Data Processing Addendum
Draft for review • Version 26 September 2026
Before this Addendum is used contractually, Luna must complete the subprocessor register in Annex 3 and verify that the security measures and retention commitments below match the production service. This draft is not a certification of GDPR compliance.
This Data Processing Addendum (DPA) sets out the terms on which LunaSites processes personal data on behalf of a customer under Article 28 of Regulation (EU) 2016/679 (GDPR). It forms part of the service agreement when incorporated into the agreement and accepted by the parties.
1. Parties and scope
The processor is DOBRICEAN IOAN-DORIAN PERSOANA FIZICA AUTORIZATA, trading as LunaSites (“Luna”), CUI 46952301, Trade Registry no. F06/336/2022, with registered office at ORS. NASAUD, STR. TUDOR VLADIMIRESCU, NR.22, Bistrita-Nasaud, ROMANIA. The customer is the person or entity identified in the service agreement or account billing records (“Customer”). Contact for this DPA: contact@lunasites.io.
This DPA covers personal data in Customer Content that Luna processes to provide the website builder, CMS, hosting, forms and related services on the Customer’s behalf (“Customer Personal Data”). The Customer acts as controller or, where acting for another controller, as a processor authorised to appoint Luna as a subprocessor. References to the Customer’s instructions include instructions it is authorised to give for that controller.
Luna’s independent-controller processing, including its own account administration, billing, marketing and necessary security or legal-compliance activities, is described in the Privacy Policy and is outside the processor scope of this DPA. A supplier used for Luna’s own billing, such as Stripe, is not automatically a subprocessor of Customer Personal Data.
2. Documented instructions and confidentiality
Luna shall process Customer Personal Data only on documented instructions from the Customer, including instructions concerning international transfers, unless Union or Member State law requires otherwise. Where legally permitted, Luna shall inform the Customer of that requirement before processing. Instructions include this DPA, the service agreement, authorised settings, support requests and actions by authorised users or connected clients. Luna shall immediately inform the Customer if, in its opinion, an instruction infringes applicable data-protection law and may suspend the affected processing while the issue is resolved.
Luna shall ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality and receive access only as necessary for their authorised tasks.
3. Customer responsibilities
The Customer is responsible for the lawfulness of its collection and instructions, the applicable legal basis, notices to data subjects, required consents, retention settings and the rights of the people whose data it submits. It shall configure access permissions and integrations appropriately and shall not instruct Luna to process data outside the agreed scope. The Customer shall inform Luna of processing requirements that materially affect the safeguards or assistance needed.
4. Security of processing
Taking account of the state of the art, implementation costs and the nature, scope, context, purposes and risks of processing, Luna shall implement appropriate technical and organisational measures under Article 32 GDPR. The agreed baseline is set out in Annex 2 and includes confidentiality, integrity, availability, resilience, restoration and regular evaluation of the measures. Luna may update measures provided that the overall level of protection is not reduced.
5. Data-subject requests and regulatory assistance
Taking account of the nature of the processing, Luna shall assist the Customer through appropriate technical and organisational measures, insofar as possible, in responding to requests under Chapter III GDPR. If Luna receives a request concerning Customer Personal Data, it shall promptly notify the Customer and shall not respond substantively except on the Customer’s instructions or where required by law. Requests may be sent to contact@lunasites.io with the relevant site or account identifier.
Taking account of the nature of processing and the information available to it, Luna shall assist the Customer with compliance with Articles 32–36 GDPR, including security, breach notifications, data-protection impact assessments and prior consultation with supervisory authorities. The Customer remains responsible for its own decisions and statutory deadlines.
6. Personal-data breaches
Luna shall notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. The notification shall describe, to the extent known, the nature of the breach, affected categories and approximate numbers of data subjects and records, a contact point, likely consequences, and measures taken or proposed to address and mitigate the breach. Information may be provided in phases without undue further delay. Luna shall take reasonable steps to contain and remedy the breach and assist the Customer with any required notifications. Notice shall not be delayed until an investigation is complete.
7. Subprocessors
Subject to completion of Annex 3 and the Customer’s acceptance of this DPA, the Customer gives general written authorisation for the listed subprocessors. Before adding or replacing a subprocessor, Luna shall give at least 30 days’ advance notice through the Customer’s account email or another agreed written channel, including sufficient information to assess the change. The Customer may object within that period on reasonable data-protection grounds. The parties shall seek an alternative; if no adequate solution is available, the affected processing shall not proceed with the proposed subprocessor for that Customer, and the Customer may terminate the affected service before the change takes effect.
Luna shall impose on each subprocessor, by contract, the same data-protection obligations as those set out in this DPA insofar as applicable to the delegated processing, including sufficient guarantees for appropriate technical and organisational measures. Luna remains fully liable to the Customer for the subprocessor’s performance of those obligations.
8. International transfers
Luna shall transfer Customer Personal Data outside the European Economic Area only on documented instructions and in accordance with Chapter V GDPR. Where applicable, a transfer shall rely on a valid adequacy decision or appropriate safeguards, such as the applicable module of the European Commission’s Standard Contractual Clauses, with required assessments and supplementary measures. This DPA does not itself execute Standard Contractual Clauses or establish that a particular transfer mechanism is in place. Relevant destinations and safeguards must be recorded in Annex 3 before the transfer.
