Version 1.0 — effective 10 September 2026
Data Processing Agreement
This Data Processing Agreement is Annex A to the General Terms and Conditions for Cloud Services and is incorporated into them by §9.7. It applies between MClimate Jsc (the “Processor”) and the customer (the “Controller”) and records the parties’ obligations under Article 28 of the General Data Protection Regulation.
A signable standalone version of this agreement is available on request from privacy@mclimate.eu for customers whose procurement process requires a countersigned document. The two versions are produced from the same text and do not differ in substance.
1. Definitions
1.1 “GDPR” means Regulation (EU) 2016/679.
1.2 “Cloud Services” means the MClimate Enterprise platform and associated APIs made available by the Processor under the General Terms and Conditions for Cloud Services (the “GTC”).
1.3 “Customer Personal Data” means personal data that the Processor processes on behalf of the Controller in the course of providing the Cloud Services, as described in Annex 1.
1.4 “Sub-processor” means any third party engaged by the Processor to process Customer Personal Data.
1.5 “LNS” means a LoRaWAN Network Server.
1.6 “FUOTA” means firmware update over the air.
1.7 Terms not defined here carry the meaning given in the GDPR; where the GTC defines the same term differently, this DPA prevails for data protection purposes.
1.8 Scope. This DPA applies to the extent that, and for as long as, the Processor processes personal data on the Controller’s behalf in the course of providing the Cloud Services. Where data processed in the Cloud Services does not constitute personal data, this DPA does not apply to it. Whether device data relates to an identifiable natural person depends on what the Controller records in and associates with the Cloud Services, which is within the Controller’s control and not the Processor’s.
2. Subject matter, duration, nature and purpose
2.1 Subject matter. The Processor’s processing of Customer Personal Data for the sole purpose of providing the Cloud Services to the Controller.
2.2 Duration. For the term of the GTC between the Parties, and thereafter only for the period and purposes set out in clause 11.
2.3 Nature and purpose. Hosting, storage, transmission, display, aggregation and analysis of device and account data; provision of device monitoring and control functions; provision of support; and making available software and firmware updates, in each case as necessary to deliver the Cloud Services.
2.4 Categories of personal data and data subjects. As set out in Annex 1.
2.5 The Processor processes Customer Personal Data only on the Controller’s documented instructions. The GTC, this DPA, and the Controller’s configuration of and use of the Cloud Services together constitute the Controller’s documented instructions. Any further instruction requires written agreement and may be chargeable where it exceeds the scope of the Cloud Services.
2.6 The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law, and may suspend performance of that instruction until it is confirmed or withdrawn.
2.7 Where the Processor is required by Union or Member State law to process Customer Personal Data otherwise than on the Controller’s instructions, it informs the Controller of that legal requirement before processing, unless that law prohibits such notification.
3. Roles
3.1 In respect of Customer Personal Data the Controller is the controller and the Processor is the processor.
3.2 Where the Controller itself processes the personal data of its own customers or of the occupants of premises in which devices are installed, and acts as a processor for a third party, the Processor acts as a sub-processor. In that case the obligations in this DPA apply to the Processor as if references to the Controller were references to that third party’s controller, and the Controller confirms it has authority to appoint the Processor.
3.3 The Processor acts as an independent controller in respect of account administration, billing, service security and monitoring, and the improvement of its own products and services, as described in its Privacy Policy. This DPA does not apply to that processing.
4. Confidentiality of personnel
4.1 The Processor ensures that persons authorised to process Customer Personal Data are bound by written confidentiality obligations surviving the end of their engagement, and are instructed to process Customer Personal Data only as necessary to provide the Cloud Services.
4.2 Access is limited to personnel who require it for a defined role. The roles with access are listed in Annex 1.
4.3 Personnel with access receive data protection and information security training, in accordance with the Processor’s certified information security management system.
5. Security of processing
5.1 The Processor implements and maintains the technical and organisational measures set out in Annex 1, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.
