NoCodeBackend

Product details
rabenklangrabenklang
rabenklangPLUS
Sep 16, 2026

Q: GDPR

1. Do you provide a DPA
(Data Processing Agreement) that we can sign with NoCodeBackend?
This is essential for compliance with GDPR Art. 28 when processing
sensitive health data. If yes, is it specifically suitable for
mental health / therapy applications?
2. **Sub-processors**: Can you provide a transparent list of
sub-processors (e.g., payment processors, CDN, analytics,
monitoring services) that have access to our data? Where are
they located?
3. **Backup Storage & Residency**: You mentioned EU (Frankfurt)
for active databases — are backups and disaster recovery
copies also stored exclusively within the EU?
4. **Data Residency Guarantee**: Is there a contract clause
that guarantees data never leaves the Frankfurt region
(no transfers to US or non-EU servers)?
Thanks!

Founder Team
Riya_NoCodeBackend

Riya_NoCodeBackend

Sep 17, 2026

A: Hi there,

Thank you for reaching out! Here are the answers to your questions:

1. Do you provide a DPA
-Yes. We provide a legally binding Data Processing Addendum (DPA) compliant with GDPR Article 28 incorporating standard EU Standard Contractual Clauses (SCCs, Module 2: Controller-to-Processor). You can review it at https://nocodebackend.com/legal/dpa, and we can issue a counter-signed copy with a tamper-evident audit certificate via SignWell upon request.

Suitability for Mental Health / Therapy Data:
Mental health and clinical notes fall under Special Category Data (GDPR Art. 9):
NoCodeBackend acts strictly as your Data Processor (infrastructure provider) with isolated tenant schemas, TLS 1.3 in transit, and encrypted backups. As the Data Controller, you remain responsible for patient consent/clinical compliance. For sensitive clinical therapy notes, we strongly recommend implementing client- or field-level encryption before storing records in database columns.

2. Transparent Sub-processors Directory
Our live, searchable sub-processor directory with processing purposes, locations, and safeguards is available at:
👉 https://nocodebackend.com/legal/subprocessors

3. Backup Storage & Residency
Platform Disaster Recovery Backups (7-Day Retention): Our system automatically creates daily disaster recovery backups retained on a 7-day rolling cycle. For EU databases, these are hosted strictly within the EU region. These exist strictly for system-level disaster recovery and GDPR business continuity (not for end-user rollbacks).
Developer Snapshots (On-Demand Backup & 1-Click Restore): For user-controlled backups, you have the Snapshots feature in your dashboard. This allows you to capture an on-demand snapshot of your entire database at any point in time and restore/rewrite your database whenever you need. All snapshots you take are stored strictly within your selected EU data residency.

4. Data Residency Guarantee
Contractual Guarantee: In DPA Section 9 and Section 2, Clause 6, NoCodeBackend contractually guarantees that data stored in EU-designated database instances, user snapshots, and automated disaster recovery copies never leave the European Union (Frankfurt am Main, Germany / Cloudflare R2 EU). No transfers or replication to US or non-EU servers occur.

Share
Helpful?
0
Log in to join the conversation
Related questions
View product details