Data Processing Agreement

Chocolate Cloud ApS (CVR 35865756) · Klostergade 56, 8000 Aarhus C, Denmark · Last updated: 8 October 2026

This Data Processing Agreement (the "Clauses") forms part of the Terms of Service for IronShard (the "Main Agreement"). It applies automatically when you accept the Terms and store personal data as Content. No signature is needed.

1. The parties

1.1 The Clauses are agreed between the customer who accepts the Terms (the "Data Controller") and Chocolate Cloud ApS, CVR 35865756, Klostergade 56, 8000 Aarhus C, Denmark (the "Data Processor"). "IronShard" is the name of the Service, not a legal entity. The agreement is with Chocolate Cloud ApS. The Clauses are made to meet the requirements of the GDPR and to protect the rights of data subjects.

1.2 Where you act as a processor for your own customers, you are a processor and we are a sub-processor, and these Clauses apply between us on that basis. You confirm that you are authorised by your own controller to engage us.

2. Preamble

2.1 The Clauses set out the rights and obligations of the Data Controller and the Data Processor when the Data Processor processes personal data on behalf of the Data Controller.

2.2 The Clauses are designed to ensure compliance with Article 28(3) of Regulation (EU) 2016/679 (the "GDPR").

2.3 Under the Main Agreement the Data Processor provides IronShard, an S3-compatible object storage service (the "Service"), and processes personal data on behalf of the Data Controller in accordance with the Clauses. The Service receives the data uploaded by the Data Controller at a gateway, encrypts it with AES-256, divides it into fragments, encodes the fragments by erasure coding, and distributes the coded fragments between independent storage providers selected by the Data Processor.

2.4 The Clauses take priority over any similar provisions in other agreements between the parties, including the Terms, to the extent they concern the processing of personal data.

2.5 Three appendices form an integral part of the Clauses. Appendix A describes the processing. Appendix B lists the authorised sub-processors and the conditions for using them. Appendix C contains the instructions, the security measures, and the audit procedures.

2.6 The Clauses are retained in writing, including electronically, by both parties.

2.7 The Clauses do not exempt the Data Processor from obligations under the GDPR or other legislation.

3. The rights and obligations of the Data Controller

3.1 The Data Controller is responsible for ensuring that the processing takes place in compliance with the GDPR (see Article 24), the applicable EU or Member State data protection provisions, and the Clauses.

3.2 The Data Controller has the right and obligation to decide the purposes and means of the processing of personal data.

3.3 The Data Controller is responsible, among other things, for ensuring that the processing it instructs the Data Processor to perform has a legal basis.

4. The Data Processor acts according to instructions

4.1 The Data Processor processes personal data only on documented instructions from the Data Controller, unless required to do so by Union or Member State law. The instructions are set out in Appendices A and C. The Data Controller gives further instructions through its use of the Service (including API calls and configuration) and in writing to [email protected]. Instructions must be documented and kept in writing, including electronically, with the Clauses.

4.2 The Data Processor will inform the Data Controller without undue delay if, in its opinion, an instruction contravenes the GDPR or applicable EU or Member State data protection provisions.

4.3 The Data Controller instructs the Data Processor to carry out the processing that is necessary to comply with law that applies to the Data Processor, to enforce the Acceptable Use Policy, and to handle notices under the Notice and Action procedure. Where the law does not prohibit it, the Data Processor will tell the Data Controller before processing for these purposes beyond what is needed to preserve evidence and meet the legal requirement.

5. Confidentiality

5.1 The Data Processor grants access to personal data processed on behalf of the Data Controller only to persons under its authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and only on a need-to-know basis. The list of persons with access is reviewed periodically, and access is withdrawn when no longer necessary.

5.2 At the request of the Data Controller, the Data Processor will demonstrate that the persons concerned are subject to this confidentiality.

6. Security of processing

6.1 Article 32 GDPR requires the Data Controller and the Data Processor, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk to the rights and freedoms of natural persons, to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

6.2 The Data Controller evaluates the risks to the rights and freedoms of natural persons inherent in the processing and implements measures to mitigate those risks. The Data Controller provides the Data Processor with the information necessary for the Data Processor to identify and evaluate such risks.

6.3 The Data Processor also evaluates those risks independently and implements measures to mitigate them. The minimum measures are set out in Appendix C.2.

6.4 The Data Processor assists the Data Controller in complying with Article 32 by providing information about the technical and organisational measures already implemented, and any other information the Data Controller needs.

6.5 If the Data Controller considers that further measures are needed, it specifies them in writing to the Data Processor. Further measures take effect only when the Data Processor agrees to them in writing.

7. Use of sub-processors

7.1 The Data Processor meets the requirements of Article 28(2) and (4) GDPR when it engages another processor (a sub-processor).

