1. Definitions
In this DPA the terms "personal data", "processing", "controller", "processor", "sub-processor", "data subject" carry the meanings from the GDPR (Regulation (EU) 2016/679) and the Ukrainian Law on Personal Data Protection.
2. Roles of the parties
The Customer (signatory or user of an enterprise account) is the controller of personal data processed through the Service.
Alvo is the processor — it processes personal data only on the Customer's instructions and to provide the Service under the Terms of Service.
3. Subject matter and scope
- Types of personal data: user identifiers (email, names), session parameters, audit events, request metadata, data the Customer voluntarily uploads to the workspace.
- Categories of data subjects: Customer's employees, representatives, persons authorized to access the Customer's account.
- Duration: while the Customer's account exists, plus 30 days after it is closed so the Customer can obtain a copy of its data.
- Nature and purpose: providing the decision-support Service, authentication, security, audit, and technical support.
4. Alvo's obligations as processor
- process personal data only on documented Customer instructions;
- ensure confidentiality of personnel with data access;
- implement technical and organizational security measures (section 6);
- engage sub-processors only under terms no less strict than this DPA;
- assist the Customer in responding to data-subject requests, public-authority inquiries, and DPIAs;
- notify of personal-data breaches within 72 hours of becoming aware;
- on Service termination, return or delete personal data at the Customer's choice.
5. Sub-processors
Alvo engages the sub-processors listed below to provide the Service. The Customer gives general consent to these engagements; we notify of additions at least 30 days before activation — the Customer may object and terminate the Service if the objection is reasonable.
| Sub-processor | Purpose | Region | Status | Data categories |
|---|---|---|---|---|
| DigitalOcean, LLC (DPA) | Application + database hosting (alvo-web, alvo-api, Postgres, Redis) | Germany (Frankfurt — fra1) | Active | all tenant data, session tokens, audit events |
| WorkOS, Inc. (DPA) | Identity, authentication, SSO, MFA, organization directory | United States (EU SCC in place) | Active | email, name, organization, MFA secrets |
| Resend, Inc. (DPA) | Transactional email delivery (welcome and account notices, demo-request notifications, emails you opt into) | United States (EU SCC in place) | Active | email address, message content, delivery metadata |
| Cloudflare, Inc. (DPA) | Authoritative DNS, reverse proxy / CDN / WAF, and edge TLS termination for alvo.energy / alvo.live | Global anycast edge network (including non-EU locations) | Active | IP addresses and DNS/HTTP request metadata, HTTP headers (including cookies), request and response content, cached public content and static assets |
Updated whenever a new sub-processor is engaged. Active sub-processors handle data today. The Service uses no payment provider: no payment is collected.
6. Technical and organizational measures (TOMs)
- TLS 1.2+ for data in transit: Cloudflare terminates edge TLS for alvo.energy / alvo.live; the connection to the Caddy origin is also protected by TLS;
- Server-side payload validation via zod schemas, no-store cache for API responses, rate limit 120 req/min per route/client fingerprint;
- Strong identity via WorkOS (MFA, SSO, SCIM support);
- API key secrets stored as SHA-256 hashes, soft-delete via revokedAt, lastUsedAt monitoring;
- Separate audit_events log scoped per tenant, durable in Postgres;
- Daily compressed Postgres dumps kept on the server for up to 14 days, plus a rolling off-server copy of the last 14 dumps held in Ukraine; automated alerting on a missed backup is still being set up;
- SSH access to the servers by key only, with password login disabled;
- Role model defined (owner/trader/analyst/risk/apiClient/auditor roles and 14 permissions); role enforcement is not yet switched on in the public deployment.
Security questions go to security@alvo.energy.
7. International data transfers
The primary data processing and storage environment is European Union (DigitalOcean — Frankfurt (fra1)). Some sub-processors are located in the United States (WorkOS, Resend) — these transfers are governed by EU Standard Contractual Clauses (controller-processor and processor-sub-processor modules) and supplementary technical measures (encryption at rest + in transit, data minimization).
