Legal disclosure

DPA & Processor Agreements

What a Data Processing Agreement (DPA) is, which processors Erfüllen uses, and how to verify EU Frankfurt hosting.

Last updated: 12 August 2026

What is a DPA?

A Data Processing Agreement (DPA) is a contract required under GDPR Article 28 when a processor handles personal data on behalf of a controller. In practice:

  • Your organization (controller) may need a DPA with Erfüllen when you store compliance and personal data in the platform.
  • Erfüllen (processor to you) maintains DPAs or equivalent terms with its own sub-processors — such as Supabase, Vercel, and Upstash.
  • DPAs define processing purpose, security measures, sub-processor rules, breach notification, and deletion obligations.

To request Erfüllen's customer DPA, contact hallo@erfuellen.com.

Erfüllen sub-processor register

The table below lists key processors and links to their vendor legal pages. Erfüllen verifies EU Frankfurt configuration for the primary vault providers listed in the EU stack.

ProcessorIn primary EU vaultVendor DPA / trust page
SupabaseYes — FrankfurtOpen vendor page
VercelYes — FrankfurtOpen vendor page
UpstashYes — FrankfurtOpen vendor page
Anthropic (Claude)No — feature-dependentOpen vendor page
Google (Gemini)No — feature-dependentOpen vendor page
ResendNo — feature-dependentOpen vendor page
RazorpayNo — feature-dependentOpen vendor page

EU Frankfurt verification checklist (12 August 2026)

Erfüllen verifies the following production settings for the primary compliance data plane. Enterprise customers may request attestation screenshots during security review.

CheckExpected valueWhere to verify
Supabase project regioneu-central-1 — Central EU (Frankfurt)Supabase Dashboard → Project Settings → General
Vercel function regionfra1 — Frankfurt, GermanyVercel Dashboard → Project Settings → Functions
Upstash Redis regionEU-CENTRAL-1Upstash Console → Redis database details

EU primary stack reference

ComponentProviderRegionRole
App + APIVercelfra1 (Frankfurt)Next.js, middleware, tRPC, auth routes, workers
Database + Auth + StorageSupabaseeu-central-1 (Frankfurt)Postgres, sessions, evidence files
Rate limitingUpstash RedisEU-CENTRAL-1Auth and contact rate limits

Audit package attestation

Each audit package export includes a Hosting Attestation — EU Frankfurt document summarizing this configuration for regulators and enterprise security reviews. See also the Data Residency Overview.