Skip to main content
Legal

Data Processing Agreement

Last updated: 20 July 2026

This page summarises how Self-Control (operated by Skadi International Corporation, "the Processor") processes personal data on behalf of business customers ("the Controller") under Article 28 of the GDPR, and lists the sub-processors we use. A countersigned DPA is available on request for business customers at legal@self-control.app.

1. Roles

For personal data you submit to the Service about your own end users or team members, you are the Controller and Self-Control is the Processor. For data we collect as a service provider (such as your account and billing data), Self-Control is the Controller — see our Privacy Policy.

2. Subject matter and duration

We process personal data only to provide the Service under our Terms of Service, for the duration of your use of the Service plus any legally required retention period.

3. Nature and purpose of processing

Hosting, storing, organising, transmitting, and displaying the tasks, occurrences, items, notes, and team/sharing relationships you create, and the associated account and technical data, solely to provide the Service.

4. Categories of data and data subjects

  • Data subjects: you, your team members, and people you invite.
  • Personal data: names, email addresses, profile images, user-generated content, and technical/security data (IP address, user-agent, session records).
  • We do not require or intend to process special-category data.

5. Our obligations as Processor

We will: (a) process personal data only on your documented instructions; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement appropriate technical and organisational security measures; (d) engage sub-processors only under written terms consistent with this DPA and notify you of changes; (e) assist you with data-subject requests and with your security, breach-notification, and impact-assessment obligations, taking into account the nature of processing; (f) delete or return personal data at the end of the engagement; and (g) make available information necessary to demonstrate compliance.

6. International transfers

Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the Standard Contractual Clauses (plus the UK Addendum) or an adequacy decision.

7. Sub-processors

We use the following sub-processors. We keep this list current and will provide a mechanism to object to material changes for business customers under a signed DPA. Our self-hosted observability stack runs on our own corp-controlled infrastructure and is not a third-party sub-processor.

Sub-processorPurposeProcessing location
PaddlePayments, billing, tax (merchant of record)UK / EU / US
NeonDatabase hosting (Neon Postgres)EU / US
CloudflareApplication runtime (Workers), DNS, CDNGlobal edge
ResendTransactional and reminder emailUS

8. Security measures

Encryption in transit (TLS), short-lived access tokens, rotating refresh tokens with replay detection, rate limiting, least-privilege access, redaction of personal identifiers from operational telemetry, and regular backups with a tested restore procedure.

9. Contact

Requests for a signed DPA or sub-processor enquiries: legal@self-control.app.