Safe Pro Data Processing Agreement
Last updated: Version 1.0, effective 6 October 2026
If you would like to sign our Data Processing Agreement, please do so here.
This Data Processing Agreement ("Agreement") forms part of the Safe Pro Terms ("Terms") between the entity accepting the Terms ("Customer", the controller) and Safe Labs GmbH, Unter den Linden 10, 10117 Berlin, Germany ("Safe Labs", the processor). This Data Processing Agreement becomes effective from the date of signature of both parties.
(A) The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
(B) The Parties wish to lay down their rights and obligations.
(C) Customer Personal Data is not intended to include special categories of personal data (Art. 9 GDPR) or data relating to criminal convictions; Customers shall not enter such data into Safe Pro.
(D) Where Customer acts as processor for a third party, Customer warrants it is authorised to appoint Safe Labs as sub-processor and to give the instructions in this Agreement.
1. Definitions and Interpretation
Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meaning:
"Agreement" means this Data Processing Agreement and its Annexes A to C.
"Authorised User", "Safe Pro", "Service Descriptions", "Terms", and "Workspace" have the meanings given to them in the Terms.
"Customer Personal Data" means Personal Data that Safe Labs Processes on behalf of Customer under the Terms, as described in Annex A.
"Data Protection Laws" means the Data Protection Laws of the European Union, including, but not limited to the GDPR, and, to the extent applicable, the UK GDPR, the UK Data Protection Act 2018, the Swiss FADP, and the data protection or privacy laws of any other country applicable to the Processing under the Terms.
"EEA" means the European Economic Area.
"GDPR" means EU General Data Protection Regulation 2016/679.
"Subprocessor" means any person appointed by or on behalf of Safe Labs to process Personal Data on behalf of Safe Labs in connection with the Agreement.
The terms "Commission", "controller", "processor", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing", and "Supervisory Authority" shall have the same meaning as in the GDPR.
2. Subject Matter and Roles
The subject matter, nature, purpose, and duration of the processing, as well as the categories of Customer Personal Data and Data Subjects, are described in Annex A. Safe Labs shall carry out the processing on behalf of Customer as a processor.
3. Customer Obligations
Customer is responsible for the lawfulness of processing and for informing data subjects (Authorised Users, address-book contacts, persons named in notes); enters no special-category or children's data; ensures instructions comply with law; keeps Workspace administrator contacts current, with notices to those addresses deemed received; and supplies Art. 30(2) information on request.
4. Instructions
Customer's documented instructions are the Terms, this Agreement, and the settings Customer makes in Safe Pro. Safe Labs shall comply with all applicable Data Protection Laws in the Processing of Customer Personal Data; and shall not process Customer Personal Data other than on Customer's documented instructions. Where EU or Member State law requires other processing, Safe Labs informs customers beforehand unless the law prohibits it. Safe Labs shall immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
5. Confidentiality
Persons authorised to process Customer Personal Data have committed to confidentiality in writing or are under a statutory duty, act only on Safe Labs' instructions (Art. 29, 32(4) GDPR), have need-to-know access, and receive data protection training.
6. Security
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, Safe Labs shall in relation to the Customer Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk. A list of applicable measures is indicated in Annex B of this Agreement. Safe Labs may update Annex B provided the overall level of security is not reduced.
7. Personal Data Breach
Safe Labs shall notify Customer without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, to the e-mail address of Customer's Workspace administrators. The notification will include the information in Art. 33(3) GDPR as far as known, supplemented as it becomes available. Safe Labs does not notify authorities or Data Subjects on Customer's behalf unless instructed. Safe Labs shall cooperate with Customer and take reasonable commercial steps as are directed by Customer to assist in the investigation, mitigation and remediation of such Personal Data Breach.
