Logo
EkonLabs
GDPR Article 28

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between Ekon Labs (“Processor”) and the Client (“Controller”) and governs the processing of personal data in accordance with GDPR Article 28.

Last updated: 1 August 2026

1. Parties & Definitions

Data Controller

The Client

The natural or legal person who determines the purposes and means of processing personal data.

Data Processor

Ekon Labs

Processes personal data on behalf of the Controller in accordance with this DPA.

"Personal Data"Any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1).
"Processing"Any operation performed on personal data as defined in GDPR Article 4(2).
"Data Subject"The natural person to whom the personal data relates.
"Sub-Processor"Any third party engaged by the Processor to process personal data on behalf of the Controller.
"Security Incident"A breach of security leading to accidental or unlawful destruction, loss, alteration, or disclosure of personal data.

2. Scope & Purpose

This DPA applies to all processing of personal data carried out by Ekon Labs as Processor on behalf of the Client as Controller in connection with the provision of Ekon Labs services, including software products, automation systems, CRM platforms, and consulting services.

Subject Matter of Processing

  • Contact and lead data stored in CRM systems
  • Client and customer data processed through automation workflows
  • User account data for software platform access
  • Communication data processed through marketing automation
  • Any other personal data submitted by the Controller through our Services

3. Processor Obligations

As Processor, Ekon Labs undertakes to:

  • Process personal data only on documented instructions from the Controller
  • Ensure that persons authorised to process personal data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures in accordance with GDPR Article 32
  • Assist the Controller in responding to data subject rights requests
  • Assist the Controller in fulfilling obligations under Articles 32–36 GDPR
  • Delete or return all personal data upon termination of the agreement
  • Provide all information necessary to demonstrate compliance with this DPA
  • Notify the Controller without undue delay upon becoming aware of a personal data breach

4. Customer Instructions

Ekon Labs acts solely as a Processor and processes personal data only on the documented instructions of the Controller. The Controller is responsible for:

  • Determining the legal basis for the processing of personal data under applicable law, including GDPR Article 6
  • Ensuring that personal data is collected and processed lawfully before it is submitted to Ekon Labs for processing
  • Providing instructions that are lawful, complete and consistent with applicable data protection legislation
  • Ensuring that data subjects have been informed of the processing in accordance with applicable transparency requirements

Where Ekon Labs reasonably believes that an instruction from the Controller would infringe applicable data protection law, Ekon Labs shall promptly inform the Controller. Ekon Labs shall not be required to follow instructions that would place it in breach of applicable law.

5. Sub-Processors

The Controller grants general authorisation for the Processor to engage sub-processors. Ekon Labs maintains a centrally managed Sub-Processor List, which is published in the to this DPA and kept up to date within the Ekon Labs Trust Center. The Processor shall inform the Controller of any intended changes to sub-processors with reasonable advance notice, giving the Controller the opportunity to object.

The Processor shall impose data protection obligations on sub-processors equivalent to those in this DPA and shall remain liable to the Controller for the performance of sub-processors' obligations.

The current list of approved sub-processors is set out in the to this DPA. The most up-to-date version is always available at https://www.ekon-labs.com/legal/data-processing-agreement#annex.

6. Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risks to the rights and freedoms of natural persons, Ekon Labs implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32. These measures include, but are not limited to:

Encryption of personal data in transit and at rest using industry-standard protocols
Ongoing confidentiality, integrity, availability and resilience of processing systems
Role-based access controls and the principle of least privilege
Multi-factor authentication for access to systems processing personal data
Regular testing, assessment and evaluation of the effectiveness of security measures
Incident response and personal data breach notification procedures
Employee security awareness and training programmes
Data minimisation and pseudonymisation where appropriate
Regular backups with tested recovery procedures
Vendor and supply chain security assessments

The specific technical and organisational measures applied may evolve over time to reflect improvements in industry best practices and changes in the threat landscape. Ekon Labs will not reduce the overall level of security provided under this DPA without reasonable notice to the Controller.

