Data Processing Agreement
For business customers who publish personal data through
the hosted Sitebin service. It is presented at sign-in as the consent
document dpa, and accepting it there concludes it.
1. Parties and how this agreement is concluded
This Data Processing Agreement ("DPA") is concluded between the customer of the hosted Sitebin service who acts as controller ("Customer", "you") and IT-Trail GmbH, Schärdinger Straße 15, 4061 Pasching, Austria (FN 642899s, Landesgericht Linz), as processor ("we", "us").
It is concluded online: at sign-in to app.sitebin.io the IT-Trail
SaaS Stack's consent gate presents this document under the key
dpa, version 2026-09-08, and records your
acceptance with the version, the date and time, and the account that
accepted it. That record is your copy of the signed agreement and is
included in your account's data export. A customer who signed up
before this document was presented at sign-in can conclude it by
email to datenschutz@ittrail.at
naming the account; we confirm the same version in reply.
The DPA supplements the terms of service. For the processing of personal data on your behalf it takes precedence over them. It is free of charge.
2. When this DPA applies
It applies to the extent that you, as a business, publish or store through the service content that contains personal data of other people — a client's staff directory, a portfolio with customer names, a documentation portal with user photographs, a form that writes to a file you host — and we therefore process that data on your behalf. For such data you are the controller and decide why and how it is processed; we host and serve it as you instruct.
It does not apply to the data we process as controller in our own right: your account, your invoices and payments, our server logs and the operation of the service. That processing is described in the privacy policy. In particular, payments are outside the scope of this DPA: Stripe processes your billing data for us as our processor and for its own purposes as an independent controller, never on your behalf, and is not a sub-processor of the content you publish.
3. Subject matter, duration, nature and purpose
- Subject matter: the hosting of files and websites you upload to the service, and everything needed to serve them to the people you make them available to.
- Duration: for as long as you use the service and have content on it, and thereafter until that content is deleted under section 11.
- Nature of the processing: storage, backup and failover replication, transmission to visitors over HTTPS, listing and rendering in the file viewer, export as an archive, and deletion. We do not analyse, index for our own purposes, profile or otherwise use the content.
- Purpose: providing the hosted Sitebin service to you as described in the terms of service.
- Categories of data subjects: whoever appears in the content you publish — typically your employees, customers, users, contractors and business contacts — and the visitors of your sites, to the extent serving a request processes their data.
- Categories of personal data: whatever you choose to upload: names, contact details, images, documents, identifiers, and any other data contained in your files; for visitors, IP address, requested URL, timestamp, transferred bytes and browser information in the server logs. You must not publish special categories of data (Art. 9 GDPR) or data of a kind that needs a higher level of protection than a static file host offers without first agreeing the measures with us.
4. Instructions
We process the data only on your documented instructions. Your instructions are the terms of service, this DPA, and the settings you make in the service — what you upload, whether a site is public or view-protected, its expiry, its domains, when you delete it. The service's functions are the mechanism for giving instructions; additional instructions in text form to datenschutz@ittrail.at are possible where the service has no setting for them, and we may decline instructions that go beyond what the service does or that would cost us disproportionate effort.
We inform you without delay if we believe an instruction infringes the GDPR or other data-protection law, and may suspend carrying it out until you confirm or change it. We process the data outside your instructions only where Union or Member State law requires it, in which case we tell you beforehand unless that law forbids it.
5. Confidentiality
Only persons who need access to run the service have it, and every such person is bound to confidentiality by contract or by statutory duty. We do not look into your content except where a support request, an abuse report, a security incident or a legal obligation makes it necessary, and then only to the extent necessary.
6. Security of processing (Art. 32 GDPR)
We implement and maintain the technical and organisational measures in Annex 2, in summary:
- Transport encryption. Every connection to the application, to the API, to WebDAV and to every hosted site is over TLS with automatically issued and renewed certificates; plain HTTP is redirected.
- Credential protection. Edit passwords and view passwords are stored as Argon2id hashes only; API tokens as SHA-256 hashes; account passwords are held by the identity service, hashed, and never by the application.
- EU hosting. The service runs on dedicated infrastructure of Hetzner Online GmbH in data centres in the European Union.
- Isolation of published content. Sites are served
from a separate registrable domain (
sitebin.app) and each on its own subdomain, so a hosted site runs in its own browser origin and cannot read or set cookies or storage of the application or of another site. Content on untrusted tiers is additionally served with restrictive content-security headers. - Backups. Nightly backups of the whole data volume — sites, settings and indexes together — kept on a rolling basis for at most 30 days, with a documented restore procedure.
- Access control and logging. Administrative access to servers is by SSH key from named persons only; server logs are kept for 14 days and used for security and troubleshooting.
The measures are reviewed and may be improved over time; we will not replace them with less protective ones during the term. On request we provide a current description.
7. Sub-processors
You authorise us in general to use the sub-processors listed in Annex 3. We impose on every sub-processor, by contract, data-protection obligations equivalent to those in this DPA, and we remain fully responsible to you for their performance.
We inform you of any intended addition or replacement of a sub-processor by email to your account address at least 30 days before it takes effect. You may object on reasonable data-protection grounds within that period; if we cannot accommodate the objection, you may terminate the service for the affected content without penalty, and we refund the unused part of a prepaid period pro rata.
