Data Processing Agreement
Last updated: 23 August 2026
The short version
If you use Snugport to keep track of your clients, your leads or anyone else, then some of the information in your panel is personal data about other people. Under data protection law you are the one responsible for it, and we are only handling it on your behalf. That relationship has to be put in writing, and this page is that contract.
It only matters if you subscribe to Snugport Sync. The free panel never sends anything to us, so there is nothing for us to process and nothing here applies.
1. The parties
This agreement is between you — the account holder, referred to here as the controller — and:
- Processor
- Fritz Reif Garcia
- Tax identification number
- 03152180F
- Registered address
- Juan Ramón Jiménez 63, 46026 Valencia, Spain
- Contact for data protection matters
- support@snugport.app
It is entered into under Article 28(3) of the GDPR (Regulation (EU) 2016/679) and forms part of the Terms of Service. You accept it when you create a Snugport account. Where this page and the Terms of Service disagree about the processing of personal data, this page prevails.
This agreement does not cover the personal data we hold about you — your email address, your billing records, your subscription. For that we are the controller in our own right, and what we do with it is described in the Privacy Policy.
2. What is being processed
- Subject matter
- Storing a copy of your Snugport panel on our servers and making it available to your own devices.
- Duration
- For as long as your account exists. It ends when you delete your account or when this agreement is terminated.
- Nature and purpose
- Storage, transmission and retrieval. Nothing else: we do not analyse, enrich, combine or otherwise use the contents of your panel.
- Types of personal data
- Whatever you choose to write into your panel. In practice that typically means names, contact details, notes, project descriptions, rates and amounts. You decide what goes in, and the panel does not require any of it.
- Categories of data subjects
- The people you record in your panel — typically your clients, prospective clients and contacts.
Snugport is not designed for special categories of personal data (health, beliefs, biometrics, and the rest of Article 9), nor for data about criminal convictions. Please do not put them in.
3. Our instructions come from you
We process this data only on your documented instructions. Using the product is the instruction: when your panel syncs, you are telling us to store it and give it back to you. Beyond that we do nothing with it — including no transfer to another country except as described in section 6.
If we ever had to process it for some other reason because European or Spanish law required us to, we would tell you first, unless that same law forbids us from telling you. And if we think one of your instructions breaks data protection law, we will say so.
4. Confidentiality
Access to your data is limited to the people who need it to run the service. Today that is one person: Fritz Reif Garcia, who operates Snugport. Anyone else given access in future will be bound by a duty of confidentiality before they get it.
5. Security — and what we do not claim
We take appropriate technical and organisational measures under Article 32 of the GDPR. Concretely, and without dressing it up:
- Everything travels over encrypted connections (TLS).
- The database is encrypted at rest by our hosting provider.
- Access is restricted at database level by row-level security, so an account can only ever read and write its own copy.
- Passwords are stored hashed and are never visible to us.
- Writing to the cloud copy requires an active subscription; reading and deleting it never does, so your data is never held hostage.
What we do not claim: your panel is not end-to-end encrypted. It is stored as structured data that we could technically read, in the same way that any provider running your database could. We do not read it, and nothing in the product does anything with it beyond storing and returning it — but you should choose what you put in knowing that, and this page would be worth very little if it said otherwise.
6. Who else is involved
You give us general authorisation to use the following sub-processors, each of which is bound by equivalent data protection obligations:
- Supabase — database and authentication. Stores the cloud copy of your panel. Hosted in the London region (eu-west-2), United Kingdom.
- Cloudflare — hosting and delivery of the website and the panel, and routing of our email addresses.
- Stripe Payments Europe, Ltd. — payments, invoicing and tax calculation. Handles your billing data, not your panel.
- Resend — delivery of transactional email such as account confirmation and password recovery.
Payment providers. For part of what they do with billing data — detecting fraud, meeting anti-money-laundering and other legal obligations, and keeping their own records — Stripe and PayPal decide by themselves why and how, and there they act as independent controllers under their own privacy policies, not as our sub-processors. If a subscriber pays with PayPal, PayPal handles that payment data as an independent controller. Neither of them has access to your panel.
If we add or replace a sub-processor, we will tell subscribers by email at least 30 days in advance. If you object, you may cancel your subscription before the change takes effect and we will refund the unused part of the period you have paid for.
International transfers. Because our Supabase project is in the United Kingdom, your cloud copy is stored outside the European Economic Area. The United Kingdom is covered by an adequacy decision of the European Commission, renewed in December 2025 and running until 27 December 2031, which means the transfer is permitted without further conditions. Where any other sub-processor processes data outside the EEA without such a decision, the transfer relies on the safeguards recognised under the GDPR, such as the European Commission's standard contractual clauses.
7. Helping you answer your own obligations
If one of the people in your panel exercises their rights — access, rectification, erasure, portability, objection — that request is yours to answer, because the data is yours and we do not know who these people are. In practice you can handle all of it yourself from inside the panel: the records are editable and deletable, and the whole panel exports to JSON in one click.
Where something genuinely cannot be done from the panel, write to us and we will help, taking into account the nature of the processing and the information available to us. We will also give you reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, if you ever need one.
8. If something goes wrong
If we become aware of a personal data breach affecting your data, we will notify you without undue delay by email to the address on your account, so that you can meet your own 72-hour obligation under Article 33. We will tell you what we know: what happened, which categories of data are involved, the likely consequences, and what we are doing about it — and we will follow up as we learn more rather than wait until we have the full picture.
9. Showing that we do what we say
We will make available the information reasonably needed to demonstrate compliance with Article 28, and allow for audits, including inspections, conducted by you or an auditor you appoint. Given the size of this service, in the ordinary case that means answering your questions in writing and pointing you at what we publish here. An on-site audit is available where a supervisory authority requires it or where there is a specific reason for one, at your cost and arranged with reasonable notice so it does not disrupt the service for other subscribers.
10. Deletion and return
You can export your panel at any time as a JSON file — that is the return of the data, and it needs no request to us.
When your account is deleted, the cloud copy is deleted with it, without delay — and so is its version history. You can also erase the cloud copy on its own from Settings → Sync and keep the account; that erases the history too. The version history is a feature of the service, not a backup of ours: it is described in the privacy policy, it prunes itself, and you can delete it at any time by the two routes just named. Backups made for disaster recovery are overwritten in the ordinary course and are not used for any other purpose. We keep billing records for the period tax and commercial law requires, but those are our records about you and contain nothing from your panel.
11. Liability and duration
This agreement takes effect when you create your account and lasts as long as we process personal data on your behalf. Terminating your subscription or deleting your account ends it. The liability provisions of the Terms of Service apply here too, save that nothing in them limits either party's liability under Article 82 of the GDPR towards a data subject or a supervisory authority.
12. Changes
If we change this agreement in a way that materially affects you, we will notify subscribers by email at least 30 days in advance, on the same terms as a change to the Terms of Service. The date at the top of this page always says when it last changed.
13. Contact
Anything about this agreement, or about data protection generally: support@snugport.app.