velstash
Pricing Docs FAQ Try it free

Legal

Data Processing Addendum

Last Updated: August 24, 2026

This Data Processing Addendum ("Addendum") forms part of, and is incorporated by reference into, the Terms of Service for Velstash (the "Terms"), entered into between the Client and the Provider (as identified in Section 1 of the Terms).

By registering for and using the Service, the Client agrees to the terms of this Addendum.

Background

  1. The Provider and the Client have entered into the Terms, pursuant to which the Provider agrees to provide the Service to the Client.
  2. In the course of providing the Service, the Provider processes certain personal data on behalf of the Client, specifically data the Client (or the Client's applications) transmits to the Provider's Memcached infrastructure ("Client Personal Data"), as described in Section 1 of the Privacy Policy.
  3. This Addendum is intended to ensure that Client Personal Data is processed by the Provider in accordance with applicable Data Protection Laws.

THE PARTIES AGREE AS FOLLOWS:

1. Definitions

Unless otherwise defined in this Addendum, capitalized terms have the meaning given to them in the Terms or the Privacy Policy. In addition:

  • "Data Protection Laws" means the GDPR (Regulation (EU) 2016/679) and Spain's Organic Law 3/2018 (LOPDGDD), together with any implementing or successor legislation.
  • "Client Personal Data" means any personal data processed by the Provider on behalf of the Client in connection with the Service, as described in Section 1 of the Privacy Policy.
  • "Sub-processor" means any third party engaged by the Provider to process Client Personal Data on the Provider's behalf.
  • "Data Subject Request" means a request by a data subject to exercise their rights under Chapter III of the GDPR.
  • The terms "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", and "Processing" have the meanings given to them under the GDPR.

This Addendum is incorporated into and forms part of the Terms. In the event of any conflict between this Addendum and the Terms concerning the processing of personal data, this Addendum shall prevail.

2. Roles and Scope of Processing

2.1. With respect to Client Personal Data, the Client acts as the Data Controller and the Provider acts as the Data Processor, as described in Section 1.c of the Privacy Policy.

2.2. The Provider shall process Client Personal Data only:

  1. on the Client's documented instructions, including as necessary to provide the Service and perform the Provider's obligations under the Terms; and
  2. as required by applicable law, in which case the Provider will inform the Client of that legal requirement before processing, unless the law prohibits it from doing so.

2.3. The Client instructs the Provider to process Client Personal Data as necessary to provide the Service, including the temporary caching, storage, and automatic deletion of such data in accordance with Section 5 of the Terms and Section 1 of the Privacy Policy.

2.4. The Client warrants that it has, and will maintain throughout the term of the Terms, a valid legal basis under Article 6 GDPR for any Client Personal Data it transmits to the Service, and that it has provided any notices and obtained any consents required from its own data subjects.

2.5. Details of the processing carried out under this Addendum, as required by Article 28(3) GDPR, are set out in Schedule 1.

3. Provider Personnel

The Provider will ensure that access to Client Personal Data is limited to personnel or contractors who require such access to perform the Service, and who are subject to confidentiality obligations.

4. Security

4.1. The Provider will implement and maintain appropriate technical and organizational measures to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Schedule 2.

4.2. Taking into account the nature of the processing, the Provider will provide the Client with reasonable assistance necessary for the Client to comply with its obligations under Articles 32 to 34 GDPR, to the extent such assistance is technically possible for a service of this nature and scale.

5. Sub-processing

5.1. The Client generally authorizes the Provider's engagement of the Sub-processors listed in Schedule 3.

5.2. When engaging a Sub-processor, the Provider will ensure, via a written contract, that the Sub-processor is subject to data protection obligations materially equivalent to those set out in this Addendum.

5.3. The Provider remains fully liable to the Client for the performance of any Sub-processor's obligations relating to Client Personal Data.

5.4. The Provider will notify the Client, via an update to Schedule 3 and a notice on velstash.com/dpa (or by email, at the Provider's discretion), at least fifteen (15) days before engaging any new Sub-processor that will process Client Personal Data. The Client may object to a new Sub-processor within fifteen (15) days of such notice by terminating the affected paid subscription(s) without penalty, which shall be the Client's sole remedy in respect of such objection.

6. Data Subject Requests

If the Provider receives a Data Subject Request relating to Client Personal Data, it will, to the extent legally permitted, inform the requester that their request should be directed to the Client, and will notify the Client without undue delay. The Provider will provide reasonable assistance to help the Client respond to such requests, taking into account the nature of the processing.

7. Personal Data Breach

7.1. If the Provider becomes aware of a Personal Data Breach affecting Client Personal Data, it will notify the Client without undue delay after becoming aware of it, and will take reasonable steps to mitigate the breach and secure the affected data.

7.2. Such notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, and the measures taken or proposed to address it.

7.3. The Client is solely responsible for complying with any breach notification obligations owed to its own data subjects or supervisory authorities.

8. Deletion or Return of Data

8.1. Client Personal Data stored in the Service's cache infrastructure is, by its nature, automatically and irreversibly deleted upon the technical triggers described in Section 1.b of the Privacy Policy (TTL expiration, eviction, cancellation, or server restart/maintenance).

8.2. Given the volatile, non-persistent nature of the cache data described in Section 5 of the Terms, the Provider does not retain durable copies of Client Personal Data beyond these automatic deletion triggers, and accordingly no separate return-of-data process applies to cache data.

