Skip to content
COLLAPY— home
FeaturesPricingDownloadDocs
Sign inStart free
// legal

Data Processing Agreement

Last updated: 11 October 2026

This Data Processing Agreement (“DPA”) applies when an organization uses Collapy — the website at collapy.com, the app at app.collapy.com, the documentation at docs.collapy.com and the Collapy API at api.collapy.com (together, the “Service”) — to process personal data on its own behalf. It sets out the terms required by Article 28 of the EU General Data Protection Regulation (GDPR) and forms part of our Terms of Service (the “Terms”). Words such as “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meaning given to them in the GDPR.

How this DPA is concluded: it applies automatically to every organization that uses the Service under the Terms, without a separate signature. If you need a signed copy, write to support@collapy.com.

1. Parties and scope

1.1 The Customer is the company or other organization that uses the Service under the Terms, represented in the Service by the Owners of its Collapy organization. For the personal data covered by this DPA the Customer is the controller.

1.2 The Processor is the operator of Collapy (“we”, “us”):

Company
Corp42 s.r.o.
Registered office
Petrkov 24, 580 01 Lípa, Czech Republic
Company ID (IČO)
21440808
Registration
Commercial Register kept by the Regional Court in Hradec Králové (Krajský soud v Hradci Králové), file no. C 52743
Managing director
Jan Prokeš
Email
support@collapy.com

1.3 This DPA covers personal data that we process on the Customer’s behalf while providing the Service to the Customer’s organization (“Customer Personal Data”): the content the Customer and its members put into the organization and its workspaces, the organization’s membership, roles and invitations, the execution history, change log and audit log of the organization, and the account data of the Customer’s members to the extent it is shown or used within the organization. Annex I describes it in detail.

1.4 This DPA does not cover data we process as a controller for our own purposes, as described in our Privacy Policy — for example creating and securing user accounts, signing users in, preventing abuse, answering support requests, billing and accounting, and meeting our legal obligations.

1.5 If the Customer is itself a processor acting for its own client, the Customer confirms that its client has authorized the Customer’s use of the Service, and we act as the Customer’s sub-processor under the same terms.

1.6 If this DPA and the Terms conflict on the processing of Customer Personal Data, this DPA prevails. The annexes are part of this DPA.

2. Subject matter, duration, nature and purpose

2.1 Subject matter. Providing the Service to the Customer under the Terms.

2.2 Duration. For as long as the Customer uses the Service, and afterwards until Customer Personal Data is deleted under section 10.

2.3 Nature. Hosting, storing, synchronizing and displaying workspace content to the members the Customer grants access; sending the HTTP requests the Customer’s members ask Collapy’s cloud to send and recording the result; importing collections and OpenAPI specifications, including fetching a synced workspace’s specification from the address the Customer configures; sending invitation and other transactional emails; enforcing access rights, plan limits and rate limits; keeping execution history, change log and audit log; and deleting data.

2.4 Purpose. Solely to provide, secure and support the Service for the Customer, as described in the Terms and this DPA.

3. The Customer’s responsibilities

3.1 The Customer is responsible for having a lawful basis for the personal data it puts into the Service and for informing the data subjects concerned.

3.2 The Customer decides what it stores and sends through the Service. The Service is not designed for special categories of personal data (GDPR Art. 9) or data on criminal convictions; the Customer should not store such data in requests, responses or variables unless it is necessary and lawful.

3.3 The Customer controls who can see its data by inviting members and assigning organization and workspace roles. Members of a workspace can see its execution history, including requests other members sent and the responses they received. Credentials should be kept in secret variables, which are stored separately and never shown in history.

3.4 Requests the Customer’s members send to third-party APIs go to the servers the Customer chooses. Those recipients are not our sub-processors; any disclosure or transfer of personal data to them is the Customer’s.