5.2 The Processor operates an information security management system certified to EN ISO/IEC 27001:2022 (certificate reg. № BG-7063-IS, issued by Alpha Quality Certification Ltd, accredited by EA BAS). The certified scope is stated in Annex 1.
5.3 The Processor may update the measures in Annex 1 provided the level of security is not materially reduced.
5.4 Availability and restoration. The Processor maintains the ability to restore availability of and access to Customer Personal Data in a timely manner in the event of a physical or technical incident, as required by Art. 32(1)(c) GDPR. The Processor is not responsible for Customer Data that is never delivered to the Cloud Services.
6. Sub-processors
6.1 The Controller gives general authorisation for the Processor to engage Sub-processors, subject to this clause.
6.2 The current list of Sub-processors is published at Sub-processors and forms part of Annex 2. The Controller may subscribe to notifications of changes at that page.
6.3 The Processor gives the Controller at least fifteen (15) days’ notice, by updating the list referred to in clause 6.2 and by the notification mechanism made available there, before a new Sub-processor begins processing Customer Personal Data. The Controller may object on reasonable data protection grounds within that period. If the Parties cannot resolve the objection, the Controller may terminate the affected Cloud Services on written notice without penalty, and clause 11 applies.
6.4 Where a Sub-processor must be engaged immediately in order to preserve the security, integrity or continuity of the Cloud Services, the Processor may engage it before the period in clause 6.3 has elapsed, provided that it notifies the Controller as soon as reasonably practicable and the Controller’s rights to object and to terminate under clause 6.3 continue to apply.
6.5 The Processor imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for a Sub-processor’s performance.
6.6 LoRaWAN Network Servers. Two data paths exist and they are treated differently:
(a) Where the Controller connects its own LNS to the Cloud Services (under GTC §8), that LNS is the Controller’s own infrastructure or its own processor. It is not a Sub-processor of the Processor, and the Processor has no responsibility for its operation. The Processor processes data received from it on the Controller’s instructions.
(b) Where a building or device group is subscribed to an LNS instance operated by the Processor, the provider of that instance processes Customer Personal Data on the Processor’s behalf and is a Sub-processor, listed in Annex 2.
7. Assistance with data subject rights
7.1 The Cloud Services provide the Controller with functions to access, correct, export and delete Customer Personal Data. The Controller uses those functions in the first instance to respond to data subject requests. Export covers device inventory, building structure and labels, device configuration, telemetry history, user accounts and roles, mobile application data and integration configuration, in a structured machine-readable format; the scope and its limits are set out in GTC §19.3.
7.2 Where telemetry is exported, the Processor bounds each device’s records by the period during which that device was assigned to the Controller. Records from any other period relate to another controller’s data subjects and are not disclosed.
7.3 Where a request cannot be satisfied through those functions, the Processor provides reasonable assistance, taking into account the nature of the processing, within a period allowing the Controller to meet its statutory deadlines and in any event within ten (10) business days of a written request.
7.4 The limits in clause 11.4 (backups) and clause 11.5 (free-text labels and the Processor’s business and support systems) apply equally to an erasure request assisted under this clause.
7.5 The Processor promptly forwards to the Controller any request it receives directly from a data subject relating to Customer Personal Data, and does not respond to that request itself except to confirm that it has been forwarded.
8. Personal data breaches and regulatory assistance
8.1 The Processor notifies the Controller without undue delay, and in any event within forty-eight (48) hours, of becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notification includes, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, it is provided in phases without further undue delay.
8.3 The Processor does not notify a supervisory authority or any data subject of a breach affecting Customer Personal Data on the Controller’s behalf unless instructed to do so in writing.
8.4 The Processor provides reasonable assistance to the Controller in complying with Arts. 32 to 36 GDPR, including data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to it.
8.5 Security vulnerabilities. Reporting, triage, severity classification and remediation of vulnerabilities in the Processor’s software and device firmware are governed by the Processor’s Security Policy at https://mclimate.eu/pages/security-policy and by the Service Level Agreement. Those obligations sit alongside, and do not limit, clause 8.1.
