Data Processing Agreement

This DPA supplements the Stora Terms of Service for Controllers subject to GDPR. Last updated: July 2026.

How to counter-sign: Print this page to PDF using your browser (File → Print → Save as PDF) and sign it as your organisation's controller-side signature. Send a copy to privacy@storabackup.com for our records.

1. Subject Matter and Duration

This Data Processing Agreement ("DPA") governs the processing of personal data by Stora ("Processor") on behalf of the customer organisation ("Controller") when the Controller uses the Stora backup and data-exploration service ("Service"). This DPA is effective from the date the Controller first uses the Service and remains in force until the Controller's account is closed or this DPA is superseded by a written replacement signed by both parties.

2. Nature and Purpose of Processing

Stora processes personal data solely to provide the following services as instructed by the Controller:

  • Pairing the Controller's WhatsApp account as a linked device, using the WhatsApp Web multi-device protocol, on the Controller's instruction.
  • Capturing message, media, contact, group, call, and status content according to the categories the Controller selects for backup.
  • Storing the backed-up content in Stora's archive storage, hosted at Hetzner Storage Box (object storage in Germany).
  • Providing a web interface for the Controller to browse, search, and export the backed-up archive.

Stora will not use personal data included in backed-up content for any purpose other than providing the Service.

3. Type of Personal Data

Stora processes personal data decrypted from the Controller's WhatsApp account as part of operating as a linked device — this is decrypted, plaintext personal data, not an encrypted blob Stora cannot read. Depending on the categories the Controller selects for backup, this includes: message text; media (photos, videos, voice notes, and documents); contact names and phone numbers; group membership and rosters; call metadata; and status updates from people the Controller follows. Stora has no control over what personal data is present in the Controller's WhatsApp account and instructs Stora to back up.

On a plan with a limited history window, the Controller's full WhatsApp message history is decrypted into Stora's sync infrastructure's database before being filtered down to the window the Controller's plan includes; only the entitled window is written to the long-term archive. Rows from that intermediate database — including messages outside the plan's window — persist in Stora's nightly database backup for up to 7 days.

4. Categories of Data Subjects

Data subjects include the Controller and any personnel authorised to use the Controller's account, and — most significantly — the Controller's WhatsApp contacts and the participants of any groups the Controller belongs to. These contacts and group participants are natural persons who are not Stora customers, have not created a Stora account, and have not agreed to Stora's terms, but whose names, phone numbers, and message content are present in the backed-up archive.

5. Controller Obligations

The Controller agrees to:

  • Provide lawful instructions to Stora for all processing, ensuring a valid legal basis under GDPR Article 6 (and where applicable Article 9) for backing up their WhatsApp account, including the personal data of their contacts and group participants contained within it.
  • Obtain any necessary consents from data subjects before backing up WhatsApp content that contains their personal data, to the extent required by applicable law.
  • Notify Stora promptly if any instruction would cause Stora to violate applicable data protection law.
  • Implement appropriate technical and organisational measures to protect their Stora account credentials and their linked WhatsApp device pairing.

6. Processor Obligations

Stora agrees to:

  • Process personal data only on documented instructions from the Controller (including via the category-selection settings the Controller uses to choose what is backed up), except where required by Union or Member State law.
  • Ensure that authorised personnel are bound by appropriate confidentiality obligations.
  • Assist the Controller in fulfilling data subject rights requests (access, erasure, rectification, portability, restriction) using the tools available in the Service. The Controller is responsible for identifying and routing such requests.
  • Maintain records of processing activities under Article 30(2) of the GDPR.
  • Delete or return all personal data to the Controller upon termination of the Service, unless legally required to retain it.

7. Sub-processor Flow-Down

By accepting this DPA, the Controller provides general authorisation for Stora to engage sub-processors. The current list of sub-processors is published at /legal/sub-processors/.

Stora will notify the Controller of any intended changes to the sub-processor list (additions or replacements) by emailing the organisation's Owner and Admin users at least 14 days before the change. The Controller may object within this period; objection will be treated as a termination notice without penalty. Stora imposes data protection obligations on all sub-processors equivalent to those in this DPA via written agreements.

8. Technical and Organisational Measures

Stora implements the following technical and organisational measures ("TOMs") to protect backed-up personal data:

  • Transit encryption: All data in transit between the Stora application and Hetzner Storage Box is protected by TLS 1.3.
  • At-rest protection: Backed-up content is stored unencrypted at the application layer at Hetzner's Germany data centre; at-rest encryption below the application layer is whatever Hetzner's storage infrastructure provides. There is no user-held passphrase and no encryption key protecting the archive — this is what makes email-based account recovery possible without losing the archive, see the Privacy Policy's credential-recovery posture — and it also means Stora personnel with production access can read backed-up content.
  • Access control: Multi-tenant row-level isolation (each account's data is scoped by tenant key). Production system access is restricted to authorised personnel with MFA.
  • Session credential isolation (planned): Stora's design commitment is to isolate WhatsApp linked-device session credentials from the database role used by the rest of the application, limiting the impact of any single compromised credential. This isolation is planned as part of the WhatsApp protocol layer under active development and is not yet deployed.
  • Audit logging: All authenticated actions are logged with timestamp, user, IP address, and action type. Logs are retained per the schedule in the Privacy Policy.
  • Vulnerability management: Dependencies are monitored via automated pip-audit CI checks; patches are applied within 30 days of disclosure.

9. Breach Notification

In the event of a personal data breach (as defined in GDPR Article 4(12)), Stora will notify the Controller without undue delay — and in any event within 72 hours of becoming aware of the breach (GDPR Article 33). Notification will be sent to the email address associated with the organisation's Owner account and will include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

The Controller is responsible for notifying the relevant supervisory authority and affected data subjects in accordance with GDPR Articles 33 and 34.

10. Audit Rights

Stora will make available to the Controller all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice (30 days) and confidentiality obligations. Stora may satisfy audit requests by providing a current third-party audit report (e.g., SOC 2 Type II or equivalent) in lieu of a dedicated on-site audit.

11. Return and Deletion at End of Service

Upon termination of the Controller's Stora account, Stora will delete all personal data in backed-up content within 30 days, unless a longer retention period is required by law. The Controller may export their backed-up data at any time before account termination using the Data Export feature.

12. Governing Law

This DPA is governed by the law of the Republic of Ireland, without prejudice to the mandatory data protection provisions of the GDPR as applicable in the Controller's jurisdiction. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the Irish courts, except where mandatory consumer-protection law confers jurisdiction elsewhere.

Questions

For DPA queries or to register your signed counter-signature: privacy@storabackup.com.