Data Processing Agreement
Last updated 3 October 2026
This agreement is part of the Terms of Service between Fairpage (Aleksandar Stevanovic PR, Milana Rakica 12, Belgrade, Serbia) and each site owner ("you"). It applies when Fairpage processes personal data for you as your processor, under the EU General Data Protection Regulation (GDPR), the UK GDPR and Serbia's Law on Personal Data Protection. It needs no signature; if you need a signed copy, write to [email protected].
1. Roles
You are the controller of personal data about your site's visitors and the people in your site's content. Fairpage is your processor for that data. Fairpage is the controller of account and billing data, as the Privacy Policy describes.
2. What we process
- Subject matter: hosting and running your site and its forms, content, media, analytics and AI features.
- Duration: while we provide Fairpage to you, and until the data is deleted under section 9.
- People concerned: your site's visitors, people who send your forms, and people whose details are in your content or media.
- Kinds of data: what visitors enter in your forms (such as names, email addresses and messages); analytics data (pages viewed, referrer, country, device type, browser and a daily-changing hash, without IP addresses); and any personal data in the content, rows and images you add.
- Purpose: only to provide Fairpage to you.
Do not use Fairpage for special categories of personal data (such as health data) or data about criminal offences.
3. Our obligations
We:
- process the data only on your documented instructions, which are these terms and your use and settings of Fairpage, unless the law requires otherwise, in which case we tell you first unless the law forbids it;
- make sure that anyone authorised to process the data is bound by confidentiality;
- apply the security measures in the annex;
- help you, as far as we reasonably can, to answer requests from people exercising their rights, and with security, breach notification, impact assessments and consultations with authorities;
- tell you about a personal data breach affecting your data without undue delay, and give you what we know so you can meet your own obligations;
- give you the information you need to show that we meet this agreement, and allow audits as in section 8.
4. Sub-processors
You authorise us to use the sub-processors on our sub-processor page. We bind each one to data protection obligations that are at least as protective as this agreement, and we remain responsible for them.
We announce a new sub-processor on that page and by email to site owners at least 14 days before it starts. You can object within that time on reasonable data protection grounds; if we cannot address the objection, you can end the affected plan and we refund its unused part through Polar.
5. Transfers
Fairpage is established in Serbia, and its main hosting is in the EU. Where a transfer of personal data from the EU, the EEA or the UK to Fairpage or to a sub-processor needs safeguards, the European Commission's standard contractual clauses (Decision 2021/914) apply and are made part of this agreement: module 2 between you and Fairpage, and module 3 between Fairpage and its sub-processors, with the UK Addendum for UK data. For those clauses, the optional docking clause does not apply, clause 9 uses option 2 with the notice period in section 4, clause 11 does not use the optional wording, and clauses 17 and 18 choose the law and courts of Ireland.
6. Your obligations
You make sure you have a lawful basis for the data you put into or collect through Fairpage, that your site tells visitors what it collects (a privacy notice), and that your instructions to us comply with the law.
7. Requests from people
If someone asks us directly about data we process for you, we pass the request to you and do not answer it ourselves unless you ask us to.
8. Audits
We answer reasonable written questions about our compliance. If that is not enough, you may audit us once a year, at your cost, with 30 days' notice, during business hours and under confidentiality, in a way that does not reveal other customers' data.
9. Deletion at the end
When your plan ends or you ask us to delete a site, you can export your data for 30 days. After that we delete it, unless the law requires us to keep it. Deleted data stays in backups until they expire, at most 90 days later.
10. Liability
The limits of liability in the Terms of Service apply to this agreement, except where the law does not allow them.
Annex: security measures
- All traffic to Fairpage and to sites is encrypted with TLS.
- Each site's content and form entries are in a separate database.
- Passwords are hashed with bcrypt; session, sign-in, invitation and reset tokens are stored only as hashes and expire.
- API keys for connected services are encrypted (AES-256 with an HMAC-SHA256 integrity check).
- Analytics store no IP addresses and no cookies; unique visitors are counted with a hash salted with a random value that is replaced and deleted every day.
- Sites' code is restricted: only components Fairpage compiles from the site's own files run on a site, under a content security policy, and drafts are visible only to the site's members.
- Outbound requests from our servers cannot reach private or internal networks.
- Access to production systems is limited to the operator.
- Servers are backed up; backups expire after at most 90 days.