Last Updated: July 22, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and DataLabs.store ("Processor," "we," "us") and applies to the extent we process personal data on your behalf in connection with the DataLabs.store service (the "Service"). By using the Service, Customer agrees to this DPA. If your organization requires a separately countersigned copy, contact us at products@datalabs.store.
Note on our legal entity: DataLabs.store is currently operated by Vitaly Vinogradov, as an individual, while formal incorporation (anticipated in Delaware, United States) is in progress. References to "DataLabs.store" in this DPA mean the individual or entity operating the Service at the relevant time. This DPA will be updated with the incorporated entity's legal name once formation completes.
1. Definitions
"Customer Data" means personal data that Customer submits to, or that DataLabs.store extracts on Customer's behalf from, connected Sources (e.g., HubSpot, QuickBooks) via the Service. "Data Protection Laws" means applicable data protection legislation, including the GDPR, UK GDPR, and the CCPA/CPRA. "Processing," "Controller," "Processor," and "Data Subject" have the meanings given in the GDPR, applied correspondingly under other Data Protection Laws. "Sub-processor" means a third party engaged by DataLabs.store to process Customer Data.
2. Roles of the Parties
Customer is the Controller (or Processor acting on behalf of its own customers, where applicable) of Customer Data. DataLabs.store is a Processor, processing Customer Data solely to provide the Service per Customer's instructions, as set out in the Terms of Service, the Service's documented functionality, and this DPA. To the extent the CCPA/CPRA applies, DataLabs.store is a "service provider" as defined therein, and will not sell or share Customer Data, or use it outside the business purposes specified here and in the Terms of Service.
3. Processing Instructions
DataLabs.store will process Customer Data only as necessary to provide the Service and per Customer's instructions, unless otherwise required by law, and will inform Customer if it believes an instruction violates Data Protection Laws.
4. Confidentiality
Personnel authorized to process Customer Data are subject to confidentiality obligations.
5. Security Measures
DataLabs.store implements appropriate technical and organizational measures to protect Customer Data, as described in our Security page, including encryption in transit, restricted need-to-know access control, per-customer database isolation, and automated brute-force protection.
6. Sub-processors
Customer authorizes DataLabs.store to engage sub-processors to process Customer Data. DataLabs.store's current sub-processor for Customer Data is:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Optional database hosting, used only if Customer selects the Azure tier | EU |
DataLabs.store will impose data-protection obligations no less protective than this DPA on any sub-processor, and will give reasonable notice of new sub-processors so Customer may object on reasonable grounds. (Payment and outreach service providers are disclosed in our Privacy Notice — they process DataLabs.store's own business data, not Customer Data, so they don't appear here.)
7. International Data Transfers
Where Customer Data is transferred outside the EEA, UK, or Switzerland (for example, to our US infrastructure), such transfers are made subject to appropriate safeguards, including the Standard Contractual Clauses (Module Two: Controller to Processor) issued by the European Commission (Decision 2021/914) or the UK International Data Transfer Addendum, as applicable, incorporated into this DPA by reference.
8. Assistance with Data Subject Requests
DataLabs.store will provide reasonable assistance to Customer in responding to data subject requests under Data Protection Laws, to the extent Customer cannot reasonably fulfill them itself using the Service.
9. Personal Data Breach Notification
DataLabs.store will notify Customer without undue delay upon becoming aware of a breach affecting Customer Data, and provide reasonably available information to support Customer's own notification obligations.
10. Deletion or Return of Data
Upon termination of the Service, DataLabs.store will delete or anonymize Customer Data within a reasonable period, except where retention is required by law, consistent with the Privacy Notice's Data Retention section.
11. Audits
DataLabs.store will make available information reasonably necessary to demonstrate compliance upon Customer's written request, and permit audits by Customer or its mandated auditor, subject to reasonable notice, confidentiality, and no more than once per year absent a legitimate concern.
12. Liability
Liability under this DPA is subject to the limitations in DataLabs.store's Terms of Service.
13. Governing Law
This DPA is governed by the laws of the State of Delaware, United States, consistent with DataLabs.store's anticipated place of incorporation.
14. Term
This DPA remains in effect for as long as DataLabs.store processes Customer Data on Customer's behalf under the Terms of Service.
Contact: products@datalabs.store