4. Our obligations

4.1 Instructions. We process Customer Personal Data only on the Customer’s documented instructions. The Terms, this DPA and the Customer’s use and configuration of the Service — for example inviting members, sending requests, setting up synced workspaces or deleting content — are the Customer’s complete instructions. Further instructions must be agreed in writing. If EU or Member State law requires us to process Customer Personal Data otherwise, we will tell the Customer before processing unless that law prohibits it.

4.2 We will tell the Customer without delay if, in our opinion, an instruction infringes the GDPR or other data-protection law.

4.3 No other use. We do not use Customer Personal Data for our own purposes, do not sell it and do not use it for advertising.

4.4 Confidentiality. Only people who need access to operate, secure or support the Service can access Customer Personal Data, and they are bound by confidentiality obligations.

4.5 Security. We implement the technical and organisational measures in Annex II, which are designed to meet GDPR Article 32. We may update them as the Service evolves, as long as the overall level of protection does not decrease.

4.6 Assistance. Taking into account the nature of the processing and the information available to us, we will reasonably assist the Customer with its obligations under GDPR Articles 32 to 36 — security, breach notification, data protection impact assessments and prior consultation of a supervisory authority.

5. Sub-processors

5.1 The Customer gives us general authorization to engage sub-processors. The sub-processors we use today are listed in Annex III.

5.2 We impose on each sub-processor, by contract, data-protection obligations that are in substance no less protective than this DPA. We remain responsible to the Customer for our sub-processors’ performance of their obligations, as GDPR Article 28(4) requires.

5.3 Changes. We will notify the Customer of any intended addition or replacement of a sub-processor at least 30 days before it starts processing Customer Personal Data, by email to the Owners of the Customer’s organization and by updating Annex III on this page.

5.4 Objections. The Customer may object to a change on reasonable data-protection grounds by writing to support@collapy.com within the notice period. We will try in good faith to resolve the objection. If we cannot, the Customer may stop using the affected part of the Service or close its organization.

5.5 Not sub-processors. Google and GitHub, when a user chooses to sign in with them, act as independent controllers under their own terms: they confirm the user’s identity to us at the user’s choice. The servers that receive requests sent from Collapy are chosen by the Customer (section 3.4).

6. International transfers

6.1 Customer Personal Data is stored and processed in the European Union — in Appwrite Cloud’s Frankfurt region, Germany.

6.2 We transfer Customer Personal Data outside the European Economic Area only where a sub-processor in Annex III does so, and only with appropriate safeguards under GDPR Chapter V: an adequacy decision (such as the EU–US Data Privacy Framework for certified recipients) or the European Commission’s standard contractual clauses (Decision (EU) 2021/914), together with any supplementary measures needed.

7. Data subject requests

7.1 Much of what data subjects can ask for, the Customer can do in the Service itself: members edit their own profile, Owners remove or disable members and change roles, and content and whole workspaces can be deleted.

7.2 If we receive a request from a data subject about Customer Personal Data, we will forward it to the Customer without undue delay and will not answer it ourselves, except to tell the data subject to contact the Customer.

7.3 Where the Customer cannot fulfil a request with the Service’s own functions — for example an export of data, which is not self-service yet — we will assist the Customer through support@collapy.com with appropriate technical and organisational measures, insofar as this is possible.

8. Personal data breaches

8.1 We will notify the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Customer Personal Data, by email to the Owners of the Customer’s organization.

8.2 The notification will describe, as far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Where we cannot provide all of this at once, we will provide it in phases without further undue delay.

8.3 We will take reasonable steps to contain the breach and limit its consequences, and will cooperate with the Customer’s own notification to the supervisory authority and data subjects. A notification is not an admission of fault or liability.

9. Retention during the term

9.1 Workspace content (collections, requests, environments, variables, test scenarios) is kept until the Customer deletes it or deletes the workspace.

9.2 Execution history, the change log, test results and the audit log are kept for a limited time or number of entries per organization, depending on the organization’s plan; older entries are removed automatically. The limits are set out in the Privacy Policy and on the pricing page.

