Legal

Data Processing Agreement

Last updated 13 August 2026

Draft. Not yet legally reviewed.

This document is a working template with placeholder company details. It is not legal advice and must be reviewed by a qualified lawyer before launch.

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and puka.studio [LEGAL FORM — TODO] (“Processor”, “Puka”) and reflects the parties’ obligations under Article 28 GDPR where Puka processes personal data on the Controller’s behalf — for example, listener and analytics data associated with the Controller’s podcasts.

1. Roles

For personal data the Controller submits to or generates through the Service (e.g. show and listener data), the customer is the Controller and Puka is the Processor. For account and billing data, Puka acts as an independent controller as described in the Privacy Policy.

2. Subject matter and duration

Puka processes personal data only to provide the Service for the duration of the agreement. The subject matter is the hosting, distribution, and analytics of the Controller’s podcast content. Categories of data subjects include the Controller’s team members and podcast listeners; categories of data include identifiers, usage and download statistics, and any personal data contained in show metadata.

3. Processing on instructions

Puka processes personal data only on the documented instructions of the Controller, including as configured through the Service, unless required otherwise by EU or member-state law. Puka will inform the Controller if it believes an instruction infringes the GDPR.

4. Confidentiality

Puka ensures that persons authorized to process personal data are bound by confidentiality obligations and process data only as necessary.

5. Security measures

Puka implements appropriate technical and organizational measures under Article 32 GDPR, including encryption in transit, access controls, EU-based hosting, and regular review of its security posture.

6. Sub-processors

The Controller authorizes Puka to engage the sub-processors listed below. Puka imposes data protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance. Puka will give notice of intended changes and allow the Controller to object on reasonable grounds.

Sub-processor Purpose Location Safeguard
Stripe Payments Europe, Ltd. / Stripe, Inc. Payment processing and subscription billing Ireland / USA EU Standard Contractual Clauses; EU-U.S. Data Privacy Framework
Resend (Plover, Inc.) Transactional email delivery (verification, invitations, notifications) USA EU Standard Contractual Clauses
PostHog (EU Cloud) Product and usage analytics European Union (Frankfurt, Germany) Processed within the EU
[Hosting provider — TODO: confirm] Application hosting and object storage (audio, images) Austria / European Union Processed within the EU

7. Assistance

Taking into account the nature of processing, Puka assists the Controller with data subject requests and with the Controller’s obligations under Articles 32–36 GDPR (security, breach notification, and impact assessments) to the extent reasonably possible.

8. Breach notification

Puka notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and provides information reasonably available to assist the Controller’s reporting obligations.

9. International transfers

Where a sub-processor processes personal data outside the EU/EEA, such transfers are governed by EU Standard Contractual Clauses or another lawful transfer mechanism, as indicated above.

10. Return and deletion

On termination, Puka deletes or returns personal data processed on the Controller’s behalf within a reasonable period, except where retention is required by law.

11. Audits

Puka makes available information necessary to demonstrate compliance with Article 28 GDPR and allows for reasonable audits, subject to appropriate confidentiality and security arrangements.

12. Contact

To request a signed copy of this DPA or ask questions, contact privacy@puka.cloud.