Droova Platform — Terms of Service
These Commercial Terms of Service (“Terms”) are an agreement between Droova and you or the organization, company, or other entity that you represent (“Customer”). “Droova” means Droova, Limited. These Terms are effective on the earlier of the date that Customer first electronically consents to a version of these Terms and the date that Customer first accesses the Services (“Effective Date”).
1 Preamble
Droova provides the Customer with an AI-powered task management platform (the "Droova Platform"), delivered as a cloud-based Software-as-a-Service.
The Droova Platform automatically extracts tasks, action items and project context from the Customer's connected data sources — meetings, email, calendar and chat — and presents them to authorised users via individual and team views.
This Master Subscription Agreement (the "Agreement") governs the Customer's use of the Droova Platform. Droova and the Customer agree as follows.
Part A — General section
1 Definitions
Unless otherwise indicated by the context, the following definitions apply:
- “Active user”
- An individual created on the Platform by the Customer who is able to log in, regardless of whether they have done so.
- “Activated employee”
- An Active User who has completed account setup, including setting a password.
- “Customer Data”
- All data, content and information that the Customer or its users transmit to, store on, or have processed through the Platform, including communications content ingested via connected sources.
- “Documentation”
- The user guides and reference materials Droova provides electronically.
- “Sub-Processor”
- A third party processing Customer Data on Droova's behalf (e.g., LLM providers, hosting providers). The current list is maintained in the DPA.
- “Confidential Information”
- Any non-public commercial or technical information disclosed by one party to the other, marked or reasonably understood to be confidential.
The words "in particular" or "including" are used for illustrative purposes only and do not limit the generality of the preceding words; any headings are for convenience only and do not affect the interpretation of this contract.
2 Contract formation; customer's terms and conditions
- The subject of this Agreement is the Customer's use of the Droova Platform. Use of the Platform by the Customer's employees is governed by separate end-user terms presented at sign-in.
- Droova's services are offered for business purposes only. The Customer warrants that it is entering this Agreement in the course of its trade, business or profession and is not a "consumer" within the meaning of section 2 of the Consumer Rights Act 2015.
- The Agreement is formed when the Customer signs and submits the Order Form (the "Offer") and Droova accepts it, either by counter-signing the Order Form or by granting access to the Droova Dashboard (the "Effective Date").
- The Customer receives an electronic copy of the executed Agreement. Electronic signatures are valid and binding.
- The Agreement is concluded in English.
- The Customer's standard terms and conditions do not apply unless Droova accepts them in writing.
- Affiliates of the Customer (as defined in section 1159 of the Companies Act 2006) may accede to this Agreement on the same terms upon prior written notice to Droova, subject to Droova's right to object within 14 days for good cause or to require an adjustment of pricing.
3 Services from Droova
- For the term of the Agreement, Droova provides the Customer with access to the Droova Platform over the internet. The exact scope is set out in the Order Form.
- The Platform is accessed via a standard web browser; no client installation is required.
- Droova performs daily encrypted backups of Customer Data, retained for 30 days. Backups are not individually verified and no individual backup is warranted.
- Droova provides Documentation electronically in English and/or German during onboarding. The Customer may not edit, distribute or publish the Documentation.
- Where the Platform produces analytics, reports or AI-generated outputs, these are informational only. Droova accepts no liability for business or tax decisions the Customer takes in reliance on them, except in cases of intent.
- Droova may rely on Sub-processors (in particular LLM providers) to deliver the Service. Sub-processors are listed in the DPA. Droova remains responsible to the Customer for their performance under this Agreement.
4 Service-Level-Agreement (SLA)
Unless otherwise agreed in the Order Form, the provider guarantees an average monthly availability of the platform of 70%, corresponding to a maximum downtime of 7.5 hours per month. This excludes planned maintenance work and disruptions that are outside the provider's control, in particular force majeure, network or power supply failures or incorrect operation by the customer.