9. Software and firmware updates
9.1 The Processor may deploy updates to the Cloud Services, including security updates required under Regulation (EU) 2024/2847 (the Cyber Resilience Act), as part of providing the Cloud Services. Such deployment is within the Controller’s instructions under clause 2.5 and does not constitute a new instruction or a change to the subject matter of processing.
9.2 Device firmware. The Processor’s obligation is to make firmware updates available. Deployment to the Controller’s devices by FUOTA is initiated solely by the Controller through the Cloud Services. The Processor does not initiate a FUOTA session on any device without the Controller’s explicit instruction. Maintaining the LNS connectivity required to receive firmware updates is the Controller’s responsibility.
10. International transfers
10.1 The Processor processes Customer Personal Data within the European Economic Area. The hosting regions are stated in Annex 1: the Cloud Services and all associated storage and backups are hosted in AWS Europe (Frankfurt), and the LoRaWAN Network Server instance operated by the Processor runs on The Things Stack Cloud eu1 in Ireland.
10.2 The Processor does not transfer Customer Personal Data to a third country except where an adequacy decision applies, or under Standard Contractual Clauses or another transfer mechanism permitted by Chapter V GDPR, and after notice under clause 6.3 where the transfer arises from engaging a Sub-processor.
10.3 Where the Controller is established outside the EEA and Customer Personal Data is transferred to it, the Controller is responsible for the lawfulness of that transfer.
11. Return and deletion
11.1 On termination or expiry of the Cloud Services, the Processor retains Customer Personal Data and keeps it available to the Controller through the Cloud Services for thirty (30) days.
11.2 Within that period the Controller may instruct the Processor in writing to return Customer Personal Data in a commonly used machine-readable format, or to delete it. Absent an instruction, the Processor deletes it at the end of the period.
11.3 After deletion the Processor certifies deletion in writing on request. The Processor may retain Customer Personal Data to the extent required by Union or Member State law, in which case it continues to protect it under this DPA and processes it only for the purpose requiring retention.
11.4 Backups. Deletion under clauses 11.2 and 11.3 is performed against live systems. Backup copies are not individually edited; they are held on a rolling cycle of fourteen (14) days and expire automatically at the end of it. During that period a backup may still contain Customer Personal Data that has been deleted from live systems. Such data remains subject to the security measures in Annex 1 and to this DPA, is not returned to live systems, and is not otherwise processed. Where a backup is restored for continuity purposes, the Processor re-applies any outstanding deletion instruction to the restored data without undue delay.
11.5 Scope of the deletion commitment. Clauses 11.2 to 11.4 apply to Customer Personal Data held in the live Cloud Services, subject to the backup cycle in clause 11.4. Two further limits are stated expressly rather than left to be discovered. First, personal data that the Controller has entered into a free-text space, building or group label is part of the Controller’s own configuration rather than of any individual account, and is not removed by account deletion; it persists until the Controller edits the label. On request the Processor assists the Controller in identifying labels that may require amendment. Second, where Customer Personal Data has also been recorded in the Processor’s business and support systems in the course of providing support — for example a support ticket, a service record or correspondence — the Processor deletes or anonymises that data on the Controller’s instruction within thirty (30) days, subject to any retention required by law.
12. Audit and information
12.1 The Processor makes available to the Controller the information reasonably necessary to demonstrate compliance with Art. 28 GDPR, including its ISO/IEC 27001 certificate, the applicable Statement of Applicability scope, and its Annex 1 measures.
12.2 Where that information does not reasonably satisfy the Controller, the Controller may audit the Processor’s processing of Customer Personal Data, on thirty (30) days’ written notice, once in any twelve (12) month period (and additionally following a personal data breach affecting the Controller), during business hours, without unreasonable disruption, and subject to confidentiality obligations. Costs are borne by the Controller unless the audit reveals material non-compliance.
12.3 A supervisory authority’s exercise of its own powers is not limited by clause 12.2.
12.4 The Processor is not required to disclose information relating to other customers, or information whose disclosure would compromise the security of the Cloud Services.