Cloudflare also processes public-site HTTP traffic, including headers and request and response content, on its global edge network. This processing may occur outside the EU; the primary hosting region does not limit edge locations. Cloudflare's international transfer terms are set out in its DPA, linked from the sub-processor registry.
Database backups are also held in Ukraine — at the controller's place of registration.
Our sub-processors' SCCs are available on request at legal@alvo.energy. We do not yet hold an SCC set executed with a customer — and we do not claim otherwise.
8. Assistance with data-subject rights
Alvo helps the Customer respond to data-subject requests: on request to privacy@alvo.energy it provides a copy of the data in JSON or CSV, corrects it, or deletes the account together with its related data. There is no self-serve account deletion in the interface yet — we carry out deletion on written request.
Alvo's response time on a Customer assistance request — up to 10 business days. Direct data-subject requests are routed to the controller (Customer).
9. Personal-data breaches
Alvo notifies the Customer of a confirmed personal-data breach within 72 hours of becoming aware, with a description of the breach nature, affected data-subject categories and counts, response actions, and pre-mortem information to help the Customer fulfill its regulator-notification obligations.
10. Audit and reports
The Customer has the right to audit DPA compliance no more than once a year (excluding confirmed incidents) with 30 days' notice. Audits are at the Customer's expense and must not breach other customers' data confidentiality.
We do not yet hold any third-party security certification (such as SOC 2 or ISO 27001). On request we describe the measures in section 6 and answer security questionnaires.
11. Duration, termination, and data return
This DPA is in effect from the start of processing, while the Customer's account exists, and for 30 days after it is closed — until the personal data are fully deleted or returned.
After the account is closed the Customer has 30 days to request a copy of its data. After 30 days the data are deleted, except those required for legal compliance (minimum necessary scope, retention per law). Deleted data remain in backups until those backups are replaced in the normal rotation — normally up to 14 days.
12. Market-data sources (not sub-processors)
The Service reads public and licensed third-party market-data sources. These sources receive no Customer personal data — we only request their time series. The data stay under their providers' licences: Alvo claims no rights in them and attributes the source wherever the licence requires. Which of them are live right now is shown on /status.
- ENTSO-E Transparency Platform — European electricity-market data: cross-border flows, load, generation, and day-ahead prices
- Market Operator of Ukraine (OREE) — Ukrainian day-ahead (DAM) and intraday (IDM) market prices and volumes
- Ember — European wholesale electricity prices and carbon intensity (CC BY 4.0)
- Energy-Charts (Fraunhofer ISE) — day-ahead prices for selected EU zones — only where the source itself declares a CC BY 4.0 licence
- PSE — Raporty OSP (Polish transmission system operator) — Poland's market price of electricity (RCE) at 15-minute resolution — a reference for the Ukraine–Poland basis
- energy-map.info — licensed aggregator of Ukrainian market data, including Ukrenergo data; shown only as aggregated or derived values, with attribution
- JAO (Joint Allocation Office) — cross-border capacity auction results
- ENTSOG Transparency Platform — gas-transmission flows as context for power prices
- GIE AGSI+ (Gas Infrastructure Europe) — European gas-storage fullness as fuel-system context; not used as a price-forecast input
- National Bank of Ukraine (NBU) — official UAH/EUR and UAH/USD reference rates
- Open-Meteo — weather data for load and generation context
- ukrainealarm (api.ukrainealarm.com) — air-raid alert status
- Ukrenergo — public announcements of the transmission system operator
- Yasno — public power-outage schedules
- NEURC, Ukraine's energy regulator — official regulator publications — links to the original and derived status only
13. DPO and legal contacts
Privacy / DPO: privacy@alvo.energy
Legal: legal@alvo.energy
Address: вул. Святослава Хороброго 8, кв. 69, Київ 03151, Україна.
Write to us — we will agree and sign a DPA with a sub-processor list current as of the signature date. The template is ready; we do not yet hold a countersigned copy with SCCs, so we will sign it together with you rather than send you a finished one.
legal@alvo.energy