Compliance Document

GDPR /
Data Processing Addendum (DPA)

Legal framework for business customers and agencies

Contracting Parties

This Addendum (DPA) is entered into with the operator: Ondřej Frait (Company ID: 09586105, based in Olomouc). DashFast acts here as the Data Processor of personal metrics that you (as the Data Controller) feed into the platform via our client telemetry telemetry payload script.

Subject of Processing

The scope of processing encompasses technical characteristics of user sessions across the Controller's web applications to compile automated telemetry analytics graphs.

  • Data Categories:Technical data strings (anonymized hash sequences), client metadata contexts, geo-location profiles (city/country), origin tracking URLs, and layout interaction events.

Security Baselines

Data in transit encryption (HTTPS/TLS standard layout)
Data at rest encryption (AES-256 standard via Neon DB infrastructure)
Strict schema project isolation models across databases
Instantaneous IP address stripping routine (IP Masking)
Daily rotating salt sequences protecting visitor hash signatures
Continuous audit logging across infrastructure gateways

Authorized Sub-processors

EntityGeographyCertification Baseline
Neon, Inc.Relational cluster layer management (PostgreSQL)USA / EU (AWS Frankfurt)Encryption at Rest
Stripe, Inc.Transaction flow settlement and invoicing managementGlobal operations (EU residency assignment models)PCI DSS Level 1

Purging and Ingestion Offloading

Governed by your Controller jurisdiction rights, you retain permissions to execute an absolute target project data wipe at any moment. Upon customer account termination, production environment metrics clear within 30 days. To shift data objects out of our infrastructure, the interface offers flat file raw format exports via JSON.

DashFast DPA v1.0 — Olomouc, CZ
Last updated: 2026