Data Processing Addendum

Last Updated & Effective Date: August 9, 2026

What this document is for

When you use FreelioPro, you upload personal data about your own clients — their names, email addresses, messages, feedback, and files. Data protection law treats you as the controller of that data and us as your processor. This Addendum is the contract that law requires between us. It applies automatically to every Freelancer account; no signature is needed. It forms part of our Terms of Service.

1. Parties, Scope and Structure

This Data Processing Addendum ("DPA") is entered into between Swift Byte Solutions (Private) Limited, Registration No. PV 00347854, of No:22/6A, Sri Sarananda Road, Hingurugamuwa, Badulla, Uva Province, Sri Lanka ("Processor", "Company", "we") and the FreelioPro account holder ("Controller", "you").

This DPA applies to our processing of Client Personal Data (defined below) in the course of providing the Service, and is incorporated into and forms part of the Terms of Service. It applies whether or not you are subject to the GDPR; where you are not, its provisions still describe how we handle your Clients' data.

In the event of a conflict, this DPA prevails over the Terms of Service in respect of the processing of Client Personal Data. The Standard Contractual Clauses referenced in Section 11 prevail over this DPA to the extent of any conflict.

2. Definitions

  • Client Personal Data: personal data relating to your clients or their personnel that you upload to, enter into, or generate through the Service, or that your clients submit through a portal you operate.
  • Data Protection Laws: all applicable laws relating to the processing of personal data, including the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, and the Sri Lanka Personal Data Protection Act No. 9 of 2022.
  • Controller, Processor, Sub-processor, Data Subject, Processing, Personal Data Breach, Supervisory Authority: as defined in the GDPR.
  • SCCs: the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.

3. Roles of the Parties

You are the Controller of Client Personal Data and we are your Processor. You determine the purposes and means of processing; we process Client Personal Data only as set out in this DPA, in the Terms of Service, and on your documented instructions.

Separately, we act as