Data processing agreement.
How client data is processed under GDPR — scope, subprocessors, safeguards.
Last updated 2 August 2026 · GDPR
OGtraplord — Legal
Sheet L-03 · Data Processing Agreement
This Data Processing Agreement ("DPA") is the plain-words version of the commitments OGtraplord ("we", "us") makes under the EU General Data Protection Regulation and similar laws when we handle personal data on someone else's behalf. It forms part of our Terms of Service for client engagements.
OGtraplord is a one-person studio in Bangkok, and this page is written the way we actually work — no enterprise theatre. If your company needs a countersigned copy for its records, email gem.tra@ogtraplord.com and you'll have one within a few days.
1.What this covers
"Personal data" means anything that identifies a living person — a name, an email address, an IP address, an order. "Processing" means anything done with it: collecting, storing, reading, deleting.
This DPA applies when we process personal data for you — typically when we build, host, or maintain a website for a client and that website collects data from the client's own customers (contact forms, orders, sign-ups). For data you give us as a visitor or member of ogtraplord.com itself, the Privacy Policy is the governing document.
2.Controller & processor
- On ogtraplord.com — we decide what's collected and why, so we are the controller, and the Privacy Policy applies.
- On client projects — you decide what your site collects from your customers and why; you are the controller and we are your processor. We touch that data only to build and run your site.
3.What data is processed
For client engagements, the categories depend on what the site does, and are typically:
- End-customer contact data — names, emails, phone numbers from forms and enquiries.
- Order data — what was bought, when, and payment status (never full card numbers).
- Technical data — IP addresses and server logs kept by the hosting platform.
Data subjects are your customers and site visitors. Duration is the length of the engagement plus any agreed maintenance period.
4.Processing on instructions
As your processor we act only on your documented instructions — the project brief, the feature list, and what you ask for in writing. We will:
- Never use your customers' data for our own purposes, and never sell it to anyone.
- Keep it confidential — the only person with access is the studio owner.
- Collect the minimum the feature needs, by design.
- Tell you promptly if we believe an instruction would break the law.
5.Sub-processors
We use a short list of infrastructure providers, and each one gets only what its job requires:
- Hostinger — hosting, databases, and transactional email delivery.
- Google (Gemini API) — powers AI chat features, where a site includes one; receives the chat messages.
- SlipOK — verifies Thai PromptPay transfer slips, where a site takes PromptPay payments.
- NOWPayments — processes crypto checkout, where a site offers it.
We'll give you notice before adding or replacing a sub-processor on your project, and you can object on reasonable grounds. Each sub-processor is bound by its own data-protection terms at least as protective as these.
6.Security measures
- All traffic runs over TLS; passwords are stored only as bcrypt hashes.
- Admin access is limited to the studio owner — the least-access model of a one-person studio.
- Card numbers are never seen or stored; payments settle inside the customer's own banking or crypto app.
- Data minimalism throughout: what isn't collected can't leak.
- Hosting-level backups and hardening are provided by Hostinger's platform.
7.International transfers
We work from Thailand, and our providers run infrastructure in various regions — which may mean personal data is processed outside your country or the EEA. Where GDPR applies, transfers rely on the providers' standard contractual protections (SCC-based terms in their data-processing agreements). We don't move data anywhere it doesn't need to be.
8.Data subject requests
If one of your customers asks to see, correct, export, or delete their data, and the request reaches us instead of you, we'll forward it to you within a few days. Where the request is yours to answer, we'll do the technical work — looking up, exporting, or deleting the records — at no charge for anything reasonable.
9.Breach notification
If we become aware of a personal data breach affecting your project, we'll tell you without undue delay — plainly, with what we know: what happened, what data is affected, and what we're doing about it. We'll help with anything you need for your own notifications to authorities or customers.
10.Return & deletion
When an engagement ends, you choose: we hand the data back (a database export in a standard format), delete it, or both. Deletion happens within 30 days of the request, except records we're legally required to keep for bookkeeping — those are kept only for that purpose.
11.Audits & assurances
You're entitled to know how your data is handled. We'll answer written questions about our processing honestly and promptly, and share relevant provider documentation on request. For a studio of one, that written route replaces the on-site audit ritual — and if a regulator genuinely requires more, we'll cooperate.
12.Contact
DPA questions, signed copies, or processing instructions: gem.tra@ogtraplord.com — OGtraplord, Bangkok, Thailand. See also the Privacy Policy, Terms of Service, and the CCPA Notice.