purposeRetrieving data via the Linear API and copying the files hosted by Linear that this data links to, compressing and storing it, making it available for download (per dataset, per file, or as a ZIP of a whole backup), and writing part of it back to Linear during a restore
Categories of data subjectsMembers, guests and other users of the Customer's Linear workspace; people recorded in the Customer's Linear customer records and requests; people invited to the workspace (only with extended coverage, see below); any person mentioned in the workspace's content
Categories of personal dataLinear user ID, name, display name, email address, avatar, title, timezone, status, account status (active/admin/guest), team memberships and on-call schedule entries; authorship, assignment, subscriptions and reactions on workspace content; the history of changes to issues, projects, initiatives and releases, and earlier versions of documents (who changed what and when); names, domains and other details of the Customer's customers and their requests as recorded in Linear; any personal data the Customer's users write in the workspace's content (issues, comments, documents, projects, initiatives, updates, releases, posts, views, templates and conversations with Linear agents) or place in files attached to it. Only if the Customer enables extended coverage (which grants Linear's admin access): audit log entries (actor, IP address, country and request details), invitations (invitee email and role), workspace settings, and integration and webhook metadata — never credentials, webhook URLs or secrets
Special categoriesNot intended. The Customer should not store special-category data in Linear content that is backed up; if it does, it is processed only as stored content
Processing locationServers in Falkenstein, Germany; backup storage in Cloudflare R2 under the EU jurisdiction setting; see section 8 and the subprocessor list

2. Instructions

BackupLatte processes Customer personal data only on the Customer's documented instructions, including for international transfers. Those instructions are the Terms, this DPA, and the Customer's configuration and actions in the Service (connected workspaces, schedule, retention, manual backups, downloads, restores and deletions). If EU, Member State or UK law requires other processing, we will inform the Customer before it takes place unless that law prohibits notice. BackupLatte will immediately inform the Customer if it believes an instruction infringes data protection law.

3. Confidentiality

Everyone authorised by BackupLatte to process Customer personal data is bound by confidentiality. Only the owner has access to the production systems: servers, storage and service accounts.

4. Security

BackupLatte implements the measures in Annex 1 and may update them as long as the overall level of protection is not reduced.

5. Subprocessors

This section covers the processors BackupLatte engages to process Customer personal data, listed as subprocessors at /subprocessors. It does not cover Linear, which the Customer itself connects, or Paddle, which acts as an independent controller for payments and does not receive Customer personal data from Linear.

The Customer gives general authorisation for the listed subprocessors. BackupLatte will give at least 30 days' notice of any new or replaced subprocessor by updating that page and emailing account holders. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve it, the Customer may terminate and receive a refund of any prepaid, unused period. BackupLatte imposes data protection obligations on each subprocessor that are equivalent in substance to this DPA, and remains responsible for them.

6. Assistance

Taking into account the nature of processing, BackupLatte will help the Customer respond to data subject requests, and with security, breach notification, data protection impact assessments and prior consultation, to the extent the Customer cannot do so using the Service itself. Data subject requests received directly will be forwarded to the Customer without undue delay.

7. Personal data breaches

BackupLatte will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer personal data. The notice will include what is known of the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed, with updates as more becomes known.

8. International transfers

Stored backups remain in the EU. Processing by subprocessors outside the EEA or the UK (for example Cloudflare's global network carrying requests) relies on the safeguards in each subprocessor's data processing terms — for Cloudflare, the EU Standard Contractual Clauses, the UK Addendum and the EU–US Data Privacy Framework. Details are available on request.

9. Return and deletion

10. Audits

BackupLatte will make available the information necessary to demonstrate compliance with this DPA, primarily by answering reasonable written questionnaires. The Customer may also audit our processing, itself or through an auditor it mandates, subject to confidentiality and safeguards for other customers' data. Routine audits normally require 30 days' notice, take place during business hours and occur no more than once a year. These routine limits do not apply when an audit is reasonably needed to investigate a credible compliance concern, follows a personal data breach affecting the Customer, or is required by a supervisory authority. In those cases we will cooperate within the time the authority requires or as soon as reasonably possible.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms, to the extent permitted by law. If this DPA conflicts with the Terms regarding personal data, this DPA prevails.


Annex 1 — Technical and organisational measures

Describes what is in place as of the effective date.

Network and access

Encryption

Isolation and integrity

Availability and resilience

Minimisation and deletion

Organisational