Data Processing & Upload Policy - solid.garden

Preamble

This Data Processing Agreement ("DPA") and Data Upload Policy is entered into between DÉNES SZILÁRD e.v. ("Data Processor") and you or your entity ("Data Controller" or "you") and forms part of our Terms of Service and Privacy Policy. This DPA complies with Article 28 of the EU General Data Protection Regulation (GDPR).

1. Parties

1.1. Data Processor: DÉNES SZILÁRD e.v. (egyéni vállalkozó), Magyarország 8171 BALATONVILÁGOS, PONTY UTCA 4, Hungarian tax number: 59835165-1-34, Email: szilard@solid.garden. The Data Processor processes personal data on behalf of the Data Controller.

1.2. Data Controller: The customer or entity using solid.garden services, which determines the purposes and means of personal data processing. By accepting our Terms of Service, you confirm that you are a Data Controller with authority to enter into this DPA.

2. Scope of Processing

2.1. Categories of Data Subjects: Employees, representatives, and contractors of the Data Controller; users of the Data Controller's systems who interact with solid.garden; individuals whose contact information is provided to us by the Data Controller; individuals accessing the platform on behalf of the Data Controller.

2.2. Categories of Personal Data: Contact information (names, email addresses, phone numbers); professional information (job titles, company names, department information); account information (usernames, authentication tokens, access logs); communication data (support tickets, email correspondence, project discussions); billing information (invoice details, payment information processed via Stripe).

2.3. Special Category Data: We do not process special categories of personal data (health, biometric, political opinions, etc.) as defined in GDPR Article 9, unless explicitly required for a specific project with your prior written consent and separate safeguards. All subsurface geological data is treated as confidential business information, not as personal data, unless it contains personal identifiers.

3. Data Upload Procedures

3.1. Supported File Formats: We accept seismic data (SEG-Y, SEGD, SEG-2, SEG-3, Kingdom projects, Petrel files, OpendTect projects), well data (LAS, DLIS, LIS, well headers, deviation surveys, checkshot and VSP data), maps and spatial data (ESRI Shapefiles, GeoTIFF, MapInfo files, KML/KMZ), and documents (PDF, Word, Excel).

3.2. Upload Limits: Maximum file size is 5 GB per file (can be increased on request). Up to 5 simultaneous uploads per account. For large datasets, contact us for bulk transfer options (FTP, physical media).

3.3. Upload Security: All uploads are protected with TLS 1.3 encryption, HTTPS-only connections, certificate pinning to prevent man-in-the-middle attacks, SHA-256 hash verification, and immediate encryption before writing to disk. Files are virus-scanned, integrity-verified using cryptographic hashes, and access is restricted to your company account.

3.4. Data Storage: Primary storage is on Railway infrastructure (AES-256 encryption at rest, PostgreSQL database for metadata, encrypted object storage for large files). Automated backups are retained for 7 days with AES-256 encryption and off-site geographic redundancy.

4. Nature and Purpose of Processing

4.1. Processing Activities: Store and maintain account data; process user authentication and authorization; provide technical support services; generate reports and analytics; communicate with Data Controller personnel; manage billing and invoicing; maintain audit logs and security records.

4.2. Purpose of Processing: Delivering geoscience consulting services; providing platform access and functionality; managing customer relationships and support; processing payments and billing; maintaining platform security and integrity; complying with legal obligations; improving service quality.

4.3. Duration of Processing: Active projects (data retained while project is active); completed projects (subsurface data deleted after 30 days, personal data retained for 8 years per Hungarian tax law); prospective leads (contact data retained for 2 years from last interaction); backup data (automated backups retained for 7 days).

5. Data Processor Obligations

5.1. Confidentiality: Treat all personal data as confidential; ensure authorized personnel have signed confidentiality agreements; do not disclose personal data except as instructed by Controller; maintain confidentiality after termination of this DPA.

5.2. Data Security: Implement appropriate technical measures per GDPR Article 32; AES-256 encryption for data at rest; TLS 1.3 encryption for data in transit; multi-tenant architecture with company_id isolation; regular security assessments and updates.

5.3. Controller Instructions: Process personal data only per documented Controller instructions; notify Controller if instructions conflict with GDPR requirements; do not process data for Processor's own purposes; obtain prior approval for any subprocessor engagement.

5.4. Data Subject Rights: Assist Controller in responding to data subject requests; provide access logs for data subject access requests; support data deletion, correction, and portability requests; facilitate Controller's GDPR compliance obligations.

5.5. Breach Notification: Notify Controller without undue delay of any personal data breach; provide detailed information about the breach nature and impact; document all breaches and Controller notifications; cooperate with Controller in breach response and notification to supervisory authorities.

6. Data Isolation & Audit Trail

6.1. Multi-Tenant Architecture: Company-level data isolation ensures complete separation; database-level isolation with company_id filtering on every query (cannot be bypassed); file system isolation with company-specific directories; no data co-mingling; dedicated workspaces for each company.

