asyncmate Data Processing Agreement
Last updated: August 3, 2026
This Data Processing Agreement ("DPA") forms part of the asyncmate Terms of Service (the "Terms") between Code7 d.o.o., a limited liability company registered in Croatia (OIB 76594489608, MB 06051537, registered address Zagorska ulica 105, 42220 Novi Marof, Croatia) ("asyncmate") and the Customer. It applies whenever asyncmate processes personal data contained in Customer Data on the Customer's behalf and the GDPR, or an equivalent data protection law, applies to that processing.
No signature is required: this DPA is accepted together with the Terms when you install the asyncmate Slack app or otherwise use the Service. If your procurement process needs a countersigned copy, email support@asyncmate.com and we will provide one.
Capitalized terms not defined here ("Customer Data", "Workspace", "Service", "Authorized User") have the meanings given in the Terms. "GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in Article 4 GDPR.
1. Roles and scope
1.1 For personal data in Customer Data, the Customer is the controller and asyncmate is the processor. If the Customer is itself a processor for another controller, asyncmate acts as its sub-processor, and the Customer warrants that its instructions to asyncmate are consistent with the controller's instructions.
1.2 This DPA does not cover the data for which asyncmate is an independent controller (account, billing, security, and website data). That processing is described in the Privacy Policy.
1.3 In case of conflict between this DPA and the Terms, this DPA prevails for personal-data processing matters.
2. Details of the processing
- Subject matter: provision of the asyncmate Service to the Customer under the Terms.
- Duration: the term of the Terms, plus the deletion window in Section 10.
- Nature and purpose: hosting and storing Customer Data; scheduling and delivering check-ins, reminders, polls, and surveys into the Customer's Slack workspace; collecting responses and votes; compiling digests, including optional AI digests; hours and out-of-office logging; exports; and support.
- Categories of data subjects: members of the Customer's connected Slack workspace (employees, contractors, and guests) and the Customer's account owners and administrators.
- Categories of personal data: Slack member profile data (Slack user ID, names, profile image URL, timezone, role flags); check-in and survey answers, including free text; poll and survey votes; logged hours and out-of-office periods; blocker records and digest snapshots derived from answers; and related timestamps and participation records.
- Special categories: none intended. The Customer must not configure the Service to solicit special categories of personal data (Terms, Section 7). Free-text answers may incidentally contain sensitive information; asyncmate processes such content under the same safeguards as all other Customer Data and makes no separate use of it.
3. Instructions
asyncmate processes Customer Data only on the Customer's documented instructions, including regarding transfers, unless required to do otherwise by EU or Member State law that applies to asyncmate; in that case asyncmate will inform the Customer of the legal requirement before processing, unless the law prohibits it. The Terms, this DPA, the Customer's configuration of the Service (for example enabling or disabling the AI digest), and written support requests together constitute the documented instructions. asyncmate will inform the Customer if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
asyncmate ensures that every person it authorizes to process Customer Data is bound by a contractual or statutory obligation of confidentiality.
5. Security
asyncmate implements and maintains the technical and organizational measures described in the Annex to this DPA, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing. asyncmate may update those measures from time to time, provided the update does not materially reduce the overall level of protection during a subscription period the Customer has already paid for.
6. Sub-processors
6.1 The Customer gives asyncmate general authorization to engage sub-processors for the processing of Customer Data. The current list is the sub-processor table in Section 6 of the Privacy Policy.
6.2 asyncmate will update that list and notify account owners by email at least 30 days before adding or replacing a sub-processor that processes Customer Data.
6.3 The Customer may object to a new sub-processor on reasonable data protection grounds within that notice period. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may cancel the affected part of the Service (or the subscription) under Section 6 of the Terms before the new sub-processor starts processing, and asyncmate will refund any prepaid fees for the period after cancellation.
6.4 asyncmate imposes data protection obligations on each sub-processor that are materially equivalent to those in this DPA, and remains liable to the Customer for the sub-processor's performance.
7. Assistance with data subject rights
Taking into account the nature of the processing, asyncmate assists the Customer, by appropriate technical and organizational measures, in fulfilling the Customer's obligation to respond to data subject requests. The in-app tooling described in Section 9 of the Privacy Policy lets the Customer's authorized account owner export a member's data and erase a member's linked records directly. For anything the tooling does not cover, asyncmate provides reasonable assistance on request. If a data subject contacts asyncmate directly about Customer Data, asyncmate will forward the request to the Customer without undue delay and will not respond on the merits except on the Customer's instruction or where the law requires.
