SaveState
DownloadFeaturesPricingSupport
Sign upStart 14-day trial
LEGAL

Data Processing Addendum

Effective 21 August 2026

This Data Processing Addendum (“DPA”) forms part of the SaveState Terms of Service when a business customer uses SaveState to process personal data on its behalf.

Parties and roles

The customer is the controller and SaveState is the processor for personal data placed in backups or supplied as operational instructions. Each party remains independently responsible for personal data it controls, including SaveState’s account administration, security, support, and billing records.

Processor: SaveState, operated by Gustav Fyhn Larsen

Dalagervej 12, 6623 Vorbasse, Denmark

privacy@savestate.dk

Processing instructions and scope

SaveState processes customer personal data only to provide, secure, support, and delete the encrypted backup service; to comply with documented customer choices in the product; or as required by law. The subject matter is encrypted backup storage and restore. Processing lasts for the subscription and deletion lifecycle. Data may include any categories selected by the customer for backup, plus paths, timestamps, file counts, sizes, schedules, and job status. Data subjects may include the customer’s staff, users, clients, or other people represented in the backed-up systems.

The customer is responsible for lawful instructions, notices, legal bases, data minimisation, and ensuring that SaveState is suitable for the data being backed up. The customer must not use the service for processing that requires controls SaveState has not expressly agreed to provide.

Confidentiality and security

SaveState limits access to authorised persons bound by confidentiality and uses measures appropriate to the service, including encryption in transit, client-side authenticated encryption of backup contents, restricted administrative access, encrypted operational secrets, rate limits, security logging, private Backblaze buckets, and provider access controls. The customer controls the backup selection and key material and must protect recovery credentials.

Subprocessors

The customer authorises SaveState to use the following subprocessors for the backup service:

  • Backblaze, Inc. — encrypted object storage in the EU Central region, Amsterdam.
  • Cloudflare, Inc. — network, edge security, Workers, queues, and database infrastructure.

Stripe processes payments separately and is not used to store customer backup contents. SaveState uses written data-processing terms with its subprocessors and remains responsible to the customer for its processor obligations; those obligations cannot be assigned away merely because an incident occurs inside Backblaze or Cloudflare. Material subprocessor changes will be posted on this page or communicated through the service. A customer with a reasonable data-protection objection should contact SaveState before the change takes effect.

International transfers

Encrypted backup objects are configured for Backblaze’s EU Central region without cross-region replication. Cloudflare may process network and operational data globally. Where processing involves a restricted transfer from the EEA, SaveState will rely on an adequacy decision, approved Standard Contractual Clauses made available by the provider, or another lawful transfer mechanism.

Assistance and incidents

Taking into account the nature of the processing and information available, SaveState will reasonably assist the customer with data-subject requests, security obligations, breach assessment, and legally required impact assessments. SaveState will notify the customer without undue delay after confirming a personal-data breach affecting customer personal data and will provide available information needed for the customer’s legal duties.

Deletion and return

During an active subscription and the documented three-day restore-only grace period, the customer can retrieve encrypted backups through the service. At the grace deadline, SaveState deletes the service’s object versions, storage bucket, snapshot/folder metadata, related service state, and any vault-key envelope no longer used by another service. On a verified full-erasure instruction, SaveState additionally queues deletion of subscriptions and customer-linked account metadata. Minimal records may remain only where law requires them or where needed to prove completion without retaining backup contents.

Storage dependency and allocation of responsibility

Backblaze operates the B2 storage layer and Cloudflare operates material application infrastructure. Their availability, durability, incident response, and contractual safeguards form part of SaveState’s technical risk management, but the customer’s DPA remains with SaveState. Provider failure does not turn Backblaze or Cloudflare into the customer’s processor under this DPA, and does not remove SaveState’s obligations under applicable data-protection law. The customer remains responsible for deciding whether this single-region, non-replicated service is appropriate for its risk level and for maintaining any independent copy its continuity plan requires.

Information and audits

SaveState will provide information reasonably necessary to demonstrate compliance with this DPA. Audits must be proportionate, protect other customers and security information, use existing reports first, and be arranged on reasonable notice. The customer bears its audit costs unless an audit identifies a material breach by SaveState.

Priority and law

If this DPA conflicts with the Terms on processing customer personal data, this DPA controls. The remaining Terms, including Danish governing law and mandatory consumer protections, continue to apply.

SaveState

Automated, encrypted cloud backups for Windows systems, servers, application data, and important files.

Product

FeaturesPricingDashboard

Resources

About SaveStateSupportFile backupsWindows server backupsMySQL and MariaDB backupsOpen-source client

Legal

PrivacyTermsData processingAffiliate agreement
© 2026 SaveState. All rights reserved.Built for recoverability.