6.2. Technical Implementation: Row-level security (RLS) enforced at database level; application-level checks verify company_id on every request; file storage paths include unique company identifiers; API endpoints return 403 errors for cross-company access attempts; audit logs record all data access with company context.

6.3. Access Logging: Every file upload and download; every project view and modification; user authentication events; data export and deletion requests; administrative access to data. Each log entry includes timestamp (UTC), user identity, action performed, data accessed or modified, IP address and geolocation, and outcome.

7. Subprocessors

7.1. Authorization: The Data Processor may engage third-party subprocessors to perform specific processing activities. All subprocessors are bound by GDPR-compliant data processing agreements and provide at least the same level of protection as required by this DPA.

7.2. Railway Corporation: Purpose is cloud hosting infrastructure and platform deployment. Location is United States (EU-U.S. Data Privacy Framework certified). Activities include server hosting, network infrastructure, and backup services. Railway Data Processing Addendum: https://railway.com/legal/dpa.

7.3. Stripe, Inc.: Purpose is payment processing and financial transactions. Location is United States (EU-U.S. Data Privacy Framework certified). Activities include credit card processing, billing, and invoicing. Stripe Data Processing Agreement: https://stripe.com/legal/dpa.

7.4. Requirements: Processor remains liable to Controller for subprocessor compliance. Controller may object to new subprocessors with 30 days' notice. We will notify Controller of any new subprocessor prior to engagement.

8. Data Subject Rights (GDPR Articles 15-22)

8.1. Assistance Commitment: The Data Processor agrees to assist the Data Controller in fulfilling its obligations to respond to data subject requests under GDPR, including: Right of Access (Article 15) – provide copies and confirmation of personal data processed; Right to Rectification (Article 16) – correct inaccurate data and complete incomplete data; Right to Erasure (Article 17) – delete personal data upon Controller instruction; Right to Restriction (Article 18) – limit processing activities as requested; Right to Portability (Article 20) – provide data in a structured, commonly used format; Right to Object (Article 21) – cease processing based on legitimate interest upon request.

8.2. Implementation: We will respond to Controller requests for assistance within 15 business days. Technical measures are in place to support data export and deletion. Access logs are maintained to verify data processing activities. We will not charge fees for reasonable data subject rights requests.

9. International Data Transfers

9.1. EU-U.S. Data Privacy Framework: Personal data from the European Economic Area may be transferred to the United States under the EU-U.S. Data Privacy Framework (DPF), as certified by the U.S. Department of Commerce. Our subprocessors Railway Corporation and Stripe, Inc. participate in the DPF. The European Commission has determined that the DPF provides adequate protection for personal data transferred from the EEA to the United States.

9.2. Standard Contractual Clauses (SCCs): For transfers not covered by the DPF, we have implemented the European Commission's Standard Contractual Clauses (SCCs) in accordance with GDPR Article 46. The SCCs provide appropriate safeguards for international data transfers.

9.3. UK Transfers: For transfers from the United Kingdom, we use the UK International Data Transfer Agreement (IDTA) or UK addendum to the SCCs, as appropriate under the UK GDPR.

10. Return or Deletion of Personal Data

10.1. Upon Termination: At the Controller's option, return or securely delete all personal data. Delete existing copies unless EU or Member State law requires retention. Certify deletion of personal data within 30 days of request. Maintain backup data according to our retention policy (7 days). Provide Controller with export of personal data in common format.

10.2. Legal Retention Requirements: We may retain personal data to the extent required by applicable law, including: Hungarian tax law (8-year record retention requirement); EU data protection regulations (audit trail preservation); anti-money laundering and financial regulations; pending litigation or investigation requirements.

10.3. Data Export Rights: You may export all your data at any time, including original files uploaded, deliverables created for your projects, account information and metadata, communication history, and audit logs of your activity. Export methods include client portal download, API access for programmatic export, or email request to szilard@solid.garden for assistance.

11. Audit Rights

11.1. Controller Audit Rights: The Data Controller may audit the Data Processor's compliance with this DPA, subject to: reasonable notice (minimum 30 days); audits limited to once per calendar year unless breach is suspected; audit scope must be reasonable and specific to DPA compliance; audit conducted during normal business hours; confidentiality obligations apply to all audit findings; Controller bears costs of audit unless breach is confirmed.

11.2. Alternative Evidence: As an alternative to on-site audits, we will provide: summary of security measures and certifications; third-party audit reports (e.g., SOC 2 Type II); compliance assessment questionnaires; documentation of subprocessor agreements; breach incident reports and remediation steps.

12. Liability

12.1. Processor Liability: The Data Processor is liable to the Controller for damages caused by processing that breaches this DPA or GDPR obligations, including: unauthorized disclosure of personal data; processing outside Controller's instructions; failure to implement appropriate security measures; non-compliance with subprocessor requirements.