Droova will announce planned maintenance work in writing in advance whenever possible. However, unannounced maintenance work is expressly reserved, particularly if it is necessary for the security of the platform, the integrity of customer data, or proper operation. Planned maintenance windows will be kept to a minimum whenever possible.
Droova provides customer support services, available Monday to Friday, from 9:00 AM to 5:00 PM CET/CEST, excluding public holidays in Berlin. Support is provided via email (contact@droova.ai) and includes assistance with using the platform, troubleshooting, and general questions regarding functionality.
Faults are classified according to severity, with the following response targets:
| Priority | Description | Response target |
|---|---|---|
| Critical (P1) | Platform completely unavailable or data loss imminent | Within 7 working days |
| High (P2) | Partial functionality impaired | Within 7 working days |
| Medium (P3) | Functional limitations that do not significantly impede use | Within 72 hours |
| Low (P4) | Minor errors | Within 7 working days |
Should the SLA targets be undershot, the customer is not entitled to service credits.
Droova reserves the right to amend the SLA for objectively justified reasons, in particular due to legal changes, security requirements, or technological developments. Significant deteriorations in the SLA terms entitle the customer to terminate the agreement within two (2) months of notification.
Subcontractors
Droova is entitled to engage subcontractors as agents for the provision of services at its own discretion.
5 Extensions, further developments, changes
Droova may make changes to the Droova Platform in the following cases.
Extensions and further developments
Droova is entitled to add additional features to the services to be provided at any time. Features introduced by Droova after the conclusion of this contract are considered free additional services, unless otherwise agreed. Droova is entitled to reinstate these. Droova also reserves the right to offer upgraded plans and further developments only against payment of an additional fee.
Reasonable and insignificant changes
Droova is entitled to modify, restrict, or discontinue the functionality of the Droova Platform and the services.
Commissioning of additional services / further developments
Further developments can be requested by the customer via written notification to the Customer Success contact. Upon receipt of the notification, Droova will prepare a separate offer containing a detailed description of services and the applicable hourly rate.
The hourly rate is generally negotiable; however, Droova reserves the right to determine the specific amount according to the type, scope and requirements of the desired service.
6 Usage rights
- Upon commencement of the contract, Droova grants the customer a non-exclusive, non-transferable right, limited to the contract term, to use the Droova Platform in accordance with the contract. This right may be sublicensed to its employees only to the extent strictly necessary for the customer's intended use. Unless expressly agreed otherwise in the Order Form, the customer is prohibited from transferring the Droova Platform to third parties. The customer's other statutory rights remain unaffected.
- Excluded from the granting of rights are components of the Droova Platform that are recognisably subject to third-party rights, in particular Open-Source Software. Components disclosed by Droova within the Order Form, the Platform, or in accompanying text files as third-party content are considered identifiable.
- All rights to information, images, texts, documents, data, files, and other content transmitted to Droova by the customer, or stored within the Platform or the IT infrastructure provided by Droova, remain with the customer. The customer grants Droova a non-exclusive, geographically and temporally unlimited right to use this content to the extent necessary for the performance of the contract — in particular to reproduce the data for the purposes of operating the Platform and data backup, and to grant sublicenses to its agents where necessary. Otherwise, the right of use is not transferable.
- The customer provides Droova with marketing materials, including images of its brand, enabling Droova to promote the cooperation between the customer and Droova. Such materials also include Droova case studies in which the customer may participate. The customer grants Droova a non-exclusive, geographically and temporally unlimited right to use these marketing materials for promoting the cooperation in sales materials and on the World Wide Web, in particular on the website www.droova.com.
7 Customer's obligations
- The customer is responsible for ensuring they are able to receive Droova's services. The provision of the necessary hardware and software is not part of the contract. The customer is solely responsible for the operation and availability of their own business software.
- The customer must keep the access data for the Platform secure and may only grant access to authorised employees, who must be obligated to treat access data confidentially. The customer must inform Droova immediately of any suspicion that access data may have become known to unauthorised persons.