7. International Transfers

Where personal data is transferred to sub-processors located outside the EEA, the Processor ensures that appropriate safeguards are in place in accordance with GDPR Chapter V, including Standard Contractual Clauses (SCCs) as approved by the European Commission.

The Controller may request copies of applicable transfer mechanisms by contacting service@ekon-labs.com.

8. Retention & Deletion

Upon termination or expiry of the service agreement, the Processor shall, at the Controller's choice:

  • Delete all personal data and certify deletion in writing; or
  • Return all personal data to the Controller in a portable format

The Controller must submit a deletion or return request within 30 days of termination. After this period, the Processor may delete all data in accordance with its standard retention schedule. The Processor may retain personal data where required by applicable law, for the minimum period required.

9. Incident Notification

In the event of a personal data breach, Ekon Labs shall notify the Controller without undue delay and in accordance with applicable law upon becoming aware of the breach. The notification shall include, to the extent available at the time of notification:

  • A description of the nature of the breach, including categories and approximate number of data subjects and records affected
  • The name and contact details of the responsible contact point at Ekon Labs (service@ekon-labs.com)
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach and mitigate its effects

Where it is not possible to provide all information at the time of initial notification, Ekon Labs shall provide further information in phases as it becomes available. The Controller remains responsible for notifying the relevant supervisory authority and, where required, affected data subjects in accordance with applicable law.

10. Government Requests

If Ekon Labs receives a legally binding request from a governmental, regulatory or law enforcement authority for access to personal data processed on behalf of the Controller, Ekon Labs shall:

  • Carefully review the request to assess its legal validity and scope
  • Disclose only the minimum information that is strictly required by the applicable legal obligation
  • Notify the Controller of the request as soon as reasonably practicable and to the extent permitted by applicable law
  • Where notification to the Controller is legally prohibited, record the request and provide the Controller with such information as can be disclosed once the prohibition is lifted

Ekon Labs will not voluntarily disclose personal data to any governmental or regulatory authority without a legally binding requirement to do so. Where permitted by law, Ekon Labs will challenge requests that it reasonably believes to be unlawful, disproportionate or otherwise not in accordance with applicable legal requirements.

11. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

Audit requests must be submitted in writing with at least 30 days' notice. Audits shall be conducted during normal business hours, at the Controller's expense, and in a manner that minimises disruption to the Processor's operations. The Processor may require the auditor to sign a confidentiality agreement before the audit commences.

12. Termination

This DPA shall remain in force for the duration of the service agreement between the parties. Termination of the service agreement shall automatically terminate this DPA. The obligations of confidentiality and data deletion shall survive termination.

Annex: Approved Sub-Processors

Ekon Labs maintains a centrally managed Sub-Processor List. The following sub-processors represent the current approved providers as of the last updated date of this DPA. The most current version of this list is always available at https://www.ekon-labs.com/legal/data-processing-agreement#annex.Ekon Labs will notify Controllers of material changes to this list in accordance with Section 5 of this DPA.

Sub-ProcessorPurposeLocationSafeguard
SupabaseDatabase and authenticationEuropean Union / United StatesSCCs / Adequacy
NetlifyWeb hosting and deploymentUnited StatesSCCs / Adequacy
CloudflareCDN, DNS, DDoS protectionUnited StatesSCCs / Adequacy
OpenAIAI language model servicesUnited StatesSCCs / Adequacy
Anthropic (Claude)AI language model servicesUnited StatesSCCs / Adequacy
Google (Analytics, Workspace)Analytics, email, productivityUnited States / European UnionSCCs / Adequacy
Microsoft (Azure, 365)Cloud infrastructure, productivityEuropean Union / United StatesSCCs / Adequacy
CRM & Automation PlatformCRM systems, marketing automation and business softwareUnited StatesSCCs / Adequacy
StripePayment processingUnited States / European UnionSCCs / Adequacy

To request a signed DPA or for questions about sub-processors, contact service@ekon-labs.com.