Data Processing Agreement

Last updated: 2 August 2026

This Data Processing Agreement (the "DPA") forms part of the Terms of Service between Koode ("Squeezle", "Processor") and the business customer that uses Squeezle ("Customer", "Controller"). It applies where Squeezleprocesses personal data on the Customer's behalf in the course of providing the service, and it reflects Article 28 of the General Data Protection Regulation (GDPR).

In case of a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails. Capitalized terms not defined here have the meaning given in the Terms or the GDPR.

1. Roles of the parties

For personal data contained in Customer Data, the Customer is the controller and Squeezle is the processor. The Customer determines the purposes and means of the processing; Squeezle processes personal data only on the Customer's documented instructions, which include the Terms, this DPA, and the Customer's configuration and use of the service. If Squeezle is required by law to process personal data otherwise, it will inform the Customer first, unless the law prohibits it.

2. Subject matter, duration, nature, and purpose

  • Subject matter. Squeezle's processing of personal data to provide the SQL workbench service.
  • Duration. For the term of the Terms, plus the limited period afterwards described in the deletion and return section.
  • Nature and purpose. Connecting to Customer databases and running the Customer's queries; caching, exporting, and sharing results under the Customer's controls; keeping an audit log; providing optional AI assistance; and otherwise operating and supporting the service.

Full details are in Annex I below.

3. Processor obligations

Squeezle will:

  • Process personal data only on the Customer's documented instructions.
  • Ensure that people authorized to process personal data are bound by an appropriate duty of confidentiality.
  • Implement appropriate technical and organizational security measures as described in Article 32 and Annex II.
  • Respect the conditions for engaging sub-processors set out below.
  • Assist the Customer, taking into account the nature of the processing, in responding to requests from data subjects.
  • Assist the Customer in meeting its obligations on security, breach notification, data protection impact assessments, and prior consultation (Articles 32 to 36).
  • At the Customer's choice, delete or return personal data at the end of the service, and delete existing copies unless retention is required by law.
  • Make available information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, as described below.

4. Sub-processors

The Customer provides a general authorization for Squeezle to engage sub-processors to help provide the service. The current sub-processors are listed on our Sub-processors page, which forms Annex III.

  • Squeezle will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA.
  • Squeezle will give the Customer notice of any intended addition or replacement of a sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds.
  • Squeezle remains responsible to the Customer for the performance of its sub-processors' obligations.

5. Data-subject requests

Taking into account the nature of the processing, Squeezle will assist the Customer with appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, and objection). If Squeezle receives such a request directly from a data subject relating to the Customer's Customer Data, it will, where lawful, direct the request to the Customer rather than respond itself.

6. Security

Squeezle implements and maintains appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. A summary of these measures is in Annex II. Squeezle may update the measures over time, provided the level of protection is not reduced.

7. Personal data breach notification

Squeezle will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide the Customer with information reasonably available to help the Customer meet its own breach-notification obligations. Notice of a breach is not an acknowledgement of fault or liability.

8. International transfers

Where Squeezle transfers personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, it will do so under an appropriate transfer mechanism, including the European Commission's Standard Contractual Clauses [and the UK International Data Transfer Addendum], which are incorporated into this DPA by reference. [Confirm the module and the parties' roles under the SCCs.]

9. Audit rights

Squeezle will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To limit disruption, audits will take place on reasonable prior notice, no more than once per year (except where required by a supervisory authority or after a breach), during business hours, subject to confidentiality, and in a way that does not compromise the security or the data of other customers.Squeezle may satisfy audit requests by providing relevant certifications or reports where available.

10. Deletion and return

On termination of the service, Squeezle will, at the Customer's choice, delete or return the Customer's personal data, and delete existing copies, unless retention is required by law. The Customer can export its data for a limited period after termination.

Certain data is deleted automatically in the ordinary course: cached query results are removed on a short retention window (by default 72 hours). The append-only audit log is retained as a security and accountability record. Deletion of remaining personal data is carried out in line with Squeezle's retention practices described in the Privacy Policy.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, to the extent permitted by applicable law.

12. Annexes

Annex I: Details of processing

  • Categories of data subjects. The Customer's members and users of the service, and the individuals whose personal data appears in the databases the Customer connects (for example the Customer's own customers, employees, or contacts).
  • Categories of personal data. Account and identity data (name, email, passkey credentials); organization and role data; database connection metadata and encrypted secrets; the contents of queries, parameters, and results, which may include any category of personal data contained in the connected databases; usage and audit data (including IP address and user agent); and, where AI is used, the prompt and context sent to the AI provider.
  • Special categories of data. The Customer controls what data it connects and queries. Any special-category or otherwise sensitive data processed is determined by the Customer, which is responsible for having a lawful basis and appropriate safeguards. Squeezle provides sensitivity controls to help restrict access.
  • Frequency and duration. Continuous, for the duration of the service.
  • Purpose. Provision of the Squeezle service as described in the Terms.

Annex II: Technical and organizational measures

  • Encryption at rest of connection passwords, single sign-on secrets, and any AI provider key, using authenticated AES-256-GCM, with keys held outside the application database.
  • Encryption in transit over HTTPS/TLS.
  • Passwordless authentication using passkeys (WebAuthn) and optional single sign-on (OIDC or SAML).
  • Logical tenant isolation between organizations.
  • Role-based access controls, per-query row limits, and column-sensitivity rules that refuse queries touching data above a user's clearance.
  • A tamper-evident, append-only audit log of security-relevant events.
  • Short automatic retention for cached query results.
  • [Add operational measures: access management, logging and monitoring, backups, vulnerability management, personnel confidentiality, and incident response, as implemented.]

Annex III: Sub-processors

The list of authorized sub-processors is maintained on the Sub-processors page and forms part of this DPA.

13. Contact

To put a signed copy of this DPA in place, or for questions about it, contact legal@squeezle.app.