Download the template agreement (PDF)

Data processing agreement (DPA)

Last updated: October 7, 2026

Status and how this agreement is concluded

This data processing agreement ("DPA") applies between the customer who uses mivochart for an organisation ("Customer", the controller) and the operator of mivochart ("we", the processor) whenever the Customer's charts contain personal data. It forms part of the terms of service and is concluded by accepting them. You can download it as a PDF, for example to file it or to have it signed.

Processor: MIVO STUDIO S.R.L., Strada Teilor, Nr. 49B, Corp C3, Ap. 2, 407280 Sat Floreşti, Comuna Floreşti, Jud. Cluj, Romania, hello@mivochart.com.

1. Subject matter and duration

We process personal data on the Customer's behalf to provide mivochart: storing, displaying, editing, versioning, sharing and backing up the Customer's org charts. Annex 1 describes the data, the people concerned and the processing. The DPA applies for as long as we process personal data for the Customer.

2. Instructions

We process the data only on the Customer's documented instructions, including with regard to transfers outside the EU, unless the law requires otherwise; in that case we tell the Customer first, unless the law forbids it. The Customer's instructions are these terms and this DPA, and the Customer's use and settings of the service (for example turning a share link on). We tell the Customer at once if we believe an instruction infringes data protection law.

We do not use the data for our own purposes, do not sell it and do not combine it with other data.

3. The Customer's responsibilities

The Customer is responsible for the lawfulness of the processing, in particular for having a legal basis, for informing the people concerned (Art. 13 and 14 GDPR), for involving employee representatives where the law requires it, for deciding who receives share links and embeds, and for not entering special categories of data unless the law allows it.

4. Confidentiality

Everyone we authorise to process the data is bound to confidentiality by contract or by law, and only accesses it as far as needed, for example to answer a support request from the Customer.

5. Security

We take the technical and organisational measures described in Annex 2 (Art. 32 GDPR). We may adapt them to technical progress, as long as the level of protection does not fall.

6. Sub-processors

The Customer generally authorises us to use sub-processors. The sub-processors in use when this DPA is concluded are listed in Annex 3 and on our sub-processors page. We bind every sub-processor to data protection obligations that are equivalent to this DPA.

We will inform the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by updating the sub-processors page and by email to the account email address. The Customer may object on reasonable data protection grounds within that period. If we cannot address the objection, the Customer may end the affected service, and we refund the unused part of any prepaid fee.

7. Help with requests from data subjects

The Customer can answer most requests itself in the service: it can correct or delete people, delete charts and versions, export a chart as CSV, and export its whole account. We help with anything the Customer cannot do itself, as far as reasonable. If a data subject contacts us directly, we forward the request to the Customer and do not answer it ourselves unless the Customer asks us to.

8. Other assistance

Taking into account the nature of the processing and the information available to us, we help the Customer to meet its obligations under Art. 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation).

9. Personal data breaches

We notify the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting the Customer's data. We share what we know (what happened, which data and people may be affected, likely consequences and the measures taken or proposed) and provide further information as it becomes available. Incident contact: hello@mivochart.com.

10. Deletion and return

The Customer can export its data at any time. When the Customer deletes a chart or its account, we delete the related data from the live service at once; we keep no database backups, so nothing stays behind in backups. We keep data only where the law requires us to.

11. Information and audits

We make available the information needed to show compliance with Art. 28 GDPR, for example by answering security questionnaires and providing our providers' certifications. The Customer may carry out audits, including inspections, by itself or by an auditor bound to confidentiality, with reasonable notice, during business hours and without disrupting operations, normally once a year. Each party bears its own costs, unless the audit reveals a material breach on our part.

12. Transfers outside the EU

Chart data is stored in the EU (Frankfurt, Germany). Where a sub-processor processes data in a country without an EU adequacy decision, or can access it from there, the transfer is protected by the EU Standard Contractual Clauses or, where the provider is certified, the EU-U.S. Data Privacy Framework.

13. Liability and order of precedence

Liability follows Art. 82 GDPR and the terms of service. If this DPA and the terms of service conflict on data protection, this DPA prevails.

Annex 1: Data subjects, data and processing

Data subjects: the people the Customer puts into its charts, typically employees, managers, contractors and other staff of the Customer's organisation, including former staff if the Customer keeps them in older versions.

  • Categories of data: name; job title; department; reporting lines (manager, dotted-line managers, assistant role); work email address; employee number; photo or photo link; start date; full-time equivalent (FTE); open positions and their status; values of custom fields defined by the Customer (text, numbers, dates, links, email addresses, phone numbers, choice lists); free text on the canvas; chart titles; named versions containing earlier states of all of the above.
  • Special categories (Art. 9 GDPR): not intended. The Customer should not enter them unless the law allows it.
  • Processing: storage in the database; display in the editor and through share links and embeds the Customer turns on; creating and restoring versions; photo storage and time-limited photo links; backups; deletion. Imports and exports are processed in the user's browser.
  • Duration: until the Customer deletes the data or its account, plus the backup window in section 10.

Annex 2: Technical and organisational measures

  • Location: database, sign-in and photo storage in the EU (Supabase, Frankfurt, Germany).
  • Encryption: all connections use TLS (HTTPS); data is encrypted at rest by our database provider.
  • Access control: row-level security on every database table, so an account can only read its own charts; share settings, password hashes and billing records are readable only by our server; server keys are kept in the hosting provider's encrypted settings, never in the browser.
  • Photos: stored in a private bucket, in a folder per account and chart; shown only through signed links that expire after one hour; resized and re-encoded in the browser before upload, which drops embedded metadata; file type checked on the server from the file's content.
  • Share links: random tokens; optional password stored as a scrypt hash; unlock cookie signed with HMAC, httpOnly and valid for 24 hours; at most 5 password attempts per IP address and link in 10 minutes and 50 per link in 15 minutes; optional expiry; links can be turned off at once.
  • Protection against embedding: our pages cannot be shown inside other websites (X-Frame-Options and Content-Security-Policy), except the embed view of charts the Customer chooses to embed.
  • No third-party scripts or trackers on our pages; fonts are served by us.
  • Data minimisation: imports and exports run in the browser; the private mode keeps charts on the device; shared charts and embeds contain only the fields shown on the cards (hidden fields, such as employee numbers, are removed on the server), and people moved to “Not placed” are left out.
  • Integrity and availability: version numbers prevent one save from silently overwriting another; unsaved edits are backed up in the browser until the server confirms them; database backups by our provider.
  • Deletion: chart and account deletion in self-service, including photo files; released photos are deleted once no version uses them.
  • Organisation: access to production data only for authorised staff and only as needed; confidentiality obligations; review of sub-processors; incident handling as described in section 9.

Annex 3: Sub-processors

The following sub-processors process the Customer's chart data:

Sub-processorServiceLocation of the data
Supabase Inc., USADatabase, sign-in, photo storage, backupsEU, Frankfurt (Germany)
Vercel Inc., USAHosting, delivery of the website and server functions; chart data passes through when it is loaded or savedFrankfurt, Germany (fra1)
Back to the home page