- The customer will refrain from any actions that could jeopardise or disrupt the functionality of the Platform or Droova's IT infrastructure, will comply with all security precautions, and will not remove, overcome, disable, or otherwise circumvent any protection or authentication mechanisms.
- The customer will not transmit malware, nor upload data or content intended to induce third parties to disclose confidential information, automatically redirect them to other services outside the Platform, infringe third-party rights, or violate applicable law.
- The customer is responsible for regularly and appropriately backing up their data and content, in particular data they are legally or contractually obligated to retain.
- The customer is responsible for operating and configuring the Platform. Any information, recommendations, or analysis results generated by the Platform are automatically generated, non-binding information to support business decision-making and do not relieve the customer of the responsibility to verify accuracy.
- The customer names a contact person authorised to receive and issue declarations of intent in connection with the contract, and will report any personnel changes within a reasonable timeframe.
- The customer keeps the information provided during conclusion of the contract up to date and notifies Droova of any changes immediately, in particular contact and business information.
- The customer warrants that it will comply with all applicable legal regulations when using the Platform, will use communication functions only for their intended and contractually agreed use, and bears sole responsibility for compliance with labour-law regulations.
8 Liability for third-party rights
Droova is not liable for any infringement of third-party rights by the customer, insofar as this results from exceeding the usage rights granted under this contract. In this case, the customer shall indemnify Droova against all third-party claims upon first demand.
9 Access restriction
Droova is entitled to block the customer's access to the Platform, or to individual parts of it, taking into account the interests of both parties, if:
- there are indications that access data has been or is being misused, given to an unauthorised third party, or used by more than one natural person;
- there are indications that third parties have gained access to the Platform through other means;
- the closure is necessary for technical reasons;
- Droova is legally, judicially or officially obligated to block access;
- the customer posts prohibited content on the Platform;
- the customer is more than four (4) weeks in arrears with payment of agreed fees, or has provided incorrect or invalid contact details making communication impossible; or
- the blocking is necessary to avert imminent damage to Droova, the customer or third parties, or to mitigate damage already occurred.
Droova shall notify the customer of the suspension and its reasons in text or written form no later than seven (7) business days before it takes effect, and allow the customer to comment, provided this is reasonable for both parties and compatible with the purpose of the suspension. Such notification is not reasonable where the suspension is for security reasons or where Droova is legally, judicially, or officially obligated to suspend. Droova will unblock use once the reason for suspension no longer applies.
10 Remuneration and payment
- The customer pays Droova a monthly basic fee for using the Platform, which depends on the package booked and is specified in the Order Form.
- The basic fee consists of the amount per employee specified on the website multiplied by the number of employees registered on the Platform.
- The due date for the service and the first invoice for the basic fee is determined by the date at which the company signs up, regardless of whether this is also the actual start date.
- The customer assumes all applicable fees, charges, and costs incurred through the chosen payment method (including SEPA direct debit, bank transfer, credit card, or third-party payment services), in particular chargeback and processing fees. In the event of repeated chargebacks, Droova reserves the right to change the payment method.
- Invoices are issued monthly and all invoiced amounts are due within fourteen (14) days of receipt.
- All amounts are net amounts plus applicable VAT at the statutory rate (where applicable).
11 Warranty
- Droova provides a guarantee for free services in accordance with legal regulations.
- Droova shall not be liable for defects in the provision of the SaaS services beyond the following provisions.
- If the services are defective, Droova will, within a reasonable period after receiving written or electronic notice of defects, either rectify the defects or provide them again, at its discretion. For third-party software licensed for the customer's use, rectification consists of obtaining and installing generally available upgrades, updates, or patches. Providing user instructions enabling the customer to reasonably circumvent a defect also constitutes rectification.
- The customer shall notify Droova immediately of any defects in writing or electronically. The notice must contain all information necessary for Droova to identify, reproduce, analyse, and remedy the defect, and the customer shall provide reasonable assistance free of charge.
