Legal
Data processing agreement
Data protection terms for customers using AgooCloud as a processor.
Effective date: 9 September 20261. Scope and roles
This Data Processing Agreement forms part of the AgooCloud Terms where RVLWorks, SL processes personal data in customer backup content on the customer's behalf. The customer is controller and RVLWorks, SL is processor, unless applicable law assigns different roles.
2. Processing details
Subject matter: managed transmission, storage, versioning and restoration of customer-selected backups. Duration: the service term plus deletion and legal retention periods. Data subjects and categories are determined by the customer and may include employees, clients, suppliers and other persons represented in backed-up systems.
3. Instructions and confidentiality
RVLWorks, SL processes personal data only on documented customer instructions, including the agreement and use of service controls, unless law requires otherwise. Persons authorised to process data are bound by confidentiality.
4. Security
Measures include authenticated access, tenant ownership checks, transport encryption, optional client-side payload encryption, server-controlled object-storage credentials, logging, backup-session integrity checks and access limitation. Customers control source selection, password custody, endpoint security and restore testing.
5. Sub-processors
The customer authorises sub-processors needed to operate AgooCloud, including infrastructure, object storage and payment providers. RVLWorks, SL remains responsible for their processor obligations and will provide reasonable notice of material new sub-processors, allowing objection on substantiated data-protection grounds.
6. Assistance
Taking account of the nature of processing, RVLWorks, SL will reasonably assist with data-subject requests, security assessments, breach notifications and supervisory-authority enquiries. The customer remains responsible for the lawfulness of instructions and responses as controller.
7. Deletion and return
At the end of service, data will be returned or deleted at the customer's choice where technically available, unless law requires retention. Residual backup copies are isolated and removed through normal deletion cycles.
8. Audit information
We will provide information reasonably necessary to demonstrate compliance. Audits must be proportionate, protect other customers and security, and normally rely first on current reports and documentation.