lathe

Data Processing Agreement

This DPA forms part of the Terms of Service between you ("Controller") and Lathe ("Processor") and applies where you process personal data subject to the GDPR or UK GDPR in your instance.

1. Subject matter and duration

The Processor provides managed database instances running Postgres 17, Redis 8, CouchDB 3 and NATS 2 on a dedicated virtual machine per Controller. Processing lasts for the term of the service plus the 7-day snapshot retention after deletion.

2. Nature and purpose

Storage, backup and availability of data the Controller writes to its instance. The Processor does not determine the purposes of the data and does not access it except as described in section 7 of the Terms.

3. Categories of data and data subjects

Determined solely by the Controller. The Controller confirms it does not store special-category data without appropriate measures of its own (encryption at the application layer).

4. Processor obligations

  • Process personal data only on the Controller's documented instructions, which are the use of the service through the console and API.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures in section 6.
  • Assist the Controller with data-subject requests to the extent the service allows (you have full SQL access to your data).
  • Notify the Controller without undue delay, and within 72 hours, of a personal-data breach affecting its instance.
  • Delete all personal data on termination, subject to the 7-day snapshot retention, unless law requires retention.
  • Make available information necessary to demonstrate compliance and allow audits on reasonable notice, at the Controller's cost.

5. Subprocessors

The Controller authorises the subprocessors listed at https://lathe.computer/subprocessors, which forms part of this DPA. Additions and replacements are announced by email at least 30 days in advance; the Controller may object by terminating the service before the change takes effect.

6. Security measures

  • One dedicated virtual machine per Controller; no shared database processes between customers.
  • TLS required for every database connection; SCRAM-SHA-256 password authentication; optional IP allowlist.
  • No shell or superuser access for customers; administrative access to machines limited to the Processor's control plane over SSH with key authentication from a single fixed address.
  • Daily disk-image backups retained 7 days; snapshot before every destructive action; monthly automated restore tests.
  • Weekly security patching; delete protection on every machine; audit log of every administrative action.

7. International transfers

Data at rest stays in the EU. The Processor's staff may administer the service from Israel, which benefits from an EU adequacy decision.

8. Liability

Liability under this DPA is subject to the limitations in the Terms of Service.

Contact for privacy matters: support@lathe.computer. Last updated 5 September 2026.

Are you sure?