Data Processing Agreement
Last updated: 20 July 2026
This page summarises how Self-Control (operated by Skadi International Corporation, "the Processor") processes personal data on behalf of business customers ("the Controller") under Article 28 of the GDPR, and lists the sub-processors we use. A countersigned DPA is available on request for business customers at legal@self-control.app.
1. Roles
For personal data you submit to the Service about your own end users or team members, you are the Controller and Self-Control is the Processor. For data we collect as a service provider (such as your account and billing data), Self-Control is the Controller — see our Privacy Policy.
2. Subject matter and duration
We process personal data only to provide the Service under our Terms of Service, for the duration of your use of the Service plus any legally required retention period.
3. Nature and purpose of processing
Hosting, storing, organising, transmitting, and displaying the tasks, occurrences, items, notes, and team/sharing relationships you create, and the associated account and technical data, solely to provide the Service.
4. Categories of data and data subjects
- Data subjects: you, your team members, and people you invite.
- Personal data: names, email addresses, profile images, user-generated content, and technical/security data (IP address, user-agent, session records).
- We do not require or intend to process special-category data.
5. Our obligations as Processor
We will: (a) process personal data only on your documented instructions; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement appropriate technical and organisational security measures; (d) engage sub-processors only under written terms consistent with this DPA and notify you of changes; (e) assist you with data-subject requests and with your security, breach-notification, and impact-assessment obligations, taking into account the nature of processing; (f) delete or return personal data at the end of the engagement; and (g) make available information necessary to demonstrate compliance.
6. International transfers
Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the Standard Contractual Clauses (plus the UK Addendum) or an adequacy decision.
7. Sub-processors
We use the following sub-processors. We keep this list current and will provide a mechanism to object to material changes for business customers under a signed DPA. Our self-hosted observability stack runs on our own corp-controlled infrastructure and is not a third-party sub-processor.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Paddle | Payments, billing, tax (merchant of record) | UK / EU / US |
| Neon | Database hosting (Neon Postgres) | EU / US |
| Cloudflare | Application runtime (Workers), DNS, CDN | Global edge |
| Resend | Transactional and reminder email | US |
8. Security measures
Encryption in transit (TLS), short-lived access tokens, rotating refresh tokens with replay detection, rate limiting, least-privilege access, redaction of personal identifiers from operational telemetry, and regular backups with a tested restore procedure.
9. Contact
Requests for a signed DPA or sub-processor enquiries: legal@self-control.app.