9.3 When an organization moves to a smaller plan, automatic removal is paused for 30 days so the Customer can keep or export what it needs. After that, the new plan’s limits apply and older entries beyond them are removed.

10. Deletion and return

10.1 While it uses the Service, the Customer can delete Customer Personal Data itself. Deleting a workspace deletes everything in it — collections, requests, environments and their secret variables, execution history, change log, test scenarios and results. An organization can be deleted by its Owners once its workspaces are deleted.

10.2 Deleting a user account is not self-service yet. The user, or the Customer for its members, can ask at support@collapy.com, and we will delete the account and the personal data tied to it within 30 days.

10.3 At the end of the Customer’s use of the Service we will, at the Customer’s choice, return Customer Personal Data in a structured format where technically feasible, and then delete it within 30 days, unless EU or Member State law requires us to keep it. Copies in our hosting provider’s backups are removed as those backups expire.

11. Information and audits

11.1 On request we will make available the information necessary to demonstrate compliance with GDPR Article 28 — including this DPA, a description of our measures and, where our sub-processors publish them, their certifications or audit reports.

11.2 Where that information is not enough, or a supervisory authority requires it, we will allow and contribute to an audit by the Customer or an auditor it mandates who is bound by confidentiality. The Customer will give 30 days’ notice; audits take place during business hours, no more than once in 12 months unless a breach or an authority requires it, and in a way that does not compromise other customers’ data or the security of the Service. Each party bears its own costs of an audit.

12. Liability

Each party’s liability under this DPA is subject to the limitations in section 11 of the Terms, to the extent permitted by law. Nothing in this DPA limits the rights data subjects have under GDPR Article 82.

13. Term

This DPA applies for as long as we process Customer Personal Data. Obligations that by their nature should continue — such as confidentiality and deletion — survive its end.

14. Governing law and disputes

This DPA is governed by the laws of the Czech Republic, excluding its conflict-of-law rules, in the same way as the Terms. Disputes are decided by the courts competent according to our registered office in the Czech Republic.

15. Changes to this DPA

We may update this DPA, for example to reflect changes in law or in our sub-processors (section 5.3). The date at the top shows the current version. For material changes we will notify the Owners of the Customer’s organization by email or in the app at least 30 days before they take effect, as for the Terms. A change never lowers the level of protection of Customer Personal Data.

16. Contact

For anything related to this DPA or the processing of Customer Personal Data, write to support@collapy.com, or by post to Corp42 s.r.o., Petrkov 24, 580 01 Lípa, Czech Republic. We have not appointed a data protection officer; this address reaches the people who handle privacy requests.

Annex I — Details of the processing

ControllerThe Customer (section 1.1). Contact: the Owners of its Collapy organization.
Processor Corp42 s.r.o., Petrkov 24, 580 01 Lípa, Czech Republic, IČO 21440808 — support@collapy.com
Data subjects
  • The Customer’s users: members of its organization and workspaces, and people it invites.
  • Any other people whose personal data the Customer’s members put into the Service — for example in request URLs, headers, bodies, variables, or in the responses of the APIs they call (such as the Customer’s own customers or employees).
Personal data
  • Account data of members as used in the organization: name, email address, avatar image (optional), phone number (optional).
  • Membership: organization and workspace memberships, roles (such as Owner, Admin or Editor), disabled status, and invitations (the invitee’s email address).
  • Workspace content: collections, requests (URLs, parameters, path variables, headers, bodies, auth settings), environments and their variables, secret variables, test scenarios, and synced-workspace settings such as the specification URL.
  • Execution history: who sent a request and when, the request that went out and the response that came back, with typed credentials redacted and secret values masked before storage; test runs and their results.
  • Change log (Ultra plan): snapshots of saved requests with their author, with known credential fields redacted.
  • Audit log: the acting user, action, target and time of privileged organization actions, and where available the IP address and browser (user agent).
  • Technical data: IP addresses, device and browser information of sign-in sessions and requests to the Service, used for security, rate limiting and abuse prevention.
  • Billing data (paid plans billed through Stripe): billing contact, company name, address, VAT ID and payment details. These are entered and stored at Stripe; the Service keeps only Stripe’s reference IDs and the subscription status.
Special categories None intended. If the Customer puts such data into the Service (section 3.2), the measures in Annex II apply to it.
FrequencyContinuous, for as long as the Customer uses the Service.
Nature and purposeAs in sections 2.3 and 2.4.
RetentionAs in sections 9 and 10.
Sub-processorsAs in Annex III.