7.2 The Data Controller gives the Data Processor general authorisation to engage sub-processors. The sub-processors authorised at the date of these Clauses are listed in Appendix B. The Data Processor informs the Data Controller of any intended addition or replacement at least 30 days in advance, by updating https://ironshard.ai/legal/sub-processors and by email to anyone who has subscribed to changes at [email protected]. Where a sub-processor's own change is made on shorter notice to the Data Processor than 30 days, the Data Processor gives as much notice as it receives, and in any case as soon as reasonably possible. The Data Controller may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Data Controller's remedy is to stop using the Service and delete its Content before the change takes effect.

7.3 Where the Data Processor engages a sub-processor, it imposes on that sub-processor, by contract or other legal act, the same data protection obligations as in the Clauses, in particular sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of the Clauses and the GDPR.

7.4 At the Data Controller's request, the Data Processor provides a copy of the data protection terms of a sub-processor agreement. Commercial terms need not be disclosed.

7.5 If a sub-processor does not fulfil its data protection obligations, the Data Processor remains liable to the Data Controller for the sub-processor's obligations. This does not affect the rights of data subjects under the GDPR, in particular Articles 79 and 82.

8. Transfer of data to third countries or international organisations

8.1 The Data Processor transfers personal data to third countries or international organisations only on documented instructions from the Data Controller, and in compliance with Chapter V GDPR.

8.2 The Data Controller instructs the Data Processor to carry out the transfers described in Appendix C.6. Without further documented instructions, the Data Processor does not transfer personal data to a third country except as described there.

8.3 Where EU or Member State law requires a transfer the Data Processor has not been instructed to carry out, the Data Processor informs the Data Controller of that legal requirement before the processing, unless the law prohibits it on important grounds of public interest.

8.4 The Clauses are not standard data protection clauses under Article 46(2)(c) or (d) GDPR and cannot be relied on as a transfer tool under Chapter V.

9. Assistance to the Data Controller

9.1 Taking into account the nature of the processing, the Data Processor assists the Data Controller, as far as possible and by appropriate technical and organisational measures, in responding to requests to exercise data subjects' rights under Chapter III GDPR:

a. the right to be informed
b. the right of access
c. the right to rectification
d. the right to erasure
e. the right to restriction of processing
f. notification of rectification, erasure or restriction
g. the right to data portability
h. the right to object
i. the right not to be subject to a decision based solely on automated processing, including profiling

9.2 The Data Processor also assists the Data Controller, taking into account the nature of the processing and the information available to it, in complying with:

a. the obligation to notify a personal data breach to the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it (in Denmark, Datatilsynet), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons;
b. the obligation to communicate a personal data breach to the data subject without undue delay where it is likely to result in a high risk;
c. the obligation to carry out a data protection impact assessment;
d. the obligation to consult the supervisory authority before processing where an impact assessment indicates a high risk.

9.3 The scope of this assistance is set out in Appendix C.3.

10. Notification of personal data breach

10.1 The Data Processor notifies the Data Controller without undue delay after becoming aware of a personal data breach affecting the Data Controller's Content.

10.2 Where possible, the notification takes place within 48 hours after the Data Processor becomes aware of the breach, so that the Data Controller can meet its obligation under Article 33 GDPR.

10.3 The Data Processor assists the Data Controller in obtaining the information that Article 33(3) GDPR requires in the Data Controller's notification:

a. the nature of the personal data, including where possible the categories and approximate number of data subjects and records concerned;
b. the likely consequences of the breach;
c. the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.

10.4 Appendix C.3 sets out the elements the Data Processor provides.

11. Erasure and return of data

11.1 On termination of the processing services, the Data Processor deletes all personal data processed on behalf of the Data Controller and confirms the deletion on request, unless Union or Member State law requires storage of the personal data.

11.2 Deletion takes place as described in Appendix C.4. The Data Controller is responsible for retrieving its Content through the Service before termination. The Terms may provide that no retrieval period is available on a given plan.

12. Audit and inspection

12.1 The Data Processor makes available to the Data Controller the information necessary to demonstrate compliance with Article 28 and the Clauses, and allows for and contributes to audits, including inspections, conducted by the Data Controller or another auditor mandated by the Data Controller, as set out in Appendix C.7 and C.8.

12.2 The Data Processor gives supervisory authorities that have access to the Data Controller's or the Data Processor's facilities under applicable law access to the Data Processor's physical facilities on presentation of appropriate identification.

13. Other terms

13.1 Liability under the Clauses is governed by the Terms, including clause 12, to the extent permitted by law. The Clauses do not limit the rights of data subjects.

13.2 Any other terms must not contradict, directly or indirectly, the Clauses or prejudice the fundamental rights or freedoms of data subjects and the protection afforded by the GDPR.