- The limitations of liability in Section 12 apply to the customer's claims for damages.
12 Compensation and liability
- Droova is liable for free services in accordance with legal regulations.
- Liability is excluded in cases of slight negligence in the breach of non-essential contractual obligations (non-cardinal obligations). Liability for damages due to data loss is limited.
- The limitations of liability apply accordingly in favour of Droova's legal representatives, employees, agents and vicarious agents.
- Any liability of Droova for given guarantees (expressly designated as such) and for claims under the Product Liability Act remains unaffected.
- Claims arising from SLA violations are not part of this liability clause and are regulated under Section 4.
- Any further liability of Droova is excluded.
13 Data protection
Data submitted through the Services will be processed in accordance with the Droova Data Processing Addendum (“DPA”), which is incorporated into these Terms as Annex 1.
14 Data portability and data export
The customer has the right to export all data provided by it or generated for it during the term of the agreement in a structured, commonly used, and machine-readable format.
15 Term and termination
- The parties agree on the sign-up date as the start date of this contract. All contractually agreed payment obligations commence on the start date. This date may, but need not, differ from the actual implementation date of the Platform and is not dependent on it.
- Droova may terminate the contract without stating reasons with one (1) month's notice. The right to terminate for cause remains unaffected. For Droova, cause exists in particular where the customer is in default of payment of agreed fees for more than four (4) weeks, or of two consecutive payments due, or of a substantial portion of the agreed fees, and Droova has threatened termination in text or written form with a two (2) week notice period.
- If the contract is not terminated in due time before the expiry of the term agreed in the Order Form, the term will automatically extend by the term agreed in the Order Form.
- Upon termination for any reason, Droova will delete the customer's content. Droova is entitled, but not obligated, to retain content for security reasons for four (4) weeks to protect the customer from accidental data loss, during which the DPA in Annex 1 remains in effect. The customer is responsible for downloading content during this period. Droova may also retain content where legally, judicially, or officially obligated (in particular for commercial and tax-law reasons), or where required for accounting, documentation, and billing purposes.
16 Changes to this contract
Droova may amend these terms with future effect to the extent necessary (i) to implement amended legal requirements, official orders, or case law; (ii) to implement amended technical requirements; (iii) to maintain the operation of Droova's services; (iv) to adapt to changed market conditions; or (v) to the customer's advantage. Amendments will only be made to the extent that they do not shift the contractual balance to the customer's detriment; amendments to a primary contractual obligation are excluded.
Droova will inform the customer of any amendment at least six (6) weeks in advance by written or electronic notification or within the Droova Dashboard. The customer may object. If the customer does not object within six (6) weeks of receiving the notification, consent will be deemed given. Droova will separately inform the customer, in the notification, about the six-week period, the legal consequences of remaining silent, and the effective date of the amendment.
17 Final provisions
- Amendments and supplementary agreements to this contract must be in writing. This also applies to this written-form clause.
- The contract language is English. Translations into other languages are for informational purposes only and are not legally binding.
- Should any provision of this agreement be invalid, this shall not affect the validity of the remaining provisions. The parties shall endeavour to replace the invalid provision with a valid provision that most closely reflects its economic intent.
- The law of the United Kingdom applies, excluding the UN Convention on Contracts for the International Sale of Goods.
- The exclusive place of jurisdiction for all disputes arising from or in connection with this contract is London.
Annex 1 — Data Processing Agreement (“DPA”)
Agreement on the processing of personal data within the meaning of Article 28(3) of Regulation (EU) 2016/679 (GDPR). [Standard Contractual Clauses]
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Droova Commercial Terms of Service or other agreement between Customer and Droova that references this DPA and governs Customer's use of the Services (the “Agreement”), and applies to Droova's processing of Customer Data. Capitalised terms used but not otherwise defined in this DPA have the meaning set forth in the Agreement. Droova may amend this DPA from time to time on reasonable notice where changes are required due to changes in Applicable Data Protection Laws. If there is any conflict between this DPA and the Agreement, the conflicting terms in this DPA will govern.
