Data Processing Addendum
Effective date: 3 October 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer", controller) and Stanislav Sysoiev, sole trader (CEIDG), ul. Lwowska 6G/25, 61-131 Poznań, Poland, NIP 7822934324, REGON 527330815, operating BackupLatte ("BackupLatte", processor), and applies to personal data BackupLatte processes on the Customer's behalf where the Customer acts as a controller under the GDPR. Where the Customer is itself a processor acting for another controller (for example an agency managing a client's workspace), the Customer confirms that this controller has authorised it to use BackupLatte, BackupLatte acts as its subprocessor on the terms of this DPA, and the Customer passes on that controller's instructions. It is intended to meet Article 28 of the GDPR (EU 2016/679) and the UK GDPR.
It takes effect when the Customer accepts the Terms. A countersigned copy is available on request at [email protected].
1. Details of processing
| Subject matter | Backup of the Customer's Linear workspace and restore of that data into Linear at the Customer's request |
| Duration | For the term of the Terms, plus the deletion periods in section 9 |
| Nature and purpose | Retrieving data via the Linear API and copying the files hosted by Linear that this data links to, compressing and storing it, making it available for download (per dataset, per file, or as a ZIP of a whole backup), and writing part of it back to Linear during a restore |
| Categories of data subjects | Members, guests and other users of the Customer's Linear workspace; people recorded in the Customer's Linear customer records and requests; people invited to the workspace (only with extended coverage, see below); any person mentioned in the workspace's content |
| Categories of personal data | Linear user ID, name, display name, email address, avatar, title, timezone, status, account status (active/admin/guest), team memberships and on-call schedule entries; authorship, assignment, subscriptions and reactions on workspace content; the history of changes to issues, projects, initiatives and releases, and earlier versions of documents (who changed what and when); names, domains and other details of the Customer's customers and their requests as recorded in Linear; any personal data the Customer's users write in the workspace's content (issues, comments, documents, projects, initiatives, updates, releases, posts, views, templates and conversations with Linear agents) or place in files attached to it. Only if the Customer enables extended coverage (which grants Linear's admin access): audit log entries (actor, IP address, country and request details), invitations (invitee email and role), workspace settings, and integration and webhook metadata — never credentials, webhook URLs or secrets |
| Special categories | Not intended. The Customer should not store special-category data in Linear content that is backed up; if it does, it is processed only as stored content |
| Processing location | Servers in Falkenstein, Germany; backup storage in Cloudflare R2 under the EU jurisdiction setting; see section 8 and the subprocessor list |
2. Instructions
BackupLatte processes Customer personal data only on the Customer's documented instructions, including for international transfers. Those instructions are the Terms, this DPA, and the Customer's configuration and actions in the Service (connected workspaces, schedule, retention, manual backups, downloads, restores and deletions). If EU, Member State or UK law requires other processing, we will inform the Customer before it takes place unless that law prohibits notice. BackupLatte will immediately inform the Customer if it believes an instruction infringes data protection law.
3. Confidentiality
Everyone authorised by BackupLatte to process Customer personal data is bound by confidentiality. Only the owner has access to the production systems: servers, storage and service accounts.
4. Security
BackupLatte implements the measures in Annex 1 and may update them as long as the overall level of protection is not reduced.
5. Subprocessors
This section covers the processors BackupLatte engages to process Customer personal data, listed as subprocessors at /subprocessors. It does not cover Linear, which the Customer itself connects, or Paddle, which acts as an independent controller for payments and does not receive Customer personal data from Linear.
The Customer gives general authorisation for the listed subprocessors. BackupLatte will give at least 30 days' notice of any new or replaced subprocessor by updating that page and emailing account holders. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve it, the Customer may terminate and receive a refund of any prepaid, unused period. BackupLatte imposes data protection obligations on each subprocessor that are equivalent in substance to this DPA, and remains responsible for them.
6. Assistance
Taking into account the nature of processing, BackupLatte will help the Customer respond to data subject requests, and with security, breach notification, data protection impact assessments and prior consultation, to the extent the Customer cannot do so using the Service itself. Data subject requests received directly will be forwarded to the Customer without undue delay.
7. Personal data breaches
BackupLatte will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer personal data. The notice will include what is known of the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed, with updates as more becomes known.
8. International transfers
Stored backups remain in the EU. Processing by subprocessors outside the EEA or the UK (for example Cloudflare's global network carrying requests) relies on the safeguards in each subprocessor's data processing terms — for Cloudflare, the EU Standard Contractual Clauses, the UK Addendum and the EU–US Data Privacy Framework. Details are available on request.