8. Personal data breach
asyncmate will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent the information is available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. asyncmate will provide reasonable assistance with the Customer's obligations under Articles 33 and 34 GDPR and will document breaches as Article 33(5) requires.
9. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to it, asyncmate provides reasonable assistance with the Customer's obligations under Articles 35 and 36 GDPR (data protection impact assessments and prior consultation), where they relate to the processing of Customer Data under this DPA.
10. Deletion and return
10.1 During the subscription and for 14 calendar days after the Workspace is marked uninstalled, the Customer may request an export of its Customer Data in a structured, machine-readable format (in-app export tooling and support@asyncmate.com).
10.2 14 calendar days after uninstall, a scheduled job hard-erases the Workspace's personal data, as described in Section 8 of the Privacy Policy. The Customer may request earlier deletion in writing.
10.3 asyncmate may retain data only where EU or Member State law requires it (for example statutory accounting records), and retains the minimal non-personal entitlement record described in the Terms. On request, asyncmate will confirm in writing that deletion has completed.
10.4 Any copies in operational backups are overwritten in the normal backup rotation; backup media stay within the EU and are not used for any other purpose.
11. Audits
asyncmate makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR: this DPA, the Privacy Policy, the Annex, and, on request, written answers to reasonable security questionnaires. Where that is not sufficient, asyncmate will allow and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, under these conditions: at most once in any 12-month period (except after a personal data breach or where a supervisory authority requires it), with at least 30 days' written notice, during business hours, without access to other customers' data, and at the Customer's expense.
12. International transfers
Customer Data is hosted in the EU (Section 12 of the Privacy Policy). asyncmate transfers Customer Data outside the EEA only through the sub-processors and safeguards described in Sections 6 and 7 of the Privacy Policy: an adequacy decision (including the EU-US Data Privacy Framework where the sub-processor is certified) or the European Commission's 2021 Standard Contractual Clauses incorporated in the sub-processor's data processing agreement.
13. California (CCPA), where applicable
To the extent the California Consumer Privacy Act applies to Customer Data, asyncmate acts as the Customer's service provider: it does not sell or share personal information; does not retain, use, or disclose it for any purpose other than providing the Service under the Terms (or as the CCPA otherwise permits); does not combine it with personal information from other sources except as permitted for the business purpose; will notify the Customer if it can no longer meet these obligations; and the Customer may take reasonable steps under the CCPA to stop and remediate any unauthorized use.
14. Liability, term, and governing law
Each party's liability under this DPA is subject to Section 11 of the Terms, except where the GDPR does not permit that limitation. This DPA takes effect with the Terms and lasts as long as asyncmate processes Customer Data. It is governed by the same law as the Terms (Croatia).
Annex: technical and organizational measures
- Encryption in transit: HTTPS/TLS on all connections, with automatic certificate management.
- Encryption of secrets at rest: Slack bot tokens are encrypted with AES-256-GCM authenticated encryption; tampering causes decryption to fail; tokens are blanked on uninstall.
- Credential protection: passwords hashed via ASP.NET Identity; refresh tokens stored only as SHA-256 hashes with family-based rotation and replay/theft revocation; auth cookies are HttpOnly, Secure, SameSite=Lax.
- Tenant isolation enforced in the data layer: every tenant-scoped query is automatically filtered to the authorized Workspace, and writes take the Workspace from the authenticated tenant, not from client input.
- Access control: administrative and operations dashboards are access-controlled; production access is limited to authorized personnel.
- Abuse resistance: rate limiting on authentication endpoints; Slack webhook signatures validated; webhook idempotency records prevent replay.
- Minimized telemetry: the error tracker excludes cookies and request bodies, scrubs single-use tokens from URLs, and receives no standup content.
- Data minimization by design: member email addresses are never persisted (only a derived yes/no flag); anonymous responses are stored against an irreversible per-run hash; AI digest requests carry opaque Slack IDs instead of real names.
- EU hosting: a single EU-based server (Hetzner, Germany) with a self-hosted PostgreSQL database; backups remain within the EU.
- Resilience: containerized deployment with automatic restart policies and a
/healthendpoint for liveness checks; a scheduled retention job enforces deletion windows. - Incident handling: breaches affecting Customer Data are escalated to the operator immediately and notified under Section 8 of this DPA.