SandPlane Data Processing Addendum
Effective and last updated: July 22, 2026 · Version 2026-07-22
This Data Processing Addendum ("DPA") forms part of the SandPlane Terms of Service or other agreement for the Service ("Agreement") between the customer identified in the Agreement ("Controller") and Monoceros s. r. o., provider of SandPlane ("Processor"). It applies when Processor handles Personal Data on Controller's behalf.
1. Definitions and scope
"Data Protection Law" means the GDPR, UK GDPR, Slovak Act No. 18/2018 Coll., and other privacy laws applicable to the processing. "Personal Data", "process", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have their meanings under applicable Data Protection Law. This DPA does not govern processing for which Monoceros is an independent controller, as described in the Privacy Statement.
2. Documented instructions
Processor will process Personal Data only on Controller's documented instructions, including the Agreement, Controller's configuration and use of the Service, support requests, and other written instructions agreed by the parties. Processor will process data only to provide, secure, maintain, and support the Service, unless Union or Member State law requires otherwise. In that case Processor will inform Controller before processing, unless the law prohibits notice.
Processor will immediately inform Controller if, in its opinion, an instruction infringes Data Protection Law and may suspend that instruction while the parties resolve the issue. Controller is responsible for the lawfulness, accuracy, transparency, and minimisation of its instructions and Personal Data.
3. Confidentiality and personnel
Processor will ensure that people authorised to process Personal Data are bound by confidentiality obligations, receive appropriate privacy and security guidance, and access data only as necessary for their duties.
4. Security
Taking into account the state of the art, implementation costs, scope and purposes, and risks to individuals, Processor will maintain appropriate technical and organisational measures under Article 32 GDPR. Current measures are summarised in Annex II. Processor may update them provided the overall level of protection is not materially reduced.
5. Subprocessors
Controller gives general written authorisation to use the subprocessors listed at sandplane.com/legal/subprocessors. Processor will bind each subprocessor by written data-protection obligations providing substantially equivalent protection and remains responsible for the subprocessor's performance to the extent required by law.
Processor will publish or notify additions or replacements at least 15 days before they begin processing Personal Data where reasonably possible. Controller may object during that period on reasonable data-protection grounds. The parties will work in good faith on an alternative; if none is reasonably available, Controller may terminate the affected Service without penalty for the unused prepaid period.
6. Data-subject requests
Taking into account the nature of processing, Processor will provide reasonable technical and organisational assistance for Controller to respond to requests under Chapter III GDPR. If Processor receives a request concerning Controller Personal Data, it will forward it to Controller without undue delay and will not respond substantively unless authorised or legally required.
7. Compliance assistance
Processor will reasonably assist Controller with security obligations, breach notifications, data-protection impact assessments, and prior consultations under Articles 32–36 GDPR, considering the processing and information available to Processor. Additional assistance outside standard Service functionality may be charged at agreed reasonable rates unless caused by Processor's breach.
8. Personal data breaches
Processor will notify Controller without undue delay after becoming aware of a Personal Data breach affecting Controller Personal Data. As information becomes available, notice will describe the nature of the breach, affected categories and approximate numbers, likely consequences, mitigation taken or proposed, and a contact point. Processor's notice is not an admission of fault. Controller is responsible for notifications it must make to authorities or individuals.
9. Deletion and return
During the Agreement, Controller may export data using available Service features. On termination and at Controller's choice, Processor will return or delete Personal Data. Unless an order form states otherwise, the export window is 30 days; production copies are then deleted or anonymised and backup copies expire through normal rotation, generally within 90 days. Processor may retain data required by law, isolated and used only for that requirement.
10. Information and audits
Processor will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR, including current security and subprocessor information. No more than once annually, unless a breach or authority requires otherwise, Controller may request a remote audit or independent report. An on-site audit requires 30 days' notice, must avoid disruption and exposure of other customers' data, and is at Controller's expense unless it identifies a material Processor breach. Auditors must be independent and bound by confidentiality.
11. International transfers
Controller's selected AWS application region is stated in Annex I. Where Processor transfers EEA Personal Data to a recipient in a country without an adequacy decision, the parties incorporate Module Two (controller-to-processor) of the European Commission Standard Contractual Clauses in Decision (EU) 2021/914. The docking clause applies; Option 2 and a 30-day update period apply to subprocessors; the optional independent dispute-resolution wording does not apply; Slovak law governs Clause 17; and Slovak courts are selected under Clause 18. Annexes I–III of this DPA complete the relevant SCC annexes.
For restricted transfers under UK GDPR, the applicable UK International Data Transfer Addendum is incorporated with the same commercial and processing details. Processor will provide information reasonably needed for a transfer-risk assessment and implement supplementary measures where appropriate.
12. Liability and conflict
Liability under this DPA is subject to the Agreement's lawful limitations. If this DPA conflicts with the Agreement about processing Personal Data, this DPA controls. The SCCs control over conflicting terms where they apply.
Annex I — Processing details
- Parties: Controller is the SandPlane customer identified in the account or order. Processor is Monoceros s. r. o., Doležalova 3424/15C, 821 04 Bratislava, Slovakia, privacy@sandplane.com.
- Subject matter and purpose: hosting and operating the SandPlane financial operations service, including import, storage, organisation, calculation, reporting, reconciliation, forecasting, support, security, and Customer-enabled integrations.
- Duration: the Agreement plus the deletion and backup periods in section 9.
- Nature and frequency: collection, recording, organisation, storage, retrieval, consultation, calculation, transmission, matching, restriction, export, and deletion; continuous or as initiated by users, integrations, and scheduled jobs.
- Data subjects: Customer users, personnel, customers, suppliers, counterparties, stakeholders, advisers, and other people represented in Customer Data.
- Data: identity and contact information; employment and organisation details; financial and transaction records; invoices, statements and attachments; account and integration identifiers; support and audit data. Special-category data is not intended unless expressly agreed.
- Region: AWS eu-central-1 (Frankfurt) or us-east-1 (Northern Virginia), selected by Controller, subject to the limited global processing disclosed in the Privacy Statement and subprocessor list.
- Competent authority: the supervisory authority determined under Clause 13 SCCs; for Monoceros's Slovak establishment, the Office for Personal Data Protection of the Slovak Republic.
Annex II — Technical and organisational measures
- TLS-required application-to-database proxy connections and HTTPS for public Service traffic;
- AWS encryption at rest for regional database and object storage, and application encryption for supported secrets;
- tenant-scoped access controls, PostgreSQL row-level security, and least-privilege service roles;
- authentication, session controls, audit logging, environment separation, and secrets management;
- private database placement, network security groups, rate limiting, security headers, and webhook verification;
- regional backups, recovery procedures, monitoring, incident handling, and controlled production access;
- data minimisation for analytics and error reporting, and deletion through documented retention processes; and
- periodic testing and review of security controls and dependency updates.
Annex III — Subprocessors
The current authorised list, locations, and purposes are published on the Subprocessors and Service Providers page, which is incorporated into this DPA.