Section I — Clause 1: Purpose and scope
These standard contractual clauses ("clauses") are intended to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679. The controllers and processors listed in Annex I have agreed to these clauses to ensure such compliance. These clauses apply to the processing of personal data in accordance with Annex II, and Annexes I to IV form part of the clauses. They apply without prejudice to the obligations to which the controller is subject under the Regulation, and alone do not ensure compliance with international-transfer obligations under Chapter V.
Clause 2: Irrevocability of the clauses
The parties agree not to amend the clauses, except to supplement or update the information in the annexes. This does not prevent the parties from incorporating the clauses into a more comprehensive contract or adding further clauses or guarantees, provided they do not contradict the clauses or infringe the fundamental rights of data subjects.
Clause 3: Interpretation
Terms defined in Regulation (EU) 2016/679 have the same meaning here. The clauses must be interpreted in light of the Regulation and not in a manner contrary to the rights and obligations it provides, or that infringes data subjects' fundamental rights.
Clause 4: Priority
In the event of any conflict between these clauses and related agreements between the parties, whether existing or entered into later, these clauses prevail.
Clause 5 (optional): Coupling clause
An entity that is not a party may, with the consent of all parties, accede to these clauses as a controller or processor by completing the annexes and signing Annex I. After signing, the acceding entity is treated as a party with the rights and obligations of a controller or processor as designated in Annex I. No rights or obligations apply for the period before accession.
Section II — Clause 6: Description of the processing
The details of the processing operations, in particular the categories of personal data and the purposes for which they are processed on behalf of the controller, are set out in Annex II.
Clause 7: Obligations of the parties
7.1 Instructions. The processor processes personal data only on documented instructions from the controller, unless required by Union or Member State law (in which case it informs the controller beforehand, unless prohibited on grounds of important public interest). The controller may issue further documented instructions at any time. The processor informs the controller without undue delay if it considers an instruction infringes the Regulation or applicable data-protection provisions.
7.2 Purpose limitation. The processor processes personal data only for the specific purpose(s) in Annex II, unless it receives further instructions.
7.3 Duration. Data is processed only for the duration specified in Annex II.
7.4 Security. The processor implements at least the technical and organisational measures in Annex III to protect against personal data breaches, considering the state of the art, costs, and the nature, scope, context and purposes of processing. Personnel are granted access only to the extent strictly necessary, under a duty of confidentiality.
7.5 Sensitive data. Where processing involves special-category data, the processor applies specific restrictions and/or additional safeguards.
7.6 Documentation and compliance. The parties must be able to demonstrate compliance. The processor handles the controller's requests regarding processing, provides information necessary to demonstrate compliance, and allows and contributes to reviews/audits at reasonable intervals or where there are indications of non-compliance. The controller may audit itself or via an independent auditor, including inspections of premises with reasonable notice. Information, including audit results, is provided to supervisory authorities on request.
7.7 Use of sub-processors. The processor has the controller's general written authorisation to engage sub-processors on an agreed list, with at least 30 days' advance notice of additions or replacements so the controller may object. Sub-processor engagements must impose essentially the same data-protection obligations by contract; the processor remains fully liable to the controller for sub-processor performance, provides copies of sub-processing agreements on request (redacting confidential information), and agrees a third-party-beneficiary clause allowing the controller to terminate and instruct deletion/return where the processor ceases to exist or becomes insolvent.
7.8 International data transfers. Transfers to a third country or international organisation occur only on the controller's documented instructions or to comply with Union/Member State law, and must comply with Chapter V of the Regulation. Where a sub-processor's processing involves a transfer, the processor and sub-processor may ensure compliance using the Commission's standard contractual clauses, provided the conditions for their application are met.
