Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement between Ekon Labs (“Processor”) and the Client (“Controller”) and governs the processing of personal data in accordance with GDPR Article 28.
Last updated: 1 August 2026
1. Parties & Definitions
Data Controller
The Client
The natural or legal person who determines the purposes and means of processing personal data.
Data Processor
Ekon Labs
Processes personal data on behalf of the Controller in accordance with this DPA.
2. Scope & Purpose
This DPA applies to all processing of personal data carried out by Ekon Labs as Processor on behalf of the Client as Controller in connection with the provision of Ekon Labs services, including software products, automation systems, CRM platforms, and consulting services.
Subject Matter of Processing
- Contact and lead data stored in CRM systems
- Client and customer data processed through automation workflows
- User account data for software platform access
- Communication data processed through marketing automation
- Any other personal data submitted by the Controller through our Services
3. Processor Obligations
As Processor, Ekon Labs undertakes to:
- Process personal data only on documented instructions from the Controller
- Ensure that persons authorised to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures in accordance with GDPR Article 32
- Assist the Controller in responding to data subject rights requests
- Assist the Controller in fulfilling obligations under Articles 32–36 GDPR
- Delete or return all personal data upon termination of the agreement
- Provide all information necessary to demonstrate compliance with this DPA
- Notify the Controller without undue delay upon becoming aware of a personal data breach
4. Customer Instructions
Ekon Labs acts solely as a Processor and processes personal data only on the documented instructions of the Controller. The Controller is responsible for:
- Determining the legal basis for the processing of personal data under applicable law, including GDPR Article 6
- Ensuring that personal data is collected and processed lawfully before it is submitted to Ekon Labs for processing
- Providing instructions that are lawful, complete and consistent with applicable data protection legislation
- Ensuring that data subjects have been informed of the processing in accordance with applicable transparency requirements
Where Ekon Labs reasonably believes that an instruction from the Controller would infringe applicable data protection law, Ekon Labs shall promptly inform the Controller. Ekon Labs shall not be required to follow instructions that would place it in breach of applicable law.
5. Sub-Processors
The Controller grants general authorisation for the Processor to engage sub-processors. Ekon Labs maintains a centrally managed Sub-Processor List, which is published in the to this DPA and kept up to date within the Ekon Labs Trust Center. The Processor shall inform the Controller of any intended changes to sub-processors with reasonable advance notice, giving the Controller the opportunity to object.
The Processor shall impose data protection obligations on sub-processors equivalent to those in this DPA and shall remain liable to the Controller for the performance of sub-processors' obligations.
The current list of approved sub-processors is set out in the to this DPA. The most up-to-date version is always available at https://www.ekon-labs.com/legal/data-processing-agreement#annex.
6. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risks to the rights and freedoms of natural persons, Ekon Labs implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32. These measures include, but are not limited to:
The specific technical and organisational measures applied may evolve over time to reflect improvements in industry best practices and changes in the threat landscape. Ekon Labs will not reduce the overall level of security provided under this DPA without reasonable notice to the Controller.
7. International Transfers
Where personal data is transferred to sub-processors located outside the EEA, the Processor ensures that appropriate safeguards are in place in accordance with GDPR Chapter V, including Standard Contractual Clauses (SCCs) as approved by the European Commission.
The Controller may request copies of applicable transfer mechanisms by contacting service@ekon-labs.com.
8. Retention & Deletion
Upon termination or expiry of the service agreement, the Processor shall, at the Controller's choice:
- Delete all personal data and certify deletion in writing; or
- Return all personal data to the Controller in a portable format
The Controller must submit a deletion or return request within 30 days of termination. After this period, the Processor may delete all data in accordance with its standard retention schedule. The Processor may retain personal data where required by applicable law, for the minimum period required.
9. Incident Notification
In the event of a personal data breach, Ekon Labs shall notify the Controller without undue delay and in accordance with applicable law upon becoming aware of the breach. The notification shall include, to the extent available at the time of notification:
- A description of the nature of the breach, including categories and approximate number of data subjects and records affected
- The name and contact details of the responsible contact point at Ekon Labs (service@ekon-labs.com)
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach and mitigate its effects
Where it is not possible to provide all information at the time of initial notification, Ekon Labs shall provide further information in phases as it becomes available. The Controller remains responsible for notifying the relevant supervisory authority and, where required, affected data subjects in accordance with applicable law.
10. Government Requests
If Ekon Labs receives a legally binding request from a governmental, regulatory or law enforcement authority for access to personal data processed on behalf of the Controller, Ekon Labs shall:
- Carefully review the request to assess its legal validity and scope
- Disclose only the minimum information that is strictly required by the applicable legal obligation
- Notify the Controller of the request as soon as reasonably practicable and to the extent permitted by applicable law
- Where notification to the Controller is legally prohibited, record the request and provide the Controller with such information as can be disclosed once the prohibition is lifted
Ekon Labs will not voluntarily disclose personal data to any governmental or regulatory authority without a legally binding requirement to do so. Where permitted by law, Ekon Labs will challenge requests that it reasonably believes to be unlawful, disproportionate or otherwise not in accordance with applicable legal requirements.
11. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
Audit requests must be submitted in writing with at least 30 days' notice. Audits shall be conducted during normal business hours, at the Controller's expense, and in a manner that minimises disruption to the Processor's operations. The Processor may require the auditor to sign a confidentiality agreement before the audit commences.
12. Termination
This DPA shall remain in force for the duration of the service agreement between the parties. Termination of the service agreement shall automatically terminate this DPA. The obligations of confidentiality and data deletion shall survive termination.
Annex: Approved Sub-Processors
Ekon Labs maintains a centrally managed Sub-Processor List. The following sub-processors represent the current approved providers as of the last updated date of this DPA. The most current version of this list is always available at https://www.ekon-labs.com/legal/data-processing-agreement#annex.Ekon Labs will notify Controllers of material changes to this list in accordance with Section 5 of this DPA.
| Sub-Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Database and authentication | European Union / United States | SCCs / Adequacy |
| Netlify | Web hosting and deployment | United States | SCCs / Adequacy |
| Cloudflare | CDN, DNS, DDoS protection | United States | SCCs / Adequacy |
| OpenAI | AI language model services | United States | SCCs / Adequacy |
| Anthropic (Claude) | AI language model services | United States | SCCs / Adequacy |
| Google (Analytics, Workspace) | Analytics, email, productivity | United States / European Union | SCCs / Adequacy |
| Microsoft (Azure, 365) | Cloud infrastructure, productivity | European Union / United States | SCCs / Adequacy |
| CRM & Automation Platform | CRM systems, marketing automation and business software | United States | SCCs / Adequacy |
| Stripe | Payment processing | United States / European Union | SCCs / Adequacy |
To request a signed DPA or for questions about sub-processors, contact service@ekon-labs.com.