13. Order of precedence and changes
13.1 In the event of conflict, the order of precedence is: (a) this DPA; (b) the GTC; (c) any other agreement between the Parties, unless that agreement expressly states that it prevails over this DPA in respect of data protection.
13.2 Route A / Route B interaction. Where the Parties have separately executed a data processing agreement, that executed agreement prevails over the Annex version incorporated into the GTC, and the Annex version does not apply between them.
13.3 The Processor may amend the Annex version of this DPA where required by law or by a change in the Cloud Services, provided the Controller’s protection is not materially reduced. Each version is published with a version number and effective date and the superseded version is archived. Changes to the Sub-processor list are governed by clause 6.3 and require notice with a right to object. The executed version of this DPA is amended only by written agreement between the Parties.
13.4 This DPA takes effect on the date the Controller accepts the GTC (Route A) or on the date of last signature (Route B), and terminates when the Processor has ceased all processing of Customer Personal Data in accordance with clause 11.
ANNEX 1 — Details of processing and technical and organisational measures
A. Categories of data subjects
- The Controller’s personnel and other authorised users of the Cloud Services.
- Occupants of premises whom the Controller invites into the Cloud Services. The Controller can invite an occupant by email address and grant them access to their own apartment or office. Such occupants hold platform accounts and are data subjects in their own right.
- Occupants, tenants or other users of premises whose unit the Controller has identified in a space label, whether or not they have been invited.
B. Categories of personal data
| Category | Examples |
|---|---|
| Platform account data | name, business email address, role and permissions, authentication data, login and activity logs |
| Device identifiers | DevEUI, device keys, application and session identifiers |
| Device location / assignment data | building, floor, room or unit labels and any reference the Controller assigns, including where that reference identifies a dwelling or its occupant |
| Device telemetry | temperature, humidity, CO₂ and air quality, valve and actuator state, open/close and motion events, water flow and leak events, battery and signal data, timestamps |
| Configuration and control data | setpoints, schedules, commands issued, firmware versions |
| Integration credentials | LNS credentials, API keys and webhook endpoints supplied by the Controller |
| Support data | correspondence, tickets and diagnostic information the Controller submits |
No special categories of personal data (Art. 9) and no criminal conviction data (Art. 10) are processed. The Controller must not enter such data into the Cloud Services.
C. Frequency and duration
Continuous, for the term of the GTC, plus the period in clause 11.
Retention within the Cloud Services. Device telemetry and the analytics derived from it (daily summaries, anomaly records, energy and mould-risk models) are retained for the lifetime of the account and have no automatic expiry. Operational records — connectivity events, gateway logs and packet-loss records — expire automatically. Account, configuration and access records are retained for the lifetime of the account. The Controller may at any time instruct deletion under clause 11 or exercise an erasure request under clause 7; deletion is not dependent on any expiry period.
Backup retention. Backups are held on a rolling fourteen (14) day cycle and expire automatically. See clause 11.4.
D. Hosting
| Primary hosting region | AWS Europe (Frankfurt), eu-central-1 |
| Infrastructure provider | Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (RCS Luxembourg B186284) |
| Data at rest | eu-central-1. All datastores — MySQL (Percona XtraDB Cluster), MongoDB, ClickHouse, both Redis instances, RabbitMQ and Meilisearch — run inside the Frankfurt Kubernetes cluster on encrypted EBS volumes, spread across availability zones within the region |
| Replicas | None outside eu-central-1. MySQL is a three-node synchronous cluster and MongoDB a replica set, both within the one Frankfurt cluster; read traffic is split locally via ProxySQL. There are no cross-region read replicas |
| Backups | eu-central-1. Logical dumps written to S3 in the same region, with SSE-S3 (AES-256) default encryption and no cross-region replication. Fourteen-day rolling retention |
| LNS instance operated by MClimate | The Things Stack Cloud eu1 — Ireland, on AWS. Within the EEA; no Chapter V transfer mechanism required. Applies only where a building or device group is subscribed to the MClimate-operated instance — see clause 6.6(b) |
| Object storage | All object storage is in eu-central-1, encrypted, with no cross-region replication. |
E. Roles with access to Customer Personal Data
- Support engineers
- Software engineers and back-end developers
- Data analysts
All are bound by written confidentiality obligations and trained under the certified information security management system.
