Skip to main content
Percher is still being built and account creation is paused — get notified when it opens.

Percher Data Processing Agreement

Effective date: 10 September 2026 Version: 1.0

This Data Processing Agreement (the DPA) is between the customer using Percher as a controller or processor (Customer) and Kaizensu AB, company registration number 559595-6359, Kulvertkonstens väg 12, 422 60 Hisings Backa, Sweden (Percher). It is incorporated into the Percher Terms of Service when Percher processes personal data in App Data on the Customer's behalf.

1. Roles and scope

For personal data in source code, environment variables, application databases, files, logs, generated diagnostics and other data submitted to or generated by an application hosted through Percher (App Data), the Customer acts as controller or processor, as applicable, and Percher as processor or subprocessor correspondingly.

If the Customer acts as processor, it confirms that the relevant controller has authorised it to appoint Percher as a subprocessor and to give the instructions in this DPA, and the Customer's instructions include that controller's lawful instructions communicated through the Customer.

Percher remains controller for Account Data, security and abuse records, billing administration, first-party Service statistics and other processing for which it determines the purposes and means; the Privacy Policy describes that processing, which this DPA does not govern.

2. Processing details and instructions

ItemDescription
Subject matter and purposeBuilding, hosting, operating, routing, backing up, securing and supporting the Customer's applications as instructed through the Service
DurationThe term of the Service and any deletion or backup period stated in the Terms or Privacy Policy
Nature of processingCollection, storage, organisation, retrieval, transmission, use, troubleshooting, deletion and other processing needed to provide the Service
Personal-data typesDetermined by the Customer; may include identifiers, contact details, content, account, transaction, device, network and usage data
Data subjectsDetermined by the Customer; may include its end users, customers, personnel, suppliers and other persons represented in App Data

The Terms, this DPA, the Customer's configuration and documented support requests are the documented instructions; additional lawful instructions consistent with the Service may be given to legal@percher.app. Percher informs the Customer if, in its opinion, an instruction infringes data-protection law and may suspend the affected processing while the parties resolve it.

The Service is not approved for special-category data under Article 9 GDPR, criminal-offence data under Article 10 GDPR or other regulated data unless Percher agrees otherwise in writing, identifying the data, the lawful condition and the additional safeguards. This restriction does not remove Percher's obligations for personal data that is nevertheless received.

3. Percher's obligations

Percher will:

  • process App Data only on documented instructions, including for transfers, unless EU or Member State law requires otherwise, in which case Percher informs the Customer beforehand where permitted;
  • ensure that authorised personnel are bound by confidentiality;
  • maintain measures appropriate to the risk under Article 32 GDPR, including access controls, encryption in transit, encryption of stored environment-variable values, tenant and network isolation, logging, backups and vulnerability management;
  • taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures with data-subject requests, and forward requests relating to App Data to the Customer unless authorised to respond;
  • reasonably assist the Customer with its obligations under Articles 32–36 GDPR, taking into account the nature of the processing and the information available to Percher;
  • notify the Customer without undue delay after becoming aware of a personal-data breach affecting App Data, with the available information the Customer needs for its assessment and notices;
  • make the information reasonably necessary to demonstrate Article 28 compliance available to the Customer and allow audits as set out in Section 7; and
  • at the Customer's choice, delete or return App Data after the Service ends, delete existing copies unless applicable law requires storage, and confirm completion on request.

4. Customer obligations

The Customer warrants that it has authority to enter into this DPA, appoint Percher and give instructions. The Customer is responsible for the lawfulness, accuracy and minimisation of App Data, the required legal bases, conditions, notices and rights handling, its instructions and appropriate security settings, and must not submit App Data that Percher may not lawfully process or instruct processing contrary to law or Section 2.

5. Subprocessors

The Customer gives Percher general written authorisation to use the subprocessors listed in the current Subprocessor Notice. Percher imposes by contract the same data-protection obligations as this DPA, to the extent applicable to the subprocessing, and remains responsible to the Customer for each subprocessor's performance.

Percher notifies the Customer at the Account email before a planned addition or replacement, with enough time to object on reasonable data-protection grounds; in an emergency needed to protect the Service or App Data, notice may follow without undue delay. If an objection cannot reasonably be resolved, the Customer may terminate the affected Service before the change takes effect and receive a proportionate refund of unused prepaid fees.

6. International transfers

Percher makes no onward transfer of App Data outside the EEA unless Chapter V GDPR is satisfied, and identifies the destination and transfer mechanism in the Subprocessor Notice or related transfer information. Where no adequacy decision applies, Percher puts in place the applicable module of the European Commission's Standard Contractual Clauses (Decision 2021/914) or another lawful mechanism, with supplementary measures where its assessment requires. This DPA does not itself represent that a restricted transfer from the Customer to Percher occurs; if one requires a separate transfer instrument, the parties complete it before the transfer. Applicable SCCs prevail over conflicting terms of this DPA.

7. Security reviews and audits

Percher first provides available policies, summaries, questionnaires and independent reports. If those are insufficient, the Customer may request an audit reasonably necessary under Article 28(3)(h), which must be proportionate, protect other customers' confidentiality and security, and normally take place during business hours on reasonable notice. The Customer bears its own costs unless the audit identifies a material breach by Percher. These limits do not prevent a competent authority from exercising its powers or an urgent audit after a material incident.

8. Return and deletion

The Customer can export App Data using the Service. On deletion or termination, active copies are returned or deleted according to the Customer's choice and the Terms, and residual backup copies are removed within the backup cycle, currently no more than 30 days, unless law requires retention. Where Terms Section 15.6 applies, its retrieval and erasure deadlines control. This DPA applies until deletion; Percher confirms completion on request, noting any backup expiry or legally required retention still outstanding.

9. Liability, term and conflict

The liability provisions in the Terms apply to this DPA to the extent permitted by law. This DPA lasts while Percher processes App Data for the Customer. Mandatory law and applicable SCCs prevail, followed by this DPA and then the Terms.

10. Contact

Questions and notices under this DPA: legal@percher.app.

The English and Swedish versions are intended to have the same meaning. If they differ, the English version prevails. Mandatory law and applicable Standard Contractual Clauses prevail over this language rule.


*Last updated: 10 September 2026* *© 2026 Kaizensu AB — Percher, percher.app*