9. Return and deletion
- During the Terms, the Customer can download its backups until they expire, and can delete a workspace at any time: its records are removed immediately and its backup files within 2 days. Backups otherwise expire at the end of the retention period the Customer sets (1–365 days). Files copied from Linear are stored once and shared by the backups that contain them; each is deleted by the daily cleanup once no remaining backup contains it. A ZIP export of a backup is kept for up to 7 days and never longer than the backup itself.
- Cancelling a subscription does not end this DPA: the account, its connected workspaces and existing backups remain, and backups keep expiring under the retention setting, until the account is closed.
- When the account is closed (at the Customer's request or on termination of the Terms), the Customer chooses return or deletion: before closing, it can download all existing backups; BackupLatte then deletes all Customer personal data within 30 days — account, workspaces, backups (queued for storage deletion in the same transaction), failed-job diagnostics, and queue records (removed by an hourly cleanup, including those of a job that was still running). Disaster-recovery copies of the database normally expire about 15 days after that. Data BackupLatte must retain by law is kept only for that purpose.
- While access is suspended (for example for non-payment), existing backups stay downloadable until they expire under the retention setting.
- If BackupLatte terminates the Terms, it gives at least 30 days' notice by email, unless the law or a serious breach requires earlier termination. During that period the Customer can download all existing backups, and on request to [email protected] BackupLatte provides them as ZIP exports.
- Confirmation. On request, BackupLatte confirms by email that the deletion is complete.
10. Audits
BackupLatte will make available the information necessary to demonstrate compliance with this DPA, primarily by answering reasonable written questionnaires. The Customer may also audit our processing, itself or through an auditor it mandates, subject to confidentiality and safeguards for other customers' data. Routine audits normally require 30 days' notice, take place during business hours and occur no more than once a year. These routine limits do not apply when an audit is reasonably needed to investigate a credible compliance concern, follows a personal data breach affecting the Customer, or is required by a supervisory authority. In those cases we will cooperate within the time the authority requires or as soon as reasonably possible.
11. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms, to the extent permitted by law. If this DPA conflicts with the Terms regarding personal data, this DPA prevails.
Annex 1 — Technical and organisational measures
Describes what is in place as of the effective date.
Network and access
- Backend services (API, worker, database, queue) have no published ports. Requests reach the API only through a Cloudflare tunnel; the API gateway rejects requests without a secret header added by our edge proxy.
- Database and queue run on internal container networks not reachable from the internet.
- Server administration over SSH with key-based authentication only; password and root logins are disabled, and a firewall admits SSH only from the operator's addresses.
- Admin functions in the app require an admin flag that can only be granted with a server-side command.
Encryption
- TLS between browsers and Cloudflare, and for connections to Linear and to R2 storage. The Cloudflare tunnel to the server is encrypted; traffic between containers on the server stays on internal networks and is not separately encrypted.
- Linear OAuth tokens encrypted at rest with AES-256-GCM, with the key held outside the database.
- Passwords hashed with bcrypt; refresh tokens stored in the database only as hashes.
- Backups stored in Cloudflare R2, which encrypts all objects at rest; buckets are private and downloads use short-lived signed links.
Isolation and integrity
- Every backup, download and restore is scoped to the owning account; ownership is checked on every API request.
- Application containers (API, worker, gateway) run as non-root users with read-only root filesystems; all containers drop Linux capabilities by default, and the database, queue and gateway add back only the specific capabilities they need.
- Rate limiting on authentication, backup and restore endpoints.
- Restore progress is saved as it runs, and each restored record has an identifier tied to the target workspace, so a retried or repeated restore never creates a record twice.
Availability and resilience
- Failed jobs are retried and recorded for review.
- Daily database dumps, copied off the server to R2; local copies are pruned after 14 days and R2 copies expire by a 14-day lifecycle rule.
Minimisation and deletion
- Only the data needed for backups is fetched from Linear. No analytics or tracking in the Service.
- Payment notifications are stored without payment method details or addresses.
- Customer-controlled backup retention with daily cleanup; files no remaining backup contains and expired ZIP exports are removed by the same cleanup; deleted workspaces' files are removed from storage by a background job that retries until it succeeds.
- Not fetched: personal inbox, favourites, drafts and private views, and OAuth credentials, integration and webhook secrets.
- Failed-job diagnostics are kept 90 days and removed with the workspace they belong to.
Organisational
- Changes are tested and deployed to a separate staging environment before they reach production.
- Breach handling per section 7.