Essentio Data Processing Agreement

Last updated: 29 September 2026

Version 1, an annex to the Essentio Terms of Service.

1. Parties, roles and scope

This agreement is between the business that uses Essentio (the Business, the controller) and CPV Corporate Services Ltd, HE 252516, 23, 28th October str., 3rd floor, Engomi, 2414 Nicosia, Cyprus (Essentio, the processor). It forms part of the Essentio Terms of Service and is accepted with them. It meets Article 28 of the GDPR (Regulation (EU) 2016/679), and follows the structure of the European Commission's standard contractual clauses under Article 28(7) (Implementing Decision (EU) 2021/915), with general written authorisation of sub-processors.

It covers the personal data the Business, its team and the software it connects put into Essentio, and that Essentio processes to provide the service to the Business (the Business Data). Annex I describes that processing.

Where this agreement and the Terms of Service differ on personal data, this agreement wins. Terms defined in the GDPR have the same meaning here.

2. Essentio's obligations

Instructions. Essentio processes Business Data only on the Business's documented instructions, including on transfers to third countries, unless EU or Member State law requires otherwise; in that case Essentio tells the Business first, unless that law forbids it. The Terms of Service, this agreement, and what the Business's team and connected software do in Essentio (creating, issuing, sending, exporting and deleting) are the Business's complete instructions. Essentio tells the Business immediately if it believes an instruction breaks data protection law.

Purpose. Essentio uses Business Data only to provide, secure and support the service. It does not sell it, use it for advertising, or use it to train AI models.

Confidentiality. Only staff who need Business Data for their work can reach it, and each is bound to confidentiality. Staff read a Business's Clients, documents or payments only with the Owner's Support access (read-only, 24 hours at most, each use logged), or where needed to answer a security incident, a report under the Terms of Service or a legal obligation.

Security. Essentio applies the measures in Annex II, which meet Article 32 of the GDPR, and reviews them at least once a year. It may improve them, but not reduce the overall level of protection.

Data subjects' rights. Essentio lets the Business answer requests itself: it can view, correct, export and delete Business Data in Essentio. If a data subject writes to Essentio directly, Essentio passes the request to the Business without undue delay and does not answer it alone.

Help with compliance. Taking into account what it knows, Essentio helps the Business with security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 of the GDPR), for example by answering questions and sharing the information in this agreement.

Records and audits. Essentio keeps the records Article 30(2) requires. It makes available the information needed to show it meets this agreement: on request, it answers written questions and shares its security documentation within 30 days. Where that is not enough, or a supervisory authority requires it, the Business may audit Essentio, or have an independent auditor bound by confidentiality do so, once a year with 30 days' notice, during business hours and at its own cost.

3. Sub-processors

General authorisation. The Business authorises Essentio to use the sub-processors listed in Annex III.

Notice of changes. At least 30 days before adding or replacing a sub-processor, Essentio emails the Owner of every Business, naming the sub-processor, what it will do, the data it will receive and where. The list at essentio.pro/subprocessors is updated at the same time.

Objection. The Business may object on reasonable data protection grounds by replying to that email within 14 days. Essentio will then try, in good faith, to address the objection, for example by not using the sub-processor for that Business. If it cannot within the remaining notice period, the Business may end the Terms of Service before the change applies and receive a refund of the unused prepaid period. A Business that does not object within 14 days authorises the change.

Flow-down. Essentio binds each sub-processor by a written contract to data protection obligations no less protective than this agreement, in particular on security, and remains fully liable to the Business for each sub-processor's performance.

Recipients the Business chooses. Some recipients receive Business Data only because the Business, its team or its software instructs Essentio to send it there. They are not Essentio's sub-processors; they act under the Business's own relationship with them:

4. Transfers, breaches, deletion and changes

Transfers. Business Data is stored in Germany. Essentio transfers it outside the EEA only on the Business's instructions and under Chapter V of the GDPR: to a country with an EU adequacy decision, to a company certified under the EU–US Data Privacy Framework, or under the EU standard contractual clauses (Implementing Decision (EU) 2021/914). Annex III gives the basis for each sub-processor.

Personal data breaches. Essentio notifies the Owner by email without undue delay, and in any case within 48 hours of becoming aware of a breach affecting Business Data. The notice describes, as far as then known, what happened, the categories and approximate number of people and records concerned, the likely consequences, the measures taken or proposed, and a contact point; further information follows as it becomes available. Notifying a breach is not an admission of fault.

Deletion and return. The Business can export its data at any time (Terms of Service, section 8). When the Business, or the Owner's account, is deleted, Business Data stays retrievable for 30 days, then Essentio erases it and it leaves the backups within 8 weeks, unless EU or Member State law requires Essentio to keep it. Essentio confirms the erasure on request.

Where Essentio is a controller. Essentio is an independent controller, under its Privacy Policy, for the data it processes for its own purposes: team members' accounts, billing and the Owner's plan, security and fraud prevention, the log of its staff's actions, and anonymous, aggregated statistics about how Essentio is used.

Changes to this agreement. Essentio notifies the Owner of any change by email at least 30 days before it applies, and asks the Owner to approve it in Essentio. A Business that does not approve may end the Terms of Service before the change applies, with a refund of the unused prepaid period. Changes required by law may apply sooner.

Liability and law. Each party's liability under this agreement is subject to the limits in the Terms of Service, except where the GDPR does not allow a limit. This agreement is governed by the laws of the Republic of Cyprus, and the courts of Nicosia have jurisdiction. The competent supervisory authority for Essentio is the Office of the Commissioner for Personal Data Protection, Cyprus.

Annex I — Description of the processing

Annex II — Technical and organisational security measures

Annex III — Sub-processors

This list is also published at essentio.pro/subprocessors. Essentio announces each change as section 3 describes.

PostHog (usage statistics), GitHub (feedback) and Stripe (Essentio's own billing) receive no Business Data and are listed in the Privacy Policy.