Clause 8: Assistance to the controller
The processor informs the controller without undue delay of any data-subject request and does not respond itself unless authorised. Taking into account the nature of processing, it assists the controller in responding to data-subject requests, and also assists with data-protection impact assessments, prior consultation with supervisory authorities, keeping data accurate and up to date, and obligations under Article 32. The scope of such assistance is specified in Annex III.
Clause 9: Personal data breaches
In the event of a breach, the processor cooperates with and assists the controller to comply with Articles 33 and 34. For breaches of data processed by the controller (9.1), the processor assists with notification to the supervisory authority and affected data subjects, and with obtaining the required information (nature of the breach, likely consequences, and remedial/mitigating measures). For breaches of data processed by the processor (9.2), the processor notifies the controller immediately on becoming aware, providing the nature of the breach, a contact point, likely consequences, and measures taken or proposed — supplying available information first and further details without undue delay. Additional information requirements are specified in Annex III.
Section III — Clause 10: Non-compliance and termination
If the processor fails to comply, the controller may instruct it to suspend processing until compliance is restored or the contract is terminated. The processor informs the controller without undue delay if it cannot comply. The controller may terminate (insofar as the contract concerns processing under these clauses) where suspension has not been remedied within one month, where the processor breaches the clauses significantly or persistently, or where it fails to comply with a binding decision of a competent court or authority. The processor may terminate where the controller insists on instructions that violate applicable legal requirements after being informed. On termination, the processor — at the controller's option — deletes or returns all personal data and deletes existing copies, unless storage is required by law, continuing to ensure compliance until deletion or return.
Annex II — Description of processing
Categories of data subjects
Employees of the Customer.
Categories of personal data processed
- Account & identity — name, work email, profile photo, organisation, job title, team.
- Authentication — OAuth tokens, IP, device/browser, login timestamps, MFA metadata.
- Communications content — meeting transcripts/summaries, email subject + body, chat messages, attachments, from connected channels.
- Communications metadata — sender/recipient addresses, timestamps, thread IDs, CC/BCC, read status.
- Calendar — event titles, descriptions, times, locations, invitees, RSVP status.
- Meeting participants — attendee names, speaker attribution, third parties referenced.
- Derived data — extracted tasks, owners, due dates, priorities, status, confidence scores, tags, workload metrics.
- Usage — pages, features, click/edit events, in-app search, feedback, timestamps.
- Audit logs — per-extraction record of source, prompt version, model, output, confidence, user action.
- Support — ticket content, attachments, correspondence.
- Billing — billing contact, address, VAT ID, plan, seats. Card data handled by Stripe, not stored by Droova.
- Special categories (incidental) — Article 9 data may appear in user-generated content; Customer remains Controller.
- Third-party data — non-users named in communications, processed solely on Customer's behalf.
- Customer-provided LLM API keys — OpenAI credentials supplied by the Customer, stored encrypted at rest and used solely to invoke inference on the Customer's behalf.
Where sensitive data is processed, specific restrictions and/or additional safeguards are applied that take into account the nature of the data and the associated risks (e.g., strict purpose limitation, access restrictions including access only for specially trained employees, access logging, restrictions on onward transfers, or additional security measures).
Type of processing
- Collection / ingestion — read the Customer's connected meeting summaries, emails, calendar events and chat messages via authorised APIs.
- Storage — persist source materials and derived data in encrypted databases hosted in the EU and US regions, per the Customer's selection.
- Organisation & structuring — parse unstructured communications into structured task records (owner, due date, project, status, evidence).
- AI inference — invoke large language models to extract, classify, prioritise, deduplicate, and lifecycle-manage tasks.
- Transmission to sub-processors — send necessary inputs to OpenAI and other named sub-processors strictly for the inference above; outputs returned to Droova.
- Display & retrieval — present tasks, evidence quotes, team views and analytics to authorised users.
