sqlbook · A product by Sitelabs
Data Processing Agreement
Version 2026-10-11 · Prepared
1. Parties and application
sqlbook is a product by Sitelabs, the trading name of Christopher John Pattison. The supplier and processor is:
Christopher John Pattison trading as SitelabsDebussystraat 43, 2324 KH Leiden, Netherlands
KvK number: 94385815
hello@sqlbook.com
This DPA forms part of the pilot agreement when its dated version is incorporated into an order signed or expressly accepted by Sitelabs and the Customer. The Customer’s legal identity, contact and pilot dates are those recorded in that order. An individual accepting an account invitation does not separately enter a processing agreement for the whole business.
“Customer Personal Data” means personal data processed by Sitelabs on the Customer’s behalf through the agreed service. “Personal data”, “controller”, “processor”, “processing”, “personal data breach” and “supervisory authority” have their GDPR meanings. The Customer is the controller, or an authorized processor acting for a controller; Sitelabs is its processor or subprocessor accordingly. The parties will comply with applicable data-protection law.
This DPA governs Customer Personal Data. Information Sitelabs controls for its own account administration, business relationship, security and internal product measurements is described in the Privacy Policy. This DPA prevails over conflicting pilot provisions about personal-data processing; applicable mandatory transfer clauses prevail where required.
2. Instructions and Customer responsibilities
Sitelabs will process Customer Personal Data only on documented Customer instructions, including instructions about international transfers, unless Union or Member State law requires otherwise. If such law requires processing, Sitelabs will inform the Customer before processing unless that law prohibits notice on important public-interest grounds.
The pilot agreement, this DPA, selected sources and ranges, workspace permissions, authorized feature requests and sharing/deletion controls document the Customer’s instructions. Requests outside the agreed service require a separate written agreement. Sitelabs will immediately inform the Customer if, in its opinion, an instruction infringes applicable data-protection law and may pause the affected processing while the issue is resolved.
The Customer is responsible for lawful collection, notices, permissions, source access, accuracy and the authority of its users. If acting as a processor, it must obtain the controller’s authorization for Sitelabs and these subprocessors. It must limit content to what the service needs and must not supply special-category personal data, criminal-offence data or other highly sensitive regulated data without prior written agreement on suitable handling.
3. Confidentiality and security
Sitelabs will ensure that persons authorized to process Customer Personal Data are bound by confidentiality commitments or an appropriate statutory duty. Access will be limited to what their authorized tasks require.
Sitelabs will maintain appropriate technical and organizational measures under GDPR Article 32, taking account of the processing, risks, state of the art and implementation costs. The current technical measures are described in Schedule 2. Changes must not materially reduce the overall protection of Customer Personal Data. The Customer remains responsible for its own endpoints, source-system permissions and publication decisions.
4. Subprocessors and transfers
The Customer gives general written authorization for the relevant service providers listed in the completed, accepted Schedule 3. Sitelabs will impose data-protection obligations on each subprocessor that provide the protection required by GDPR Article 28 for its processing, and remains responsible to the Customer for the subprocessor’s performance of those obligations as required by law.
Before adding or replacing a subprocessor, Sitelabs will give advance written notice to the Customer’s contractual contact and a reasonable opportunity to object on data-protection grounds. The parties will seek a reasonable resolution. If a necessary change cannot be resolved, the affected processing must be stopped or the affected service ended under the agreement rather than proceeding contrary to applicable law. An updated website list alone does not substitute for that notice.
Restricted international transfers require a valid mechanism under applicable law before processing, such as an applicable adequacy decision or appropriate safeguards including standard contractual clauses where relevant. Sitelabs will provide information on the mechanism and available safeguards on request. A provider’s publication of standard terms is not evidence that those terms have been accepted for this pilot.
5. Rights requests and assistance
Taking account of the nature of processing, Sitelabs will assist the Customer through appropriate measures with requests to exercise data-subject rights. If Sitelabs receives a request about Customer Personal Data, it will notify the Customer and refer the requester to it where appropriate, rather than responding substantively without instructions unless legally required.
