Skip to content
SmolClouds

Legal

Data Processing Agreement

The terms under which we process personal data on your behalf when you use SmolClouds to run applications.

Effective date: 5 September 2026

01Roles and scope

This agreement applies where Pulsara LLC ("SmolClouds") processes personal data on behalf of a customer in the course of providing the service. It forms part of the Terms of Service and applies to every customer to whom data protection law grants it.

For that data the customer is the controller and SmolClouds is the processor. The customer determines the purposes and means of processing; SmolClouds acts only on the customer's documented instructions, which include using the service as it is designed to be used.

Where the customer's own data protection law requires a signed agreement, contact us and we will provide an executable copy.

02What is processed

Subject matter
Provision of the SmolClouds application hosting platform.
Duration
For as long as the customer's account is active, plus the retention periods described in the privacy policy.
Nature and purpose
Storing, building, deploying, routing, running and logging the customer's applications, and measuring resource usage against the customer's plan.
Categories of data subject
The customer's workspace members, and any individuals whose data the customer chooses to process inside a deployed application.
Categories of personal data
Account identifiers, names, email addresses and profile pictures for workspace members; whatever personal data the customer's own applications store or emit into logs.
Special categories
None are required by the service. The customer decides whether its applications process special category data and is responsible for the additional obligations that follow.

03Our obligations

  • Process personal data only on the customer's documented instructions, including for international transfers
  • Ensure that personnel with access are bound by confidentiality
  • Implement appropriate technical and organisational security measures
  • Assist the customer with data subject requests, impact assessments and consultations with regulators, taking into account the nature of the processing
  • Notify the customer without undue delay after becoming aware of a personal data breach affecting their data
  • Delete or return personal data at the end of the service, as described below
  • Make available the information needed to demonstrate compliance

04Security measures

The platform's isolation model is described on our security page: applications run in separate Firecracker microVMs with their own guest kernels and network namespaces, secrets are encrypted at rest, and traffic is served over TLS.

SmolClouds does not currently hold a SOC 2, ISO 27001 or equivalent attestation, and this agreement does not represent otherwise. Customers requiring one should discuss timelines with us before relying on the service for regulated workloads.

05Sub-processors

The customer gives general authorisation for SmolClouds to engage the sub-processors listed on our sub-processors page — currently Hetzner and Oracle Cloud Infrastructure for compute and storage, Stripe for billing, and Resend for account email. Each is bound by written terms no less protective than those in this agreement.

SmolClouds will give at least 30 days' notice before a new sub-processor begins processing customer personal data, and the customer may object on reasonable data protection grounds within that period.

SmolClouds remains liable to the customer for its sub-processors' performance of their data protection obligations.

06Data subject requests

The customer controls the personal data inside its own applications and can access, correct, export and delete it directly through the service.

Where an individual contacts SmolClouds directly about data we process on a customer's behalf, we will refer them to the customer rather than respond on the customer's behalf, and we will tell the customer promptly. We will assist with a request the customer cannot fulfil through the service itself.

07Breach notification

SmolClouds will notify the affected customer without undue delay after becoming aware of a personal data breach affecting their data, and will include the information needed for the customer to meet its own notification obligations, to the extent that information is available at the time.

Notification is not an acknowledgement of fault.

08International transfers

The customer selects the region an application is deployed to, and its application data stays in that region. Account and billing data may be processed by the sub-processors listed on the sub-processors page.

SmolClouds is established in the United States, so a customer in the EEA, the UK or Switzerland is transferring personal data out of that territory when it uses the service. That transfer takes place under the European Commission's Standard Contractual Clauses, Module Two (controller to processor) or Module Three (processor to processor) as applicable, together with the UK International Data Transfer Addendum and the Swiss amendments, all incorporated into this agreement by reference. The docking clause applies, the governing law and forum are those of Ireland for the EU Clauses, and the sub-processor list on our sub-processors page is Annex III.

Annex I (parties, categories of data, transfer details) and Annex II (technical and organisational measures) are the corresponding sections of this agreement and of our security page. A signed copy with the annexes completed is available on request.

09Audits

SmolClouds will make available the information reasonably needed to demonstrate compliance with this agreement, and will respond to a customer's reasonable security questionnaire once per year.

Where the customer's data protection law grants an audit right that cannot be satisfied by that information, the parties will agree the scope, timing and cost of an audit in advance, conducted so as not to disrupt the service or the confidentiality of other customers' data.

10Deletion and return

The customer may export or delete its data at any time through the service.

On termination, SmolClouds will delete the customer's personal data within the retention periods set out in the privacy policy, except where storage is required by law. Backups are deleted on their ordinary rotation.

11Liability and precedence

Each party's liability under this agreement is subject to the limitations in the Terms of Service.

Where this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.

Questions about this agreement: legal@smolclouds.com.

Questions about this document: legal@smolclouds.com

Security reports go to our security page.