This draft shows what Camplax intends to commit to. It is not in force, it is not a contract, and it must be reviewed by counsel for each market before it is offered. Every bracketed field still needs a decision.
1. Parties and roles
This addendum is between the customer named in the account (“Customer”, the controller) and [[Camplax legal entity]] (“Camplax”, the processor). It applies to personal data Customer or its end users put into Customer’s projects (“Customer Personal Data”). Camplax’s own account and billing data is covered by the Privacy Notice instead.
2. Instructions
Camplax processes Customer Personal Data only to provide the service described in the Terms and as Customer configures it in the console, API or command line, and as otherwise instructed in writing, unless law requires otherwise — in which case Camplax tells Customer first where the law allows.
3. Confidentiality and people
Only people who need access to operate the service can reach Customer Personal Data, under a duty of confidentiality. Support access to a project must be explicit, time-limited and recorded. [[Confirm the support-access implementation before stating it as a commitment.]]
4. Security
Camplax keeps the measures in Annex 2 in place for the life of the service. In summary: each app environment runs in its own isolated namespace with its own database, credentials and storage prefix; traffic is encrypted in transit; secrets are encrypted at rest and never shown back after they are saved; access is checked on every request; and security-relevant actions are logged. [[Counsel and the owner to confirm the final Annex 2 wording.]]
5. Subprocessors
Customer authorises the providers on the Subprocessors page. Camplax will give [[notice period, e.g. 30]] days’ notice before adding one, by updating that page [[and by email to subscribers]]; Customer may object on reasonable data-protection grounds, and if the objection cannot be resolved Customer may end the affected service. Camplax imposes data-protection terms on each provider no less protective than this addendum and remains responsible for them.
6. Helping Customer
Taking into account the nature of the processing, Camplax helps Customer answer requests from people exercising their rights, mostly through the console and API (for example finding, exporting or deleting a person’s sign-in record), and helps with impact assessments and consultations where required.
7. Personal data breaches
Camplax notifies Customer without undue delay, and within [[hours, e.g. 48]] hours, after becoming aware of a breach affecting Customer Personal Data, with what is known and the steps taken, and updates Customer as it learns more.
8. Deletion at the end
When Customer deletes a project or its account, Camplax removes the project’s compute, database, storage, domains and credentials through a tracked offboarding, as described on the Data Retention & Deletion page, except where law requires Camplax to keep something. Backups age out within [[backup retention period]].
9. Audits
Camplax makes available the information needed to show it meets this addendum, and allows reasonable audits [[frequency, notice and cost terms]].
10. International transfers
Customer apps and databases run in the United States, and the control plane runs on Cloudflare’s global network. Where Customer Personal Data is transferred out of the European Economic Area, the United Kingdom or Switzerland, the transfer relies on [[the EU Standard Contractual Clauses (Module 2 controller-to-processor, Module 3 processor-to-processor), the UK Addendum and the Swiss amendments, incorporated by reference — counsel to confirm]].
Annex 1: The processing
| Subject matter and duration | Hosting and operating Customer’s apps for as long as Customer uses the service. |
| Nature and purpose | Storing, serving, backing up and deleting data, as Customer’s apps and settings direct. |
| People concerned | Customer’s end users and anyone else whose data Customer puts into its projects. |
| Kinds of data | Whatever Customer’s apps store: typically sign-in details (email, name, hashed password), app records, uploaded files, logs and analytics events. [[Special-category data only if Customer confirms Camplax supports the safeguards required.]] |
Annex 2: Security measures
- Isolation: one Kubernetes namespace, database cluster, credential set and storage prefix per app environment; network policy denies traffic between tenants; apps run in a gVisor sandbox.
- Encryption: TLS from visitors to the edge and through Cloudflare Tunnel to the servers; secrets sealed with AES-GCM bound to their project.
- Access: every request authenticated and checked against the project and role; destructive actions need a second confirmation; support access is time-limited and logged.
- Monitoring: audit records for secrets, keys, members, deploys, exports and deletions; alerts on backup failures and platform health.
- Backups: continuous database archiving to object storage. [[Confirm retention and restore testing before stating them as commitments.]]
Annex 3: Subprocessors
The current list is the Subprocessors page.