12.2. Limitations: Processor not liable for acts outside its control; Controller responsible for lawfulness of processing; Processor not liable for following Controller instructions; force majeure events excluded from liability; liability limited to fees paid in preceding 12 months.

13. Term and Termination

13.1. Duration: This DPA commences on the Effective Date and continues while we process personal data on your behalf. Terminates automatically upon termination of the Terms of Service. Survives termination for the duration of any required data retention period.

13.2. Survival: Upon termination, the following provisions survive: confidentiality obligations (indefinitely); data security and deletion requirements; audit and record-keeping obligations; liability and indemnification provisions; general obligations regarding subprocessors.

14. Governing Law and Dispute Resolution

14.1. Governing Law: This DPA is governed by the laws of Hungary. Nothing in this DPA prevents the parties from agreeing to different governing law for the main service agreement. This DPA does not deprive EU consumers of mandatory protections under the law of their country of residence.

14.2. GDPR Supervisory Authority: For matters relating to GDPR compliance, either party may refer a dispute to the supervisory authority with primary jurisdiction: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1125 Budapest, Szilágyi Dezső square 3., Phone: +36 1 391-1400, Email: ugyfelszolgalat@naih.hu, Website: www.naih.hu.

15. Digital Non-Disclosure Agreement

As part of registration, all users must accept our Digital NDA, which creates binding confidentiality obligations. The complete text follows below.

This Digital Non-Disclosure Agreement ("Agreement") is entered into as of the date of digital acceptance by the user ("Effective Date") between DÉNES SZILÁRD e.v. ("Disclosing Party" and "Receiving Party") and the user or entity registering for solid.garden services ("Counterparty").

15.1. Definition of Confidential Information. "Confidential Information" means any non-public information, technical data, or know-how, including but not limited to: subsurface geological and geophysical data (seismic, well logs, maps); project interpretations, reports, and deliverables; business information, strategies, and financial data; software, algorithms, methodologies, and technical processes; client lists, pricing, and contract terms; any information marked as "confidential" or that a reasonable person would understand to be confidential.

15.2. Obligations of Receiving Party. The Receiving Party agrees to: maintain the confidentiality of all Confidential Information; use Confidential Information only for the purpose of receiving or providing services; restrict disclosure to employees or contractors with a need to know who have signed confidentiality agreements; protect Confidential Information with the same degree of care used to protect its own confidential information (but no less than reasonable care); not copy, reproduce, or distribute Confidential Information except as necessary for the services.

15.3. No Third-Party Sharing. The Receiving Party shall not disclose, share, or transfer Confidential Information to any third party without the prior written consent of the Disclosing Party, except as required by law or to subprocessors who have agreed to confidentiality terms no less protective than those in this Agreement.

15.4. No AI Training. The Receiving Party shall not use any Confidential Information to train, develop, or improve machine learning models, artificial intelligence systems, or automated decision-making technologies without the separate, explicit written consent of the Disclosing Party.

15.5. Data Security. The Receiving Party agrees to implement and maintain appropriate technical and organizational measures to protect Confidential Information, including: AES-256 encryption for data at rest; TLS 1.3 encryption for data in transit; access controls and authentication mechanisms; regular security assessments and updates; audit logging of all access to Confidential Information.

15.6. Exclusions from Confidential Information. Confidential Information does not include information that: is or becomes public knowledge through no fault of the Receiving Party; was rightfully in the Receiving Party's possession prior to disclosure; is independently developed by the Receiving Party without use of Confidential Information; is rightfully obtained from a third party without confidentiality restrictions; is required to be disclosed by law or court order (with prior notice to the Disclosing Party where legally permitted).

15.7. Return or Destruction of Confidential Information. Upon termination of services or at the Disclosing Party's request, the Receiving Party shall: return all Confidential Information in its possession, or securely delete or destroy all Confidential Information (including copies); provide written certification of destruction within 30 days.

15.8. Term. This Agreement commences on the Effective Date and continues during the term of service provision. The obligations of confidentiality shall survive the termination or expiration of this Agreement for a period of 5 years, or indefinitely for trade secrets.

15.9. Remedies. The parties agree that monetary damages may not be a sufficient remedy for unauthorized disclosure of Confidential Information. The Disclosing Party shall be entitled to seek equitable relief, including injunction and specific performance, as a remedy for any breach or threatened breach of this Agreement.

15.10. Governing Law. This Agreement is governed by the laws of Hungary. Any disputes arising under this Agreement shall be resolved in the courts of Hungary.

BY ACCEPTING THIS DIGITAL NDA, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY ITS TERMS.

16. Contact Information

For questions about this Data Processing Agreement or our data handling practices, please contact:

DÉNES SZILÁRD e.v.
Magyarország 8171 BALATONVILÁGOS, PONTY UTCA 4
Hungarian tax number: 59835165-1-34
Email: szilard@solid.garden

BY ACCEPTING THIS DATA PROCESSING AGREEMENT, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY ITS TERMS.