Legal
Data Processing Agreement
Last updated 13 August 2026
Draft. Not yet legally reviewed.
This document is a working template with placeholder company details. It is not legal advice and must be reviewed by a qualified lawyer before launch.
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and puka.studio [LEGAL FORM — TODO] (“Processor”, “Puka”) and reflects the parties’ obligations under Article 28 GDPR where Puka processes personal data on the Controller’s behalf — for example, listener and analytics data associated with the Controller’s podcasts.
1. Roles
For personal data the Controller submits to or generates through the Service (e.g. show and listener data), the customer is the Controller and Puka is the Processor. For account and billing data, Puka acts as an independent controller as described in the Privacy Policy.
2. Subject matter and duration
Puka processes personal data only to provide the Service for the duration of the agreement. The subject matter is the hosting, distribution, and analytics of the Controller’s podcast content. Categories of data subjects include the Controller’s team members and podcast listeners; categories of data include identifiers, usage and download statistics, and any personal data contained in show metadata.
3. Processing on instructions
Puka processes personal data only on the documented instructions of the Controller, including as configured through the Service, unless required otherwise by EU or member-state law. Puka will inform the Controller if it believes an instruction infringes the GDPR.
4. Confidentiality
Puka ensures that persons authorized to process personal data are bound by confidentiality obligations and process data only as necessary.
5. Security measures
Puka implements appropriate technical and organizational measures under Article 32 GDPR, including encryption in transit, access controls, EU-based hosting, and regular review of its security posture.
6. Sub-processors
The Controller authorizes Puka to engage the sub-processors listed below. Puka imposes data protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance. Puka will give notice of intended changes and allow the Controller to object on reasonable grounds.
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing and subscription billing | Ireland / USA | EU Standard Contractual Clauses; EU-U.S. Data Privacy Framework |
| Resend (Plover, Inc.) | Transactional email delivery (verification, invitations, notifications) | USA | EU Standard Contractual Clauses |
| PostHog (EU Cloud) | Product and usage analytics | European Union (Frankfurt, Germany) | Processed within the EU |
| [Hosting provider — TODO: confirm] | Application hosting and object storage (audio, images) | Austria / European Union | Processed within the EU |
7. Assistance
Taking into account the nature of processing, Puka assists the Controller with data subject requests and with the Controller’s obligations under Articles 32–36 GDPR (security, breach notification, and impact assessments) to the extent reasonably possible.
8. Breach notification
Puka notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and provides information reasonably available to assist the Controller’s reporting obligations.
9. International transfers
Where a sub-processor processes personal data outside the EU/EEA, such transfers are governed by EU Standard Contractual Clauses or another lawful transfer mechanism, as indicated above.
10. Return and deletion
On termination, Puka deletes or returns personal data processed on the Controller’s behalf within a reasonable period, except where retention is required by law.
11. Audits
Puka makes available information necessary to demonstrate compliance with Article 28 GDPR and allows for reasonable audits, subject to appropriate confidentiality and security arrangements.
12. Contact
To request a signed copy of this DPA or ask questions, contact privacy@puka.cloud.