---
title: "Data Processing Addendum"
description: "Fohrkast's processor commitments for Shield and hosted compliance records under GDPR Article 28."
canonical: "https://fohrkast.com/dpa"
group: "Legal"
updated: "2026-06-28"
---
# Data Processing Addendum

Fohrkast acts as a data processor under GDPR Article 28 when customers use Shield and hosted compliance tools. This page outlines processor commitments, sub-processors, and data handling safeguards.

## Summary

This DPA summary applies when Fohrkast processes personal data for a customer as a processor under GDPR Article 28. The customer is the controller for its end-user consent records, hosted policy content, and website-compliance settings.

This page provides general information about Fohrkast's own operations. It is not legal advice.

## Processor Commitments

- Fohrkast processes customer personal data only to provide and secure the service, follow documented customer instructions, and meet legal duties.
- Fohrkast applies access controls, encryption in transit, EU-region hosting choices, audit logs, rate limits, and least-privilege operational access.
- Fohrkast assists customers with data-subject access requests, security incidents, deletion, export, and compliance information where required by GDPR.

## Sub-processors

Fohrkast uses the following sub-processors for hosting, database, AI document drafting, billing, and operational delivery:

- **Supabase**: EU-hosted Postgres, Auth, Storage, and Edge Functions in Frankfurt, Germany where configured.
- **Vercel**: Application hosting, edge delivery, logs, and deployment infrastructure in the fra1 region where configured.
- **Free AI providers** (Groq, Google Gemini, Cerebras, OpenRouter): AI document drafting and scan summaries using minimised and redacted prompt data, selected by automatic failover.
- **Lemon Squeezy**: Merchant of record for paid plans: checkout, subscriptions, invoices, customer portal, EU VAT and global tax, and payment processing. Operated by Sold Through Link, LLC (formerly Lemon Squeezy LLC), US-based; Standard Contractual Clauses apply for EEA transfers.
- **Sentry**: Application error monitoring and performance diagnostics, with personal data minimisation controls.

Fohrkast keeps sub-processor contracts, DPAs, and standard contractual clauses or equivalent transfer terms where needed.

## Transfer Safeguards

- Fohrkast tracks DPAs, standard contractual clauses, and equivalent safeguards for sub-processors that may process data outside the EEA.
- Fohrkast reviews sub-processors before adding them to production processing.

## Frequently Asked Questions

**What does it mean that Fohrkast is a processor?**
When you use Shield and hosted compliance records, Fohrkast processes personal data on your behalf as a processor under GDPR Article 28. You remain the controller for this data. Fohrkast must follow only your documented instructions and has specific obligations around security, assistance with data subject rights, and sub-processor management.

**Where is my data stored?**
Fohrkast uses EU-region hosting where configured through Supabase (Frankfurt, Germany) and Vercel (fra1 region). The company also documents transfer safeguards and standard contractual clauses for sub-processors that may process data outside the EEA.

**What happens if Fohrkast uses AI to draft documents?**
Before sending prompts to an AI provider, Fohrkast minimizes and redacts personal data where it is not needed for the task. AI output is general information, not legal advice. Customers remain responsible for reviewing their own published materials.

**Who are the sub-processors?**
Core sub-processors include Supabase (hosting), Vercel (application hosting), Lemon Squeezy (billing), free AI providers (document drafting), and Sentry (error monitoring). Fohrkast maintains data processing agreements and standard contractual clauses with sub-processors handling data outside the EEA.

**Does this DPA apply to all Fohrkast services?**
This DPA applies specifically to Shield and hosted compliance records where Fohrkast acts as a processor. For Fohrkast's own website and account data, Fohrkast is the controller; see the Privacy Policy for that scope.

## About Fohrkast

Fohrkast is an AI-first compliance and cookie-consent tool for EU websites. Operated by Abhinv Das (sole trader, Jagdalpur, India), Fohrkast provides Shield for website compliance and consent management, as well as free website scans and generated compliance documents.

---

**Document version:** fohrkast-dpa-2026-06-19  
**Effective:** 19 June 2026

This document is provided for transparency. It is not legal advice. For advice specific to your situation, consult a qualified professional.

---

Source: https://fohrkast.com/dpa
This is automated readiness information, not legal advice or a guarantee of conformance. Last reviewed 2026-06-28.