F. Technical and organisational measures
Certification. Information security management system certified to EN ISO/IEC 27001:2022, certificate reg. № BG-7063-IS, issued 19.11.2024 by Alpha Quality Certification Ltd (UIC 200229912), accredited by EA BAS (№ 9 OCC). Certified scope: “Management of information security in activities of design, manufacturing and sales of software and hardware IoT solutions for building monitoring and management.” The Processor’s integrated management system is additionally certified to ISO 9001 and ISO 14001, with a single annual surveillance audit.
Access control. Governed by the Processor’s documented procedure SOP-MCL-IT-001 Access Provisioning & Termination (v1.0, effective 2026-08-14), which forms part of the certified ISMS:
- Google Workspace is the single identity anchor; every other system authenticates against it.
- Access is granted per role against a maintained Systems & Access Matrix, with a named owner per system.
- Access to the Enterprise platform for support purposes is granted case by case for specific customer buildings, not as part of standard provisioning, and is revoked on departure.
- A same-day revocation tier applies to identity, core business, engineering and production systems, and physical access. On involuntary termination, access is revoked before or at the moment the employee is informed.
- Shared or administrative credentials known to a departing person are rotated, not merely reassigned.
- Access is reviewed against the current employee roster twice yearly, in November and May; corrections are logged.
- A dated completed offboarding checklist is retained as the access-control audit record.
Authentication. Access requires an individual named account authenticated through Google Workspace, which is the single identity anchor for every other system.
Encryption. Customer Personal Data is encrypted in transit using TLS, and at rest using AES-256:
-
Live datastores. Every production database volume is encrypted. MySQL (Percona XtraDB Cluster), MongoDB, ClickHouse, both Redis instances, RabbitMQ and Meilisearch all run in the Kubernetes cluster on EBS volumes provisioned by a default
gp3StorageClass with encryption enforced; every volume was verified as encrypted against a single KMS key. - Backups. The backup bucket applies SSE-S3 (AES-256) default encryption, which every backup object inherits.
- Application secrets. Held in AWS Secrets Manager, KMS-encrypted.
-
Key management. Keys are AWS-managed (the
aws/ebsservice key), not customer-managed.
Network and platform security. Segregated production environment; managed Kubernetes on AWS with load-balanced ingress; logging and monitoring of access to Customer Personal Data; vulnerability management and patching under the Security Policy and SLA §§10.11–10.15 (CVSS v3.1: Critical 30 days, High 60, Medium 90, Low next scheduled release).
Availability. 99.9% monthly availability commitment for the Enterprise platform, Home App and backend APIs under the SLA, with service credits. Backup and restore capability per clause 5.4.
Physical security. Data centre physical security is provided by AWS under its own certifications. The Processor’s own premises (Sofia Tech Park, Building Labs) operate controlled access limited to personnel.
Personnel. Written confidentiality undertakings; data protection and information security training; documented joiner and leaver procedures.
Incident management. Documented breach detection and response; 48-hour notification to the Controller per clause 8.1; coordinated vulnerability disclosure via security@mclimate.eu under the published Security Policy.
Supplier management. Written data protection terms with each Sub-processor; Sub-processor list maintained and published.
ANNEX 2 — Sub-processors
The current list of Sub-processors is published at Sub-processors and is incorporated into this DPA by reference. Changes to that list are notified in accordance with clause 6.3.
For each Sub-processor the list states the legal entity, its country of establishment, the purpose for which it processes Customer Personal Data, its hosting region, and — where it is established outside the European Economic Area — the transfer mechanism relied on.
A LoRaWAN Network Server operated by or procured by the Controller is not a Sub-processor of the Processor. See clause 6.6.
Questions about this agreement: privacy@mclimate.eu