asyncmate Data Processing Agreement
Last updated: September 9, 2026
This Data Processing Agreement ("DPA") forms part of the asyncmate Terms of Service (the "Terms") between Code7 d.o.o., a limited liability company registered in Croatia (OIB 76594489608, MB 06051537, registered address Zagorska ulica 105, 42220 Novi Marof, Croatia) ("asyncmate") and the Customer. It applies whenever asyncmate processes personal data contained in Customer Data on the Customer's behalf and the GDPR, or an equivalent data protection law, applies to that processing.
No signature is required: this DPA is accepted together with the Terms when you install the asyncmate Slack or Microsoft Teams app or otherwise use the Service. If your procurement process needs a countersigned copy, email support@asyncmate.com and we will provide one.
Capitalized terms not defined here ("Customer Data", "Workspace", "Service", "Authorized User") have the meanings given in the Terms. "GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in Article 4 GDPR.
1. Roles and scope
1.1 For personal data in Customer Data, the Customer is the controller and asyncmate is the processor. If the Customer is itself a processor for another controller, asyncmate acts as its sub-processor, and the Customer warrants that its instructions to asyncmate are consistent with the controller's instructions.
1.2 This DPA does not cover the data for which asyncmate is an independent controller (account, billing, security, and website data). That processing is described in the Privacy Policy.
1.3 In case of conflict between this DPA and the Terms, this DPA prevails for personal-data processing matters.
2. Details of the processing
- Subject matter: provision of the asyncmate Service to the Customer under the Terms.
- Duration: the term of the Terms, plus the deletion window in Section 10.
- Nature and purpose: hosting and storing Customer Data; scheduling and delivering check-ins, reminders, polls, and surveys into the Customer's Slack workspace or Microsoft Teams team; collecting responses and votes; posting and recording kudos; compiling digests, including optional AI digests; hours and out-of-office logging; exports; and support.
- Categories of data subjects: members of the Customer's connected Slack workspace or Microsoft Teams team (employees, contractors, and guests) and the Customer's account owners and administrators.
- Categories of personal data: member profile data (Slack user ID or Microsoft Entra object ID, names, profile image URL, timezone, role flags, as each platform provides them); check-in and survey answers, including free text; poll and survey votes; kudos messages (sender and recipient Slack user IDs and free text); logged hours and out-of-office periods; blocker records and digest snapshots derived from answers; and related timestamps and participation records.
- Special categories: none intended. The Customer must not configure the Service to solicit special categories of personal data (Terms, Section 7). Free-text answers may incidentally contain sensitive information; asyncmate processes such content under the same safeguards as all other Customer Data and makes no separate use of it.
3. Instructions
asyncmate processes Customer Data only on the Customer's documented instructions, including regarding transfers, unless required to do otherwise by EU or Member State law that applies to asyncmate; in that case asyncmate will inform the Customer of the legal requirement before processing, unless the law prohibits it. The Terms, this DPA, the Customer's configuration of the Service (for example enabling or disabling the AI digest), and written support requests together constitute the documented instructions. asyncmate will inform the Customer if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
asyncmate ensures that every person it authorizes to process Customer Data is bound by a contractual or statutory obligation of confidentiality.
5. Security
asyncmate implements and maintains the technical and organizational measures described in the Annex to this DPA, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing. asyncmate may update those measures from time to time, provided the update does not materially reduce the overall level of protection. This commitment applies for as long as asyncmate processes Customer Data, including on the free tier, during a trial or the launch offer, and after the subscription ends until deletion is complete.
6. Sub-processors
6.1 The Customer gives asyncmate general authorization to engage sub-processors for the processing of Customer Data. The current list is the sub-processor table in Section 6 of the Privacy Policy.
6.2 asyncmate will update that list and notify account owners by email at least 30 days before adding or replacing a sub-processor that processes Customer Data.
6.3 The Customer may object to a new sub-processor on reasonable data protection grounds within that notice period. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may cancel the affected part of the Service (or the subscription) under Section 6 of the Terms before the new sub-processor starts processing, and asyncmate will refund any prepaid fees for the period after cancellation.
6.4 asyncmate imposes data protection obligations on each sub-processor that are materially equivalent to those in this DPA, and remains liable to the Customer for the sub-processor's performance.
7. Assistance with data subject rights
Taking into account the nature of the processing, asyncmate assists the Customer, by appropriate technical and organizational measures, in fulfilling the Customer's obligation to respond to data subject requests. The in-app tooling described in Section 9 of the Privacy Policy lets the Customer's authorized account owner export a member's data and erase a member's linked records directly. For anything the tooling does not cover, asyncmate provides reasonable assistance on request. If a data subject contacts asyncmate directly about Customer Data, asyncmate will forward the request to the Customer without undue delay and will not respond on the merits except on the Customer's instruction or where the law requires.
8. Personal data breach
asyncmate will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent the information is available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. asyncmate will provide reasonable assistance with the Customer's obligations under Articles 33 and 34 GDPR and will document breaches as Article 33(5) requires.
9. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to it, asyncmate provides reasonable assistance with the Customer's obligations under Articles 35 and 36 GDPR (data protection impact assessments and prior consultation), where they relate to the processing of Customer Data under this DPA.
10. Deletion and return
10.1 During the subscription and for 14 calendar days after the Workspace is marked uninstalled, the Customer may request an export of its Customer Data in a structured, machine-readable format (in-app export tooling and support@asyncmate.com).
10.2 14 calendar days after uninstall, a scheduled job hard-erases the Workspace's personal data, as described in Section 8 of the Privacy Policy. The Customer may request earlier deletion in writing.
10.3 asyncmate may retain data only where EU or Member State law requires it (for example statutory accounting records), and retains the minimal entitlement record described in Section 8 of the Privacy Policy. On request, asyncmate will confirm in writing that deletion has completed.
10.4 Backup copies are encrypted before they leave asyncmate's server, are stored in an EU-jurisdiction bucket, are deleted by the backup retention policy within 30 days, and are used only to recover from data loss. If asyncmate restores from a backup, the scheduled retention job re-purges any Workspace whose deletion window had already passed, and asyncmate will re-apply completed erasure requests that the restore would otherwise undo, on the Customer's notice and from its own records where they exist.
11. Audits
asyncmate makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR: this DPA, the Privacy Policy, the Annex, and, on request, written answers to reasonable security questionnaires. Where that is not sufficient, asyncmate will allow and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, under these conditions: at most once in any 12-month period (except after a personal data breach or where a supervisory authority requires it), with at least 30 days' written notice, during business hours, without access to other customers' data, and at the Customer's expense.
12. International transfers
Customer Data is hosted in the EU (Section 12 of the Privacy Policy). asyncmate transfers Customer Data outside the EEA only through the sub-processors and safeguards described in Sections 6 and 7 of the Privacy Policy: an adequacy decision (including the EU-US Data Privacy Framework where the sub-processor is certified) or the European Commission's 2021 Standard Contractual Clauses incorporated in the sub-processor's data processing agreement.
13. California (CCPA), where applicable
To the extent the California Consumer Privacy Act applies to Customer Data, asyncmate acts as the Customer's service provider: it does not sell or share personal information; does not retain, use, or disclose it for any purpose other than providing the Service under the Terms (or as the CCPA otherwise permits); does not combine it with personal information from other sources except as permitted for the business purpose; will notify the Customer if it can no longer meet these obligations; and the Customer may take reasonable steps under the CCPA to stop and remediate any unauthorized use.
14. Liability, term, and governing law
Each party's liability under this DPA is subject to Section 11 of the Terms, except where the GDPR does not permit that limitation. This DPA takes effect with the Terms and lasts as long as asyncmate processes Customer Data. It is governed by the same law as the Terms (Croatia).
Annex: technical and organizational measures
- Encryption in transit: HTTPS/TLS on all connections, with automatic certificate management.
- Encryption of secrets at rest: Slack bot tokens are encrypted with AES-256-GCM authenticated encryption; tampering causes decryption to fail; tokens are blanked on uninstall. The Microsoft Teams bot holds no per-team tokens; it authenticates with one application credential kept in server configuration, outside the database. For Microsoft Teams no per-tenant token is stored: the bot authenticates with application credentials held in server configuration, and one-time claim codes are stored only as hashes.
- Credential protection: passwords hashed via ASP.NET Identity; refresh tokens stored only as SHA-256 hashes with family-based rotation and replay/theft revocation; auth cookies are HttpOnly, Secure, SameSite=Lax.
- Tenant isolation enforced in the data layer: every tenant-scoped query is automatically filtered to the authorized Workspace, and writes take the Workspace from the authenticated tenant, not from client input.
- Access control: administrative and operations dashboards are access-controlled; production access is limited to authorized personnel.
- Abuse resistance: rate limiting on authentication endpoints; Slack webhook signatures validated; Microsoft-issued signed tokens verified on every Teams request; Microsoft Teams bot activities accepted only with a valid Bot Framework or Entra JWT for our app; webhook idempotency records prevent replay.
- Minimized telemetry: the error tracker excludes cookies and request bodies, scrubs single-use tokens from URLs, and receives no standup content.
- Data minimization by design: member email addresses are never persisted (only a derived yes/no flag); anonymous responses are stored against an irreversible per-run hash; AI digest requests carry opaque Slack or Microsoft Teams IDs instead of real names.
- EU hosting and backups: a single EU-based server (Hetzner, Germany) with a self-hosted PostgreSQL database; daily database backups are encrypted on the server (AES-256) before upload to an EU-jurisdiction object store and deleted after 30 days.
- Resilience: containerized deployment with automatic restart policies and a
/healthendpoint for liveness checks; a scheduled retention job enforces deletion windows. - Incident handling: breaches affecting Customer Data are escalated to the operator immediately and notified under Section 8 of this DPA.