8. Assistance and Prior Consultation
Safe Labs shall provide reasonable assistance to Customer with any data protection impact assessments, and prior consultations with Supervisory Authorities, which Customer reasonably considers to be required by Article 35 or 36 of the GDPR or equivalent provisions, solely in relation to Processing of Customer Personal Data. This assistance is free where provided through standard Safe Pro features and existing documentation; otherwise, it is subject to reasonable fees at current rates, unless caused by Safe Labs' breach.
9. Subprocessing
Customer hereby gives a general authorisation to involve Subprocessors to process Customer Personal Data under this Agreement. The current list of Subprocessors is in Annex C. Safe Labs will provide notice of any new Subprocessor by email to Workspace administrators and by updating the subprocessor list at a fixed URL at least 30 days in advance, providing Customer with the opportunity to object. On a reasonable objection not resolved within 30 days, Customer may terminate the affected subscription with a pro-rata refund. Safe Labs imposes data protection obligations equivalent to this Agreement on each Subprocessor by written contract and remains fully liable for their performance (Art. 28(4) GDPR).
10. International Transfers
Customer Personal Data is stored and processed in the EEA (AWS eu-central-1, Frankfurt). Safe Labs transfers Customer Personal Data outside the EEA only to the Subprocessors and for the purposes listed in Annex C, relying on the EU-US Data Privacy Framework where the recipient is certified and otherwise on the 2021 Standard Contractual Clauses (Module 3), with the UK Addendum and Swiss adaptations where applicable. The customer authorises these transfers by accepting this Agreement.
11. Audit Rights
Safe Labs shall make available to Customers on request all information necessary to demonstrate compliance with this Agreement. Audits and inspections shall be conducted as follows: information and documentation first; one audit per 12 months, 30 days' notice, business hours, at Customer's cost, maintaining confidentiality, with no access to other customers' data, and the auditor must not be a competitor and must be bound by an NDA. Additional audits are permitted only after a Personal Data Breach or on a Supervisory Authority's order. Safe Labs may satisfy the audit right with independent reports or certifications where available.
12. Deletion and Return
Customer may export Customer Personal Data in a machine-readable format at any time during the subscription and for 90 days after it ends (the Export Period). Within 30 days after the Export Period, or within 30 days of Customer's earlier written request, Safe Labs deletes Customer Personal Data from its production systems. Encrypted backups are overwritten on rotation within a further 35 days. Transaction notes submitted to the public Safe Transaction Service cannot be deleted. Data Safe Labs must retain by law is kept only for that purpose and then deleted.
13. Data Subject Rights
Safe Labs shall notify Customer within 5 business days of any request received directly from a Data Subject in respect of Customer Personal Data and shall not respond to that request except on the documented instructions of Customer. Customers can exercise most rights themselves through the Workspace administration functions.
14. Controller Processing
This Agreement does not apply to personal data Safe Labs processes as a controller: (a) account, authentication and security data of Authorised Users for their Safe{Wallet} and Safe Pro login, including via Safe Labs' identity provider; (b) Customer's billing and contract data; (c) usage, telemetry and security log data used to operate, secure, bill and improve Safe Pro; (d) data recorded on public blockchains; (e) communications to Safe Labs' support and sales channels. That processing is described in the Privacy Policy.
15. Term, Precedence, and Liability
Term and Survival: This Agreement is concluded when Customer accepts the Terms, including by checkbox at checkout, or signs this Agreement, whichever is earlier, and applies for as long as Safe Labs Processes Customer Personal Data. Sections covering Confidentiality, Deletion and Return, Audit (12 months), Governing Law, and Liability survive termination.
Precedence: The order of precedence is: SCCs where concluded, then this Agreement with Annexes, then the Terms. This supersedes prior data processing terms for Safe Pro; Customer templates do not apply unless Safe Labs agrees in writing.
Liability: Liability follows the exclusions and limits in the Terms, applied in aggregate across the Terms and this Agreement. There is no limit for intent, gross negligence, injury to life, body or health, or where law forbids. Article 82 GDPR liability towards data subjects is unaffected, with internal apportionment under Art. 82(5).