Taking account of available information and the nature of processing, Sitelabs will also assist with security duties, breach assessment and notifications, data-protection impact assessments and consultation with supervisory authorities under GDPR Articles 32–36. The parties may agree reasonable fees for assistance beyond ordinary service functions, without limiting assistance required by law.
6. Personal data breaches
Sitelabs will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, affected categories and approximate numbers where available, a contact point, likely consequences and measures taken or proposed to address it. Information may be supplied in stages as it becomes available.
Sitelabs will take reasonable steps to contain and investigate the incident, preserve relevant information and assist the Customer. Notification is not an admission of fault. The Customer remains responsible for its own legally required notices to authorities and affected people unless applicable law requires Sitelabs to notify directly. This DPA does not promise a fixed response-time SLA.
7. Information and audits
Sitelabs will make available the information needed to demonstrate compliance with this DPA and allow and contribute to audits, including inspections, by the Customer or its appointed auditor as required by GDPR Article 28.
The parties will first use relevant documentation and provider assurance material where sufficient. Inspections must use reasonable notice, appropriate confidentiality protections and arrangements that minimize disruption and protect other customers’ information. Those arrangements do not restrict an audit, inspection or supervisory-authority access required by law. Reasonable extraordinary audit costs may be agreed in advance; they must not make legally required audit rights ineffective.
8. Return and deletion
At the end of the service’s processing, Sitelabs will, at the Customer’s choice, return or delete Customer Personal Data and delete existing copies unless Union or Member State law requires retention. The Customer should use available exports and downloads and arrange support-assisted return before service access ends. No additional post-contract access or retrieval window is promised.
If return is chosen, Sitelabs will arrange an available, reasonably usable format and delete remaining copies after return, subject to legally required retention. If instructions are missing, Sitelabs will seek them; it will not treat that as permission to use the data for another purpose. Legally retained data will be isolated from ordinary use and protected until retention ends.
Application deletion removes live records and uses verified deletion of stored object versions. Deleted database records can remain in rotating recovery copies for the documented recovery window of up to three days. Provider logs and security records have their confirmed retention schedules. If a backup is restored, applicable deletion instructions must be reapplied. Sitelabs will provide information about completion on request.
Removing a member or an individual account does not instruct deletion of all data owned by a surviving Customer workspace. The Customer controls deletion of that shared content. The service cannot recall copies already published to recipients or delete the original data in a Customer-selected source.
9. Liability and contract changes
The Terms of Service and any express order exceptions govern contractual liability. The single aggregate cap for the affected pilot also covers claims under this DPA to the extent lawful; it is not increased separately for confidentiality or data protection. Nothing limits a data subject’s statutory rights, a regulator’s powers, or any liability that cannot lawfully be limited.
This DPA continues while Sitelabs processes Customer Personal Data for the pilot. Publishing a new version does not automatically amend an accepted DPA. Changes require the parties’ agreement unless mandatory law requires otherwise. Dutch law and the agreement’s competent-court provisions apply, subject to mandatory data-protection and transfer rules. A future company does not automatically replace the named supplier.
Schedule 1: Processing
- Subject matter and duration
- Providing the Customer’s sqlbook analytics workspace for the agreed three-month pilot, followed by the instructed return/deletion process and any legally required retention. Pilot dates and Customer contacts are specified in the order.
- Nature and purpose
- Authorized access, collection, storage, organization, retrieval, read-only querying, selective synchronization, analysis, AI response generation, visualization, publication, transmission and deletion to provide the Customer-selected features.
- Data subjects
- Depending on the Customer’s instructions: its staff, contractors, customers, prospects, suppliers and other people present in authorized datasets or workspace content.
- Data categories
- Depending on selected content: names and contact details; business, customer, CRM, transaction and billing information; file and spreadsheet contents; schema, SQL and returned rows; prompts, chat history, images, analysis and publication content. The Customer must identify any unusual categories before supplying them. Highly sensitive regulated categories require prior written agreement.