13.3 Anonymous and unidentified use. The Service can be used on the free tier without identifying yourself. The Data Processor cannot read stored Content at rest and does not know which data subjects, if any, appear in it. Where the Data Processor cannot identify a data subject, it is not required to collect more information just to enable identification (GDPR Article 11). The Data Controller deals with data subjects' requests itself and uses the Service's own functions (listing, retrieval, deletion) to act on them. The Data Processor's assistance under clause 9 is limited accordingly.

14. Commencement and termination

14.1 The Clauses take effect when the Data Controller accepts the Terms or first stores personal data in the Service, whichever is earlier.

14.2 Both parties may require the Clauses to be renegotiated if changes in law or the inexpediency of the Clauses give rise to it. The Data Processor may update the Clauses to reflect changes in law or in the Service, with notice published at https://ironshard.ai/legal/dpa. Changes that reduce the protection of personal data take effect only if the Data Controller continues to use the Service after 30 days' notice.

14.3 The Clauses apply for as long as the Data Processor processes personal data on behalf of the Data Controller. They cannot be terminated during that time unless other clauses governing the processing have been agreed.

14.4 If the processing ends, and the personal data has been deleted or returned under clause 11 and Appendix C.4, either party may terminate the Clauses by written notice.


Appendix A: Information about the processing

A.1 Purpose. To provide the Service, including S3-compatible object storage, to the Data Controller.

A.2 Nature of the processing. Receipt at a gateway, encryption, division into fragments, erasure coding, distribution of coded fragments to storage providers, storage, retrieval, reconstruction, transmission to the Data Controller, and erasure.

A.3 Types of personal data. The personal data in the Content the Data Controller stores in the Service. The Service is an object store, so the Data Controller decides what is stored. The processing may include any type of personal data, including special categories of personal data. Bucket names, object names and object metadata are processed too, to the extent they contain personal data.

Network identifiers such as IP addresses of the Data Controller's systems, Credential identifiers and request logs are not Content. The Data Processor processes them as controller, as described in the Privacy Policy.

A.4 Categories of data subjects. Whoever appears in the Content. This depends on the Data Controller's use of the Service.

A.5 Duration. For the duration of the Main Agreement and until deletion under Appendix C.4.


Appendix B: Authorised sub-processors

B.1 Approved sub-processors

On commencement of the Clauses, the Data Controller authorises the following sub-processors for the processing described.

NameAddressDescription of processingLocation
Fly.io, Inc.United StatesGateways. Receives Content in unencrypted form, performs encryption and encoding, handles requests.Amsterdam (Netherlands), Frankfurt (Germany), Stockholm (Sweden), London (United Kingdom), Toronto (Canada), Ashburn, Chicago and Los Angeles (United States)
Google Cloud EMEA LimitedVelasco, Clanwilliam Place, Dublin 2, IrelandControl plane, encryption key storage, logging and monitoring. Receives bucket and object identifiers. Also acts as a storage provider for coded fragments.Frankfurt, Germany
Cloudflare, Inc.101 Townsend Street, San Francisco, CA 94107, United StatesWebsite and console hosting, DNS. Also acts as a storage provider for coded fragments. Does not receive Content in unencrypted form.Global network
Functional Software, Inc. (Sentry)45 Fremont Street, 8th Floor, San Francisco, CA 94105, United StatesError monitoring for gateways and web applications. May receive bucket or object identifiers that appear in error data.Frankfurt, Germany (EU data region). Access from the United States is possible.
InfluxData Inc.548 Market St, PMB 77953, San Francisco, CA 94104, United StatesOperational metrics for fragment upload and download.Frankfurt, Germany (AWS eu-central-1)

The Data Controller authorises the use of these sub-processors for the processing described for each. The Data Processor does not, without the Data Controller's authorisation under clause 7, engage a sub-processor for a different processing than the one described.

Mailgun (service emails, EU region) is used only for data for which the Data Processor is controller, such as account contact details, and is listed on the sub-processors page.

B.2 Storage providers

Coded fragments are distributed across independent storage providers selected by the Data Processor. The Service is designed so that no storage provider receives enough coded fragments of the same object to reconstruct it. The Data Processor does not disclose to any storage provider the identity of the other providers or the keys needed to reconstruct data. In the Data Processor's assessment, supported by external legal advice, coded fragments held by an individual storage provider are not personal data for that provider, because identification of data subjects from them is practically impossible. On this basis the Data Processor does not treat storage providers as sub-processors. This is an assessment, not a warranty. The Data Controller remains responsible for its own assessment of the Service and is invited to commission its own legal advice. The provider groups are published at https://ironshard.ai/legal/sub-processors and a named list is available on request.

B.3 Prior notice

See clause 7.2.


Appendix C: Instructions on the use of personal data

C.1 Subject of the instruction. To provide the Service to the Data Controller, as described in the Main Agreement and Appendix A.