9. AI clients and Luna MCP
Actions by a Customer-authorised AI client through Luna MCP are processed within its granted permissions and the Customer’s documented instructions. Luna does not use personal data, Customer Content, prompts or commands to train AI models. Disconnecting a client revokes its MCP access and tokens; it does not extend or erase the audit-log retention period. A third-party AI provider selected and contracted by the Customer is governed by the Customer’s arrangements with that provider. Any AI provider engaged by Luna to process Customer Personal Data on Luna’s behalf is subject to the subprocessor and transfer requirements of this DPA.
10. Duration, return and deletion
Processing continues for the duration of the services and the limited return or deletion period. At the Customer’s choice, Luna shall return or delete Customer Personal Data after the end of the services and delete existing copies unless Union or Member State law requires storage. The Customer may communicate its choice and obtain assistance with return or export at contact@lunasites.io. Lawful erasure instructions take precedence over optional recovery periods.
Customer Content and site data: up to 30 days for recovery after deletion or termination, unless the Customer instructs earlier deletion. Residual backup copies are removed within 90 days of the initial deletion or termination, not an additional 90 days after the recovery period. Copies pending expiry are isolated from ordinary use; deletion instructions must be reapplied if a backup is restored.
Form responses: 12 months from submission by default, subject to a different lawful and documented Customer instruction.
MCP tool and audit logs: 90 days from the event. Logs shall be minimised and avoid full prompts or Customer Content.
Technical and request logs: 30 days from collection; security logs: 90 days from collection.
Identifiable analytics data: 6 months from collection, followed by deletion or irreversible anonymisation.
Support messages and attachments: 12 months after closure of the request. Customer Personal Data within support materials remains subject to this DPA and applicable erasure instructions.
Customer newsletter records: subject to the Customer’s lawful instructions and opt-out requirements. The baseline is retention until withdrawal or objection, review after 24 months without interaction, and a minimal suppression record only for as long as necessary to honour an opt-out.
For processor data, retention beyond the agreed instructions is permitted only where required by Union or Member State law, with access restricted to the required purpose and deletion when that requirement ends. Luna’s separate controller records follow the Privacy Policy, including applicable Romanian accounting and tax retention periods. The controller exceptions in that policy do not authorise unrestricted retention of Customer Personal Data under this DPA.
11. Information and audits
Luna shall make available all information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. The parties shall coordinate reasonable notice, confidentiality and security arrangements to protect other customers’ data and service availability. Existing reports and documentation may be used where sufficient, without preventing an inspection where necessary. Coordination requirements shall not delay urgent investigations or a supervisory authority’s lawful access.
12. Contract terms and contact
This DPA prevails over conflicting service-agreement provisions concerning the processing of Customer Personal Data. Mandatory data-protection law and applicable Standard Contractual Clauses prevail over conflicting terms in this DPA. Nothing in this DPA restricts data subjects’ statutory rights or a supervisory authority’s powers. Changes to the agreed processing scope or material safeguards must be documented. Contact: contact@lunasites.io.
Annex 1 — Description of processing
Subject matter and purpose: providing the Customer’s websites, structured content, hosting, forms, collaboration and Customer-authorised integrations.
Nature of processing: collection on the Customer’s behalf, recording, organisation, storage, retrieval, display, publication as instructed, transmission, access management, support, export and deletion.
Duration: the service term plus the return and deletion periods in Section 10.
Data subjects: site visitors, form respondents, newsletter subscribers, the Customer’s users and collaborators, and individuals whose data the Customer includes in its content.
Types of data: names, contact details, form responses, newsletter preferences, uploaded content and files, user identifiers, IP addresses, device or usage information and related technical metadata, as determined by the Customer’s use of the service.
Sensitive data: special-category data and data about criminal convictions are outside the agreed scope unless separately agreed in writing with appropriate safeguards. The Customer must not intentionally submit such data under the standard service.
Controller rights and obligations: determining purposes and lawful instructions, ensuring transparency and legal bases, responding to rights requests, and exercising the rights set out in this DPA.
Annex 2 — Technical and organisational measures
The following measures define the contractual security baseline. Their actual implementation must be checked before this draft is adopted; no particular certification, hosting region or encryption-at-rest configuration is asserted here.
Access and confidentiality: individual authorised access, least-privilege permissions, authentication controls, prompt revocation of unnecessary access and confidentiality commitments.
Transmission and separation: encryption in transit, appropriate separation of customer environments and access controls preventing unauthorised cross-customer access.
Operational security: risk-based patching and vulnerability management, protection of credentials and secrets, and controlled changes to production systems.
Logging and incident response: proportionate security and audit logs, restricted log access, documented incident assessment and response, and notification procedures supporting Section 6.
Availability and recovery: backup and restoration procedures appropriate to the risk, protection of backup access, recovery testing and enforcement of the deletion periods in Section 10.
Data lifecycle and assurance: data minimisation, controlled export and deletion, subprocessor assessment, and regular testing, assessment and evaluation of the effectiveness of security measures.
Annex 3 — Subprocessor register
To be completed before contractual use. For each subprocessor, record its exact legal entity, service and purpose, categories of Customer Personal Data processed, processing and remote-access locations, and the applicable international-transfer mechanism and safeguards. A provider must not be treated as authorised solely because it appears in the Privacy Policy.
The current Privacy Policy identifies Vercel, Render, Google/Firebase and Bunny CDN as services requiring verification. These observations are not a verified subprocessor register and do not establish the contracting legal entities, data flows or locations. Stripe is identified as the payment processor; its role in Luna’s own billing must be distinguished from any processing it performs on behalf of Customers.