Last reviewed: 2026-06-01
This DPA applies where the operator processes personal data on behalf of a business customer (the controller). A signed copy is available to B2B customers on request.
For the files and submissions your visitors send through your drop page, you (the customer) are the controller and Dropspot is the processor, acting only on your documented instructions.
We process personal data only on your documented instructions, including for transfers, unless the law requires otherwise — in which case we tell you first, unless the law forbids it. Everyone we authorize to process the data is bound by confidentiality. We maintain appropriate technical and organizational security measures — encryption in transit, access controls, and audit logging — and we assist you, so far as we reasonably can, with data-subject requests and with your own security, breach-notification, and data-protection-impact-assessment obligations.
The list of authorized sub-processors is available to customers on request; customers are notified of material changes per this DPA.
We notify affected customers without undue delay and within 72 hours of becoming aware of a personal-data breach. On termination, we return or delete the data we process on your behalf. The incident procedure is maintained in an internal runbook.
To request a signed copy of this DPA, or for any processing question, contact privacy@dropspot.me. The processor's registered legal entity will be named here once incorporation is complete — to be confirmed by counsel before launch.