C.2 Security of processing.

The level of security takes into account that the processing may involve a large volume of personal data, including special categories under Article 9 GDPR, and a high level of security is therefore appropriate. The Data Processor decides on the technical and organisational measures needed to create that level, and implements at least these:

  1. Encryption. Content is encrypted with AES-256 at the gateway before it leaves the gateway. The encryption keys are held by the Data Processor, separately from the fragments, in Frankfurt (Google Cloud).
  2. Division. The encrypted data is divided into a minimum of 3 fragments.
  3. Erasure coding. The fragments are encoded by erasure coding (random linear network coding, Reed-Solomon codes with a Vandermonde matrix structure, or similar). Each coded fragment contains elements of all the original fragments. Recovering the data requires a sufficient number of coded fragments of the same object.
  4. Distribution. Coded fragments are distributed so that no single storage provider holds a sufficient number of coded fragments of an object to reconstruct it.
  5. Access control and authentication. Access to the Service requires Credentials. Access by the Data Processor's staff is limited to what their role needs.
  6. Protection in transit. Data is protected with TLS 1.2 or higher between clients and gateways, and between gateways and storage providers.
  7. Logging. Requests are logged. Logs are kept for the periods in the Privacy Policy.
  8. Resilience. Coded fragments are stored with redundancy, so that Content remains retrievable if some storage providers become unavailable.
  9. Testing. The security measures are reviewed when the architecture changes and at least once a year.

Gateways process Content in unencrypted form in memory while performing steps 1 to 3. Content is not stored unencrypted.

C.3 Assistance to the Data Controller.

The Data Processor assists as far as possible under clauses 9 and 10. Because Content is encrypted at rest and the Data Processor does not index it, the Data Controller finds and acts on personal data in its Content itself, using the Service's functions. The Data Processor assists by providing information on the technical and organisational measures, and the architecture described in Appendix B.2, and by answering reasonable questions. In a breach, the Data Processor provides what it knows about the nature of the breach, the affected buckets, and the measures taken.

C.4 Storage period and erasure.

Personal data is stored for the duration of the Main Agreement, in accordance with the Data Controller's instructions. The Data Controller deletes objects through the Service. When an object is deleted, the Data Processor deletes the coded fragments from the storage providers within 30 days. On termination of the Main Agreement, the Data Processor deletes the Data Controller's remaining Content and the keys within 30 days, subject to clause 11.1. Fragments cannot be reconstructed after the keys are deleted. Inactive buckets are handled as described in the Fair Use Policy.

C.5 Processing location.

Processing cannot take place at other locations than the following without the Data Controller's authorisation under clause 7:

  • Frankfurt, Germany: control plane, encryption keys, logs, metrics.
  • Gateway regions: Amsterdam (Netherlands), Frankfurt (Germany), Stockholm (Sweden), London (United Kingdom), Toronto (Canada), Ashburn, Chicago and Los Angeles (United States).
  • Storage providers: the locations the Data Controller selects through Region Select, as published at https://ironshard.ai/legal/sub-processors. Region Select is available on every plan, including the free tier, and coded fragments are stored only with providers in the selected locations.
  • Error monitoring: stored in Frankfurt, Germany (Sentry EU region). Sentry's staff may access the data from the United States.

C.6 Transfers to third countries.

The Data Controller instructs the Data Processor to transfer personal data to the gateway regions, sub-processors and storage locations listed above, including those in the United States, the United Kingdom and Canada. The legal basis under Chapter V GDPR is:

  • the adequacy decision for the United Kingdom;
  • the adequacy decision for Canada (commercial organisations subject to PIPEDA), where applicable;
  • the EU–US Data Privacy Framework where the recipient is certified under it;
  • otherwise the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with a transfer impact assessment.

If the Data Controller does not give instructions on transfers, the Data Processor may not transfer personal data to a third country within the framework of the Clauses.

C.7 Audits of the Data Processor.

The Data Processor makes available the information necessary to demonstrate compliance, including its trust center, which sets out the security measures and the certifications of its infrastructure suppliers, and answers to reasonable security questionnaires. The Data Controller may carry out an audit, including an inspection, no more than once a year, on at least 30 days' written notice, during business hours, at its own expense, and subject to confidentiality. Audits are conducted remotely where possible. They do not extend to the systems or facilities of third parties, or to the data of other customers.

C.8 Audits of sub-processors.

The Data Processor relies on its sub-processors' independent certifications and audit reports (for example ISO 27001 or SOC 2). Links to each sub-processor's published security and compliance information are on https://ironshard.ai/legal/sub-processors and in the Data Processor's trust center. It reviews them where they are made available and provides them to the Data Controller on request, subject to the sub-processors' confidentiality terms. Physical inspection of sub-processors' data centres by the Data Controller is not available.