- Logging — record each extraction with prompt version, model, confidence, output and user action for accuracy measurement and debugging.
- Aggregation & anonymisation — derive team-level workload and activity metrics; produce aggregated, non-identifying statistics for product analytics.
- Retention & deletion — store personal data for the duration of the contract; delete or return on termination per Customer instruction, subject to legal-hold obligations.
- Restriction & rectification — execute Customer or data-subject requests to access, correct, restrict, port or erase personal data.
Processing time
Active subscription — personal data is processed for the duration of the Master Services Agreement between Droova and the Customer.
Annex III — Technical and organisational measures
Including measures to ensure data security.
- Anonymisation of personal data — measures to block/delete data on request across all systems.
- Pseudonymisation of personal data — no unencrypted password list is kept.
- User authentication (e.g., username & password).
- Password policy / system-enforced password requirements.
- Password complexity (at least 3 of 4: uppercase, lowercase, special characters, numbers).
- Minimum password length of 8 characters.
- Time-based password changes where applicable (otherwise event-based).
- Two-factor authentication (2FA).
- System access blocked after a defined number of incorrect login attempts.
- Group-wide auto-logout after a defined time.
- Role-based authorisation management.
- Obligation to maintain confidentiality / duty of secrecy.
- Written policy on handling electronic devices or BYOD.
- Written policy on handling personal data (e.g., Clean Desk).
- Need-to-know / Principle of Least Privilege implemented.
- Regular data-protection training.
- Encryption for critical data during transmission.
- VPN tunnel to the database.
- Data-backup concept including regular backups.
- Backup concept evaluated (regular testing and adjustment).
- Secure storage of backups (e.g., different fire compartment, in the cloud).
- Disaster Recovery Plan (DRP) / emergency plan.
- DRP evaluated (regular testing and adjustment).
- Network monitoring / Intrusion Detection System (IDS/IPS).
- Change management.
- Data-protection management system.
- Updates, patch and vulnerability management.
- Procedures for regularly reviewing and evaluating the effectiveness of the measures.
- Stress tests.
- Operation ensured during power disruption (e.g., UPS, emergency generator).
- Redundant design of all important systems.
- RAID system.
- Fire protection in the server room.
- Protection against server overheating (e.g., air conditioning).
- Contractor selection based on due-diligence criteria (certifications, references, etc.).
- Written rules for disposal/reuse of data carriers and files, or use of a certified disposal provider.
- Rules for external personnel (e.g., remote maintenance or cleaning staff) with contact to personal data.
- Virus protection / anti-malware.
- Logging of access attempts to IT systems.
- Logging of activities on the server.
- Logging of processing operations (entry, modification, deletion).
- Monitoring of data processing by external parties (e.g., during remote maintenance, via log files).
- Separation of Wi-Fi into private and public.
- Separation into testing, production, and development levels.
- Separation of data processing (logical or physical), multi-tenancy.
- Appropriate processes/guidelines to ensure the rights of data subjects.
Annex IV — List of subcontractors
The controller has authorised the use of the following sub-processors:
| Name / Company | Address / Country | (Partial) service | Server location |
|---|---|---|---|
| Google Ireland Limited | Gordon House, Barrow Street, Dublin 4, Ireland | Processing of message and usage data for the provision of email & chat functions | EU |
| HubSpot | 25 First Street, 2nd Floor, Cambridge, MA 02141, USA | Managing customer and prospect data for sales and marketing | US |
| DigitalOcean | 105 Edgeview Drive, Suite 425, Broomfield, Colorado, 80021, USA | Cloud deployment infrastructure | EU / USA (Frankfurt am Main, Germany & USA) |
| Slack (Slack Technologies Limited) | Salesforce Tower, 60 R801, North Dock, Dublin, Ireland | Processing of message and usage data for the provision of chat functions | EU |
Questions about these Terms? Contact contact@droova.ai.
© Droova, Limited · Version 2026-06-15 · See also our Privacy Policy.