PROD欧洲主权BaaS平台打开仪表板 →
GDPR 第 28 条·数据处理协议

数据处理协议

GDPR 合同为 Aurabase 作为处理者处理您的个人数据建立了法律框架。在 Pro 计划中,从您的 Studio 中一键即可签署。

一键签署 DPA
Studio → 设置 → 合规性 → “签署 DPA”。自动会签。可下载 PDF,存档 10 年。
前往工作室
#
派对

谁签署什么

本 DPA 是以下双方之间的协议:

  • 数据控制器 — 您(或您的公司),即通过 Aurabase 收集和使用个人数据的实体。
  • 数据处理器 — Aurabase SAS(法国巴黎),根据您的指示代表您处理数据。
Info
DPA 模板遵循 标准合同条款 欧盟委员会通过(第 2021/914 号决定)。可根据企业计划进行定制。
#
目的

什么数据,用于什么目的

类别相关数据保留期限
End usersEmail, password hash, profile, sessions, IP, user-agentUntil account deletion
Application contentAll data stored in your Postgres tablesDuration of project + 30 days after deletion
FilesBinary objects stored in your Storage bucketsDuration of project + 30 days
Operational logsAggregated metrics, anonymized traces30 days (Pro) / 2 years (Enterprise)
BillingName, address, VAT number, payment history10 years (legal obligation)
#
子处理者

6家经过认证的第三方

我们利用这些子处理者来提供服务。任何子处理者变更均需提前 30 天通知,并有权提出反对。

Scaleway SASFrance (Paris fr-par-1, fr-par-2, fr-par-3)
Primary managed cloud hosting: Kubernetes Kapsule, PostgreSQL HA (RDB), S3 Object Storage, Redis, Load Balancer, and Cockpit
保障措施: 100% EU Sovereign · ISO 27001, HDS, SecNumCloud-ready certifications · Scaleway DPA
Hetzner Online GmbHGermany (Nuremberg, Falkenstein)
Secondary compute infrastructure, Edge server nodes, and block volume storage
保障措施: 100% EU Sovereign · ISO 27001 certification · Hetzner DPA
Mollie B.V.Netherlands (Amsterdam, EU)
Sovereign and secure payment processing (Credit Cards / Visa / Mastercard) and SEPA direct debits
保障措施: 100% EU Sovereign · Dutch Central Bank (DNB) authorization · PCI-DSS Level 1 certification · Mollie DPA
Twilio Ireland LtdIreland (EU) / Global
SMS authentication routing and critical notification delivery
保障措施: Twilio DPA · Binding Corporate Rules (BCR) · Standard Contractual Clauses (SCC)
Apple Inc. (APNs) & Google LLC (FCM)European Union & Global
Mobile push notification gateways for iOS and Android
保障措施: End-to-end notification payload encryption · Standard Contractual Clauses (SCC)
Let’s Encrypt (ISRG)Global
Issuance and automatic renewal of TLS/SSL certificates
保障措施: Open standard X.509 RFC 8555 (ACME)
#
权利

您作为数据主体的权利

  • 访问权 — 获取结构化格式 (JSON/CSV) 的个人数据副本
  • 整改权 — 更正您不准确的数据
  • 删除权 — 请求删除(须遵守法定法律义务)
  • 数据可移植性的权利 — 以机器可读格式接收您的数据
  • 反对权 — 拒绝特定的处理活动(营销、分析)
  • 限制权 — 在争议期间请求暂时冻结数据处理
Astuce
行使这些权利: 隐私@aurabase.cloud — 30 天内回复。对于完整导出,请使用 CLI 命令 光环导出 --user <电子邮件> --format jsonl.
#
通知

数据泄露

如果发生影响您数据的违规行为,我们承诺:

  • 在任何情况下立即通知您 48小时内
  • 详细说明违规的性质、类别和受影响数据的大致数量
  • 在 5 个工作日内分享全面的事件报告
  • 配合任何强制性法律通知(CNIL、监管机构)
#
下载

获取完整的 PDF

PDF — 即将推出了解您的 GDPR 权利
DPA 很快就会以 PDF 格式提供。联系方式 法律@aurabase.cloud 如有任何疑问。
企业?

为您的行业量身定制的 DPA。

针对医疗保健 (HIPAA)、金融 (PCI DSS) 或国防的特定条款。联系我们的团队。

无需信用卡 · 500 MB 免费 · 50,000 MAU