- Processing scope
- Live database access reads selected schema and query rows. Files and synchronized Google Sheets, Stripe and HubSpot content create private approved copies. Relevant AI context is transmitted for requested features. Publication discloses the Customer-approved results to its chosen audience.
- Customer instructions and contacts
- The accepted order identifies the Customer and its authorized contractual/privacy contact. Authorized workspace controls supply ongoing feature instructions. Processing is limited by this DPA and applicable law.
Schedule 2: Security measures
These measures describe the current application controls; they do not represent a certification or an uninterrupted-security guarantee.
- Transport and sessions: production HTTPS/HSTS; encrypted, secure, HTTP-only, same-site session cookies; passwordless sign-in with expiring one-time codes and rate limits.
- Credential handling: application-level encryption of stored datasource credentials and Google authorization tokens. Customer database connections verify TLS certificates and hostnames by default.
- Workspace access: tenancy and role checks, datasource read permissions, restrictions to selected tables, and authorization for delegated AI tools. Datasource read permissions apply to the whole source; selected-table restrictions determine which tables the service can query and do not create individual table-level access grants. Published dashboard audiences are controlled separately from datasource read permissions. Destructive AI actions require the product’s approval controls.
- Query and import boundaries: read-only query validation, bounded execution, and isolated import/query processing for uploaded and synchronized content.
- Storage and publication: private uploaded files and replicas; restricted delivery of non-public results; deliberate public publication only for Customer-selected content; version-aware object deletion.
- AI and diagnostics: credential redaction, disabled API response application storage, filtered request parameters and bounded diagnostic reporting. These controls do not establish zero provider retention or identifier-free diagnostics.
- Recovery: database point-in-time recovery with a documented three-day window and application deletion orchestration. The operational procedure for reapplying deletion instructions after restoration must be confirmed before this draft is supplied for acceptance.
The service currently does not provide MFA, enterprise SSO or a comprehensive authentication/admin audit log. Additional organizational commitments and provider account controls must be confirmed for the accepted pilot; this schedule must not be read as evidence of unverified certifications, recovery-time guarantees or account settings.
Schedule 3: Providers
These are the identified application providers that can process relevant Customer Personal Data. Their exact contractual entities, accepted processing terms, locations, safeguards and retention settings must be completed and confirmed before this review draft is supplied for acceptance.
- Render Services, Inc. — hosting and databases
- Account/workspace records, Customer content, encrypted credentials and operational metadata needed for the hosted application. Production resource regions, provider log retention and accepted contractual safeguards require account confirmation.
- Scaleway — object storage and delivery
- Uploaded files, private synchronized replicas, attachments and selected published results. Amsterdam storage is documented for the upload and published-result buckets. Delivery and other processing locations, the applicable contractual entity and accepted processing terms require confirmation; this does not establish that all provider processing is confined to Amsterdam.
- OpenAI — requested AI features
- Relevant prompts, history, schema, SQL, selected results, images and feature context. Response application storage is disabled in requests. Contractual entity, account data controls, processing locations and applicable security/abuse retention require confirmation; zero retention is not claimed.
- AhaSend B.V. — transactional email
- Recipient addresses, included names/workspace details, service-message content and delivery metadata. Production storage/relay locations, message and suppression retention and accepted processing terms require confirmation.
- Functional Software, Inc. (Sentry) — diagnostics
- Exceptions, traces and operational identifiers; exceptional paths can include personal identifiers. Production region, retention, scrubbing and accepted processing terms require confirmation.
The actual support-mailbox provider and any additional business/support processing systems must be identified before finalizing this schedule. Customer-selected source services and publication recipients are instructed destinations, rather than automatically being Sitelabs-selected subprocessors. Google Fonts is a browser font-delivery service disclosed in the Privacy Policy, rather than a provider to which we send Customer workspace datasets.
Contact hello@sqlbook.com for processing questions and the completed schedule. Subprocessor-change notices are delivered to the Customer contact under section 4.