8. Location of processing and international transfers
All processing under this DPA takes place in the European Union. We do not transfer the data to a third country or an international organisation. Should that ever become necessary, we will do so only with your prior authorisation and on a lawful basis under Chapter V GDPR, and will inform you of the safeguards used.
9. Assistance
- Data subject rights. Because you control the content, you can fulfil most requests yourself: edit or remove a file, set or clear a view password, delete a site, or export it. Where a data subject contacts us directly about content you publish, we forward the request to you without undue delay and do not answer on your behalf. Where you need our help beyond the service's functions, we assist you with appropriate technical and organisational measures, at cost if the effort is significant.
- Security, breach notification, impact assessments. Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations under Art. 32 to 36 GDPR.
10. Personal data breaches
We notify you of a personal data breach affecting data processed under this DPA without undue delay and at the latest 48 hours after becoming aware of it, by email to your account address. The notification describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point; information not yet available follows as it becomes available. We document breaches and support you in your own notifications to the supervisory authority and to data subjects.
11. Deletion and return at the end of processing
You can export every site as a ZIP archive at any time, from its edit page, over the API and over MCP, and you can delete any site or your whole account yourself. On deletion of a site its files are removed from the serving volume immediately; on expiry, 24 hours after the expiry date. Copies in backups are overwritten by the normal backup rotation within 30 days. When the service ends for you — you delete the account, or the contract is terminated — all your content is deleted the same way, unless Union or Member State law requires us to keep it, in which case we keep only what that law requires, for as long as it requires, and process it for no other purpose. On request we confirm the deletion in writing.
12. Information and audits
We make available to you all information necessary to demonstrate compliance with Art. 28 GDPR: this DPA, the description of the measures in Annex 2, the sub-processor list, and answers to reasonable written questions within a reasonable time. Where that is not sufficient, you or an auditor you mandate (bound to confidentiality and not a competitor of ours) may audit the processing once per calendar year, and additionally after a breach or on request of a supervisory authority: with at least 30 days' written notice, during business hours, limited to what concerns the processing under this DPA, and without disrupting the service or other customers' data. We may charge our reasonable costs for audits beyond the first per year. Because the service runs on shared infrastructure, on-site access to the data centre is replaced by the hosting provider's own certifications and audit reports, which we pass on.
13. Liability, term and final provisions
- Liability between the parties follows Art. 82 GDPR and the liability provisions of the terms of service; the limitations there apply to claims under this DPA to the extent the law allows.
- This DPA runs for the duration of the processing described in section 3 and ends when that processing ends. Sections 10 to 12 survive until the deletion is confirmed.
- We may update this DPA when the law or the service changes; a new version is identified by its date and presented at sign-in the way the first one was. Until you accept a new version, the version you accepted applies.
- This DPA is governed by Austrian law. Place of jurisdiction is Linz, Austria. It is written in English; the English text is authoritative.
Annex 1 — Details of the processing
| Controller | The Customer: the account holder who accepted this DPA |
|---|---|
| Processor | IT-Trail GmbH, Schärdinger Straße 15, 4061 Pasching, Austria |
| Data-protection contact | datenschutz@ittrail.at |
| Subject matter | Hosting and serving of files and websites uploaded by the Customer |
| Nature | Storage, backup, transmission, rendering, export, deletion |
| Purpose | Providing the hosted Sitebin service |
| Data subjects | Persons appearing in published content; visitors of published sites |
| Data categories | Content data as uploaded by the Customer; visitor connection data in server logs |
| Special categories | None intended; not to be published without prior agreement |
| Location | European Union |
| Duration | Until deletion by the Customer or end of the contract, plus backup rotation of up to 30 days |
Annex 2 — Technical and organisational measures
- Confidentiality. Servers in access-controlled EU
data centres of the hosting provider. Administrative access only
over SSH with key authentication, from named persons, no shared
accounts. Edit and view passwords stored as Argon2id hashes; API
tokens as SHA-256 hashes; account passwords hashed by the identity
service. Every hosted site isolated in its own browser origin on
sitebin.app, separate from the application's domain; restrictive content-security headers on untrusted tiers. View passwords and expiry per site under the Customer's control. - Integrity. TLS on every connection with automatically renewed certificates; HTTP redirected to HTTPS. Uploads validated for path and size; per-site quotas stamped at creation; every change to a site requires its edit credential or the owning account.
- Availability and resilience. Single-writer data volume with nightly backups kept for at most 30 days and a documented restore procedure. Rate limits against abuse of site creation and password attempts.
- Deletion. Files of deleted sites removed immediately; expired sites removed 24 hours after expiry; backups rotated within 30 days.
- Process. Server logs limited to 14 days. Security issues handled through a documented process; the software is open-source and its security notes are public in the repository. Measures reviewed at least yearly and after incidents.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Server infrastructure and backup storage for the service | Data centres in the European Union |
Stripe Payments Europe, Ltd. processes payment data for us as controller-side processor and is not a sub-processor of Customer content (section 2). The IT-Trail SaaS Stack (identity, consent and billing) is operated by IT-Trail GmbH itself and is not a third party.
Version
2026-09-08. Consent document key dpa. Related documents:
terms of service ·
privacy policy ·
imprint.