Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between LaunchViz (“we”, “us”, the “processor”), which operates the LaunchViz Pano virtual tour builder and hosting service at pano.launchviz.com, and the company using the service (“you”, the “controller”). It applies whenever we process personal data on your behalf under the GDPR.
1. Roles and scope
You are the data controller for any personal data contained in the panoramas, media, and tour content you upload, and for the technical access logs of visitors who view your published tours. We process that data only to provide the service to you.
2. Instructions
We process personal data only on your documented instructions, which are, in the first place, these terms and your configuration of the service, unless EU or member-state law requires otherwise, in which case we inform you before processing.
3. Confidentiality
Anyone we authorise to process personal data is bound by a contractual or statutory duty of confidentiality.
4. Security
- Data is hosted on servers in the European Union.
- All traffic is encrypted in transit (TLS); account passwords are stored as bcrypt hashes.
- Access to production systems is limited to authorised personnel and protected accounts.
- Automated backups are kept on separate storage.
5. Subprocessors
You authorise the following subprocessors:
- Hetzner Online GmbH (Germany and Finland, EU) - hosting and object storage.
- Amazon Web Services SES (eu-west-1) - transactional email delivery.
- Cloudflare, Inc. - CDN and proxy.
When online billing launches, Stripe, Inc. will be added as a payment subprocessor. Subprocessors outside the EU are engaged under appropriate safeguards (Standard Contractual Clauses or an adequacy decision such as the EU-US Data Privacy Framework). We give notice before adding or replacing a subprocessor; you may object on reasonable data-protection grounds.
6. Assistance
Taking into account the nature of the processing, we assist you in responding to data-subject requests (access, rectification, erasure, objection) and in meeting your security, breach, and impact-assessment obligations.
7. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably needed for your own notification obligations.
8. Deletion and return
On termination of your account we delete the personal data we process on your behalf within 30 days, unless EU or member-state law requires longer storage. Before termination you can export or download your content from the service.
9. Audit
We make available the information reasonably necessary to demonstrate compliance with this DPA and allow audits you reasonably request, at your cost and with reasonable notice.
10. Duration and contact
This DPA applies for as long as we process personal data on your behalf. Questions: [email protected].
Last updated: 14 July 2026