Legal disclosure
DPA & Processor Agreements
What a Data Processing Agreement (DPA) is, which processors Erfüllen uses, and how to verify EU Frankfurt hosting.
Last updated: 12 August 2026
What is a DPA?
A Data Processing Agreement (DPA) is a contract required under GDPR Article 28 when a processor handles personal data on behalf of a controller. In practice:
- Your organization (controller) may need a DPA with Erfüllen when you store compliance and personal data in the platform.
- Erfüllen (processor to you) maintains DPAs or equivalent terms with its own sub-processors — such as Supabase, Vercel, and Upstash.
- DPAs define processing purpose, security measures, sub-processor rules, breach notification, and deletion obligations.
To request Erfüllen's customer DPA, contact hallo@erfuellen.com.
Erfüllen sub-processor register
The table below lists key processors and links to their vendor legal pages. Erfüllen verifies EU Frankfurt configuration for the primary vault providers listed in the EU stack.
| Processor | In primary EU vault | Vendor DPA / trust page |
|---|---|---|
| Supabase | Yes — Frankfurt | Open vendor page |
| Vercel | Yes — Frankfurt | Open vendor page |
| Upstash | Yes — Frankfurt | Open vendor page |
| Anthropic (Claude) | No — feature-dependent | Open vendor page |
| Google (Gemini) | No — feature-dependent | Open vendor page |
| Resend | No — feature-dependent | Open vendor page |
| Razorpay | No — feature-dependent | Open vendor page |
EU Frankfurt verification checklist (12 August 2026)
Erfüllen verifies the following production settings for the primary compliance data plane. Enterprise customers may request attestation screenshots during security review.
| Check | Expected value | Where to verify |
|---|---|---|
| Supabase project region | eu-central-1 — Central EU (Frankfurt) | Supabase Dashboard → Project Settings → General |
| Vercel function region | fra1 — Frankfurt, Germany | Vercel Dashboard → Project Settings → Functions |
| Upstash Redis region | EU-CENTRAL-1 | Upstash Console → Redis database details |
EU primary stack reference
| Component | Provider | Region | Role |
|---|---|---|---|
| App + API | Vercel | fra1 (Frankfurt) | Next.js, middleware, tRPC, auth routes, workers |
| Database + Auth + Storage | Supabase | eu-central-1 (Frankfurt) | Postgres, sessions, evidence files |
| Rate limiting | Upstash Redis | EU-CENTRAL-1 | Auth and contact rate limits |
Audit package attestation
Each audit package export includes a Hosting Attestation — EU Frankfurt document summarizing this configuration for regulators and enterprise security reviews. See also the Data Residency Overview.