9. Audit

Upon reasonable written request, and no more than once every twelve (12) months, the Provider will provide the Client with reasonably available documentation describing the security measures in place under Schedule 2, sufficient to demonstrate compliance with this Addendum. Any request for a more extensive audit (including on-site inspection) will be discussed and agreed between the parties in advance, including as to scope, cost, and confidentiality safeguards.

10. International Transfers

The Sub-processors listed in Schedule 3 store and process Client Personal Data exclusively within the European Economic Area (EEA), as described in Section 4 of the Privacy Policy. The Provider will not transfer Client Personal Data outside the EEA without implementing appropriate safeguards under Chapter V GDPR and providing prior notice to the Client in accordance with Section 5.4 of this Addendum.

11. Liability

Each party's liability arising out of or in connection with this Addendum is subject to the limitations of liability set out in Section 5.a of the Terms.

12. Term

This Addendum takes effect on the date the Client accepts the Terms and remains in effect for as long as the Provider processes Client Personal Data on the Client's behalf.


Schedule 1 — Details of Processing (Art. 28(3) GDPR)

  • Subject matter: The Provider's provision of the Service (memcached-as-a-service caching infrastructure) to the Client.
  • Duration: From the Client's registration until deletion of all Client Personal Data in accordance with Section 8 of this Addendum.
  • Nature and purpose: Temporary, volatile storage of data transmitted by the Client for caching/performance purposes, as instructed by the Client. Additionally, cache keys (excluding cached values) are persisted for up to twelve (12) months for the purpose of providing the Client with usage statistics via the dashboard, as described in Section 1.b.i of the Privacy Policy.
  • Categories of Client Personal Data: Any personal data the Client chooses to transmit to the cache (nature and categories determined solely by the Client's use of the Service).
  • Categories of data subjects: Determined by the Client; may include the Client's own end users, employees, or other individuals whose data the Client processes through its applications.

Schedule 2 — Security Measures

  1. Access control (dashboard/account credentials): User passwords are never stored or recoverable in plaintext; they are stored using a secure hashing mechanism.
  2. Access control (cache connections): Each cache instance requires authentication via a username/password mechanism (per the memcached text protocol) before any data can be read or written; connection to the port alone does not grant access. Clients may additionally connect over TLS (port 11212) for encrypted transport, which the Provider recommends, particularly given that authentication credentials are otherwise transmitted in plaintext over unencrypted connections (port 11211).
  3. Encryption in transit:
    • Administrative access to infrastructure (SSH) is encrypted.
    • Communications between the dashboard and cache servers, and between the dashboard and the host-agent management service, use mutual TLS (mTLS).
    • Client connections to the cache itself may optionally use TLS (port 11212), at the Client's discretion, as described in Section 5.b of the Terms of Service.
  4. Encryption at rest:
    • Cache values (the cached content itself) are never written to disk and are held exclusively in volatile memory.
    • Cache keys may be persisted to disk for statistical purposes, as described in Section 1.b.i of the Privacy Policy, and are subject to the retention limits set out there.
    • Account passwords are stored hashed, never in plaintext, as described above.
    • Other account data, such as email addresses, is stored in plaintext, consistent with common practice for account/dashboard data in comparable software (e.g., WordPress and similar platforms).
    • No payment card data is stored by the Provider; such data is handled exclusively by the Merchant of Record, Dodo Payments, as described in Section 3 of the Privacy Policy.
  5. Network security:
    • Cache servers expose the memcached ports (11211 for plaintext, 11212 for TLS) and an SSH port (22) for administrative access. Production infrastructure restricts SSH access to key-based authentication only (password authentication disabled); access is limited to the Provider's own administrative and deployment use, and is never exposed to Clients or end users.
    • Internal management interfaces used to administer cache servers from the dashboard are protected via mutual TLS (mTLS).
    • Cache data isolation between tenants is enforced by running each tenant's cache in a separate process.
  6. Infrastructure providers: The Service is hosted with the Sub-processors listed in Schedule 3, which maintain their own physical and environmental security controls.
  7. Incident response and monitoring:
    • Failed login attempts to the dashboard are logged, including the associated username and source IP address.
    • Password reset attempts are logged, including the account for which the reset is attempted and the source IP address.
    • Suspicious activity identified through these logs is investigated by the Provider.
    • These logs are retained for up to 365 days, for the specific purpose of security incident investigation, after which they are deleted.
  8. Change management and deployment: Deployments are automated and performed over encrypted connections, reducing the risk of manual deployment errors. A rollback mechanism is in place allowing a rapid return to a previous known-good state if a deployment issue is identified.
  9. Backups: Account and dashboard data is backed up automatically to a dedicated storage volume, located within the European Union, consistent with the Provider's policy of avoiding transfers outside the EEA for infrastructure hosting (see Section 4 of the Privacy Policy). Cache data itself is not backed up, consistent with its volatile, non-persistent design described in Section 5 of the Terms of Service.

Schedule 3 — Authorized Sub-processors

Name Function Location
Hetzner Online GmbH Infrastructure hosting and backups European Union (Germany/Finland)
OVH SAS Infrastructure hosting European Union (France)

Note: Dodo Payments and Proton AG (Proton Mail) are not listed as Sub-processors under this Addendum. Dodo Payments acts as an independent Data Controller with respect to payment and billing data, as described in Section 3 of the Privacy Policy. Proton Mail processes account and communication data, as described in Section 2 and Section 4 of the Privacy Policy, but does not process Client Personal Data as defined in this Addendum. This Addendum covers only Client Personal Data processed by the Provider as a Data Processor.

© 2026 Velstash
Pricing Docs FAQ Terms of Service Privacy Policy DPA
Featured on LaunchBuff