Annex II — Technical and organisational measures

Encryption

  • All traffic to collapy.com, app.collapy.com, docs.collapy.com and api.collapy.com is encrypted in transit (HTTPS/TLS).
  • In addition to the hosting provider’s storage protections, these fields are stored in encrypted database columns: request headers, bodies and auth settings; environment variable values and secret variable values; the request and response headers, bodies, parameters and auth settings kept in execution history; change-log snapshots; test assertion results; and synced-workspace error details.

Hosting and availability

  • The Service is hosted on Appwrite Cloud in Frankfurt, Germany (EU): database, authentication, file storage, server functions and the websites.
  • Backups and availability rely on the hosting provider’s infrastructure.

Access control and tenant isolation

  • Access is granted by organization and workspace roles. Users see only the organizations and workspaces they belong to; private items are visible only to their author.
  • Access rights on stored data are computed on the server from the data itself; the app and website cannot set them. Content shared into a workspace is only accepted from members of that workspace.
  • Organizations, memberships, invitations, roles, workspaces, plans and billing can only be changed through server functions that check the caller’s role. Disabled members lose read access straight away.
  • Privileged organization actions are recorded in an audit log.

Credentials and secrets

  • Secret variable values are stored separately from other variables, encrypted, and not displayed in the request editor. When a request is sent from the web app they are filled in on the server, and only if the sender can access the environment they belong to.
  • Typed credentials (bearer tokens, basic-auth passwords, API keys and credential headers such as Authorization or Cookie) are redacted, and secret values masked, before an execution or a change-log snapshot is stored.

Authentication

  • Passwords are stored only as salted hashes by the hosting provider.
  • Email verification, two-factor authentication (authenticator app, email code, recovery codes) and a list of active sessions that users can sign out of.

Cloud request execution

  • Requests sent from Collapy’s cloud, and synced-workspace specification downloads, are protected against server-side request forgery: private, loopback, link-local and cloud-metadata addresses are blocked, and the resolved address is pinned so DNS changes can’t redirect a request to them.
  • Per-user rate limits and monthly plan quotas limit abuse.

Data minimisation

  • No analytics, advertising or tracking cookies; one essential session cookie. Fonts are self-hosted.
  • Execution history, change log, test results and audit log are trimmed automatically per plan.
  • Card details are entered at Stripe and never reach our servers; incoming billing events from Stripe are verified by signature.

Organisational measures

  • Access to production systems is limited to the people who operate the Service, and deployments run through automated pipelines with scoped credentials.
  • Personal data breaches are handled as described in section 8.

Annex III — Sub-processors

Sub-processorPurposeLocation
Appwrite (Appwrite Cloud) Hosting of the Service: database, authentication, server functions (including cloud request execution), file storage, transactional email (verification, password reset, invitations) and the websites. All Customer Personal Data is stored here. Frankfurt, Germany (EU) — fra.cloud.appwrite.io
Stripe (Stripe Payments Europe, Ltd., Ireland) Payments, subscriptions, invoices and tax calculation — only for organizations on a paid plan billed through Stripe. EU and USA, under Stripe’s data-processing terms
Google WorkspaceOur support mailbox (support@collapy.com) — only when the Customer or its members email us. EU / per Google’s data-processing terms

Not listed because they are not sub-processors: Google and GitHub as sign-in providers, and the third-party APIs the Customer sends requests to (section 5.5).

© 2026 Corp42 s.r.o.
FeaturesPricingDownloadDocsTermsPrivacyDPAImprintsupport@collapy.com