16. Final Provisions
Amendments: Safe Labs may amend this Agreement to reflect changes in law, authority or court decisions, Annex B, or Annex C with 30 days' notice to Workspace administrators; material reductions give Customer the objection and termination right in Section 9. Other changes need both Parties in text form.
Notices: Notices to Safe Labs regarding data protection should be sent to the privacy mailbox at Safe Labs. Notices to Customer will be sent to registered Workspace administrator e-mail addresses.
Governing Law and Jurisdiction: This Agreement is governed by the laws of the Federal Republic of Germany. Any dispute will be submitted to the exclusive jurisdiction of the courts of Berlin (Germany). If any provision is invalid, the remainder of the Agreement shall remain valid. English prevails over translations.
ANNEX A - Subject Matter of the Processing
Subject-matter of the processing: The provision of Safe Pro as described in the Terms. The nature and purpose of the processing activities is the processing of the data the Customer enters into Safe Pro as part of:
Creating and managing a user account (name, email address, authentication details)
Inviting and managing Authorised Users, including their roles and permissions
Adding and labelling Safe Accounts and wallet addresses
Creating and maintaining the shared address book (names, wallet addresses of counterparties)
Configuring notifications and communication preferences
Submitting support requests and other communications to Safe
Additionally Safe Pro generates records of the use made of the Customer's subscription, including:
Addition and removal of Safe Accounts and wallet addresses
Addition, removal and permission changes of Authorised Users
Transaction proposals, signatures and executions initiated through Safe Pro (including timestamps and the initiating user)
Login and session events (timestamps, IP address, device and browser information)
Audit logs of changes to the Customer's workspace settings
Technical logs, error reports and usage analytics
Billing and subscription records (plan, renewal dates, invoices)
Duration of the processing: For the term of the subscription plus the 90-day Export Period, then deletion under Section 12 (Deletion and Return).
Categories of data subjects:
Authorised Users
Individuals whose details the Customer or an authorised individual enters into Safe Pro
Counterparties named in the shared address book
Persons named in transaction notes
Categories of personal data:
Identity and contact: Name, e-mail address, Auth0 user identifier, Google sign-in profile where used
Wallet data: Signer wallet addresses linked to the account, Safe account addresses and chain IDs added to a workspace
Workspace data: Workspace name, membership, role, alias, invitation status, who invited whom
Shared address book: Counterparty blockchain address, label or name, chain IDs, and pending address-book requests
Activity Log: Event type, acting user, affected user, changed values (roles, names, address-book entries), timestamp
Communications: Invitation e-mails (name, e-mail, workspace name); content of support requests
Technical data: IP address, user agent, device and browser data, approximate location and timestamp access logs, identity-provider logs and browser telemetry
ANNEX B - Security Measures
Label | Description | Type |
|---|---|---|
Encryption at rest | The production database holding Customer Personal Data (PostgreSQL on Amazon RDS) is encrypted with AES-256 using AWS KMS keys with annual rotation. Object storage is server-side encrypted; workspace CSV exports use a dedicated KMS key and expire after 30 days. Backups are encrypted. | Technical |
Application-level field encryption | E-mail addresses, wallet addresses, member names and aliases, workspace names, Safe addresses added to a workspace, shared address-book entries and Activity Log payloads are additionally encrypted in the application with per-record AES-256-GCM data keys wrapped by a dedicated AWS KMS key and cryptographically bound to the owning workspace or user, so a record cannot be read outside its workspace. Look-ups use keyed blind indexes instead of plaintext. | Technical |
Encryption in transit | TLS 1.2 or higher is enforced at the edge (CloudFront security policy TLSv1.2_2021) and between services and the database (RDS certificate authority). | Technical |
Network security | Production runs in private VPC subnets in AWS eu-central-1. Databases are not publicly reachable. The Kubernetes API endpoint is restricted to two allow-listed addresses. AWS WAF protects the web app and the client gateway. VPC flow logs are retained 90 days. | Technical |
Access control | Staff access AWS through IAM Identity Center single sign-on with role-scoped permission sets (read-only and administrator). Multi-factor authentication is enforced on the identity provider (JumpCloud), on AWS accounts and on GitHub. Database access uses IAM authentication. | Technical and organisational |
Logging and monitoring | AWS CloudTrail organisation trail (all regions, KMS-encrypted, log-file validation), GuardDuty threat detection, AWS Config, Kubernetes control-plane audit logs, and centralised application and identity logs in Datadog (15 days searchable, 180 days encrypted archive) with alerting to an on-call rotation. | Technical |
Availability and backups | Multi-AZ database with deletion protection and automated daily encrypted backups retained 35 days. Infrastructure is defined as code. An Incident Response Plan is approved. | Technical and organisational |
Secure development | Every change to the client gateway goes through a pull request with mandatory review (one approval, code-owner review, approval of the last push), required tests, a CodeQL code-scanning gate, signed commits and linear history. Secret scanning with push protection is enabled. Container images are scanned in ECR. | Technical and organisational |
Endpoint security | Company devices are managed by JumpCloud MDM with enforced full-disk encryption (FileVault 2, BitLocker), screen lock, local firewall and managed OS updates, and run CrowdStrike Falcon endpoint detection. Credentials are held in 1Password. | Technical |
Tenant isolation | Workspace data is authorised per workspace and role in the gateway; the encryption context binding above prevents decrypting one workspace's data in another. | Technical |
Customer controls | Workspace two-factor authentication (authenticator app or passkey), roles and permissions, and self-service export and deletion of members and address-book entries. | Technical |
Policies | Approved and in force: Access Control, Asset Management, Incident Response Plan, Physical Security, Code of Conduct. | Organisational |
ANNEX C - List of Subprocessors
Purpose | Subprocessor | Processing Location | Transfer Mechanism | Customer Personal Data Involved |
|---|---|---|---|---|
Hosting, databases, backups, key management, invitation e-mail (SES), content delivery and WAF | Amazon Web Services EMEA SARL, Luxembourg (Amazon.com group, USA) | AWS region eu-central-1, Frankfurt, Germany. Content delivery through CloudFront edge locations in Europe, North America, Asia, the Middle East and Africa (Price Class 200); edge functions in us-east-1 | AWS GDPR Data Processing Addendum with SCCs; AWS is certified under the EU-US Data Privacy Framework | All Customer Personal Data listed in Annex A |
Workspace login (e-mail one-time code, Google sign-in), two-factor authentication, session tokens | Okta, Inc. (Auth0), USA | Auth0 EU region (tenant safe-prod.eu.auth0.com), Frankfurt, Germany, with Dublin, Ireland | Okta DPA with SCCs; EU-US DPF | E-mail address, name and profile from Google sign-in, IP address, user agent, MFA enrolment, login history |
Application logging, monitoring, security alerting, browser performance telemetry | Datadog, Inc., USA | Datadog EU site (EU1), Germany. Log archive stored in AWS Frankfurt (S3, 180 days) | Datadog DPA with SCCs; Datadog is certified under the EU-US DPF | IP address, request paths (include Safe and wallet addresses and workspace IDs), Auth0 login events including e-mail, browser and device data, approximate location; 15 days searchable, 180 days archived |
In-app support chat | Pylon Labs, Inc., USA | US (us-west-2) and EU (eu-central-1, Frankfurt) | Pylon DPA; SCCs or DPF | Content of support conversations, whatever the user types |
Support by e-mail and shared channel | Google Ireland Limited (Google Workspace); Slack Technologies Limited (Salesforce) | EU and USA | Google and Salesforce DPAs; both parents certified under the EU-US DPF | Content of support correspondence, sender name and e-mail |
Push notifications for Safe accounts held in a Workspace | Google LLC (Firebase Cloud Messaging) | USA and global | Google DPA with SCCs; DPF | Device token, notification content (Safe address, transaction summary) |