Legal · v2026-09-01

Data Processing Agreement (DPA)

Last updated: 1 September 2026

1. Parties

This Data Processing Agreement (“DPA”) forms part of the Terms of Service / service agreement between the Customer (controller) and Idear.

Processor: FRANCISCO BARRUGUER GASCÓ, tax ID 53226439T, address AVDA. CAMÍ D'ONDA 16, 12530 BURRIANA, CASTELLÓN, ESPAÑA, contact estudio@pacobarruguer.com (“Idear” or the “Processor”).

Controller: the natural or legal person that contracts Idear and determines the purposes and means of processing personal data of its clients or other individuals through the Service (“Customer” or the “Controller”).

2. Subject matter and duration

The Processor will process personal data on behalf of the Customer solely to provide Idear.app: visual collaboration boards, asset storage, comments/review, forms/briefings when enabled, invitations, notifications, and AI tools requested by the Customer or its authorised users.

The processing lasts for the term of the Customer’s account / contract plus any additional time needed to return or delete data under this DPA.

3. Nature and purpose of processing

Nature: hosting, storage, transmission, display, backups, technical support, security, and processing by AI providers when the Customer uses those features.

Purpose: enable the Customer to collaborate on architecture/design projects and share materials with its team and end clients, as configured in the Service.

The Processor will not process the data for its own purposes unrelated to providing the Service, security, or legal compliance, nor to build marketing profiles of the Controller’s end clients.

4. Categories of data and data subjects

Data categories (depending on what the Customer submits): identity and contact data; images, renders, and project files; comments and feedback; form responses; technical metadata for shared-link access; and, if AI tools are used, inputs needed for generation.

Data subjects: the Customer’s end clients, collaborators, guests, employees, or other individuals whose data the Customer places in the Service.

The Customer must not submit special categories of data (GDPR Art. 9) or other high-risk data unless an adequate legal basis exists and Idear has agreed in writing.

5. Documented instructions

The Processor will process data only on the Customer’s documented instructions, which include: (a) this DPA; (b) the Terms of Service and Privacy Policy; (c) configuration and actions taken in the Service (permissions, sharing, deletion).

If the Processor believes an instruction infringes the GDPR or other law, it will inform the Customer and not carry it out, unless prohibited by law.

6. Confidentiality and personnel

The Processor will ensure that persons authorised to process the data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality, and receive reasonable data-protection training.

7. Security

The Processor will implement appropriate technical and organisational measures taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as risks to data subjects (access control, encryption in transit, reasonable logical segregation, monitoring, backups).

Operational detail may be described in security documentation Idear provides under confidentiality upon reasonable request.

8. Sub-processors

The Customer generally authorises use of sub-processors needed to operate the Service, including (indicative list aligned with the Privacy Policy): Render, Neon, Cloudflare (Pages/R2/Turnstile), Resend, Stripe (where processing touches entrusted data), OpenAI, PostHog, Sentry, Tally (forms when enabled), Telegram (if the Customer or users enable notifications), and fal.ai when the related AI feature is enabled.

Idear will impose essentially equivalent data-protection obligations on sub-processors. Idear will notify material sub-processor changes by reasonable means (e.g. Privacy Policy / sub-processor list update or in-app notice). The Customer may object on reasoned compliance grounds within a reasonable period; if no viable alternative exists, the Customer may terminate the affected Service.

9. Assistance with rights and impact assessments

Taking into account the nature of processing, the Processor will assist the Customer, insofar as possible, with appropriate technical and organisational measures so the Customer can respond to data-subject requests.

The Processor will also assist, where reasonably possible, with data-protection impact assessments and prior consultations with authorities, by providing available information about the Service.

10. Security incidents

The Processor will notify the Customer without undue delay after becoming aware of a personal-data breach affecting processing under this DPA, with available information so the Customer can meet its duties to notify the authority and, where required, data subjects.

Preferred incident contact: estudio@pacobarruguer.com.

11. Return and deletion

On termination of the Service or at the Customer’s request, the Processor will delete or return the entrusted personal data (and delete existing copies), unless Union or Member State law requires retention.

Export of content available in the UI or via reasonable support is the primary return mechanism. Backups may persist for a limited technical rotation cycle.

12. International transfers

If processing involves transfers outside the EEA, the Processor will ensure appropriate safeguards (e.g. standard contractual clauses) or that the recipient is covered by a valid mechanism.

NEEDS LEGAL REVIEW: location mapping and mechanisms per sub-processor before the definitive version.

13. Information and reasonable audit

The Processor will make available to the Customer the information needed to demonstrate compliance with GDPR Art. 28 obligations and will allow reasonable audits or inspections, with written notice, during business hours, without unduly disrupting operations, and under confidentiality. Idear may satisfy this obligation through security reports, questionnaires, or third-party certifications where available, instead of physical access to cloud-provider facilities.

14. Governing law

This DPA is governed by Spanish law, without prejudice to mandatory rules that may apply.. Except where mandatory law provides otherwise, For relationships with professionals or businesses, the courts of Castellón, Spain, unless mandatory law provides otherwise.

Document version: 2026-09-01. If this DPA conflicts with the Terms of Service on entrusted data protection, this DPA prevails.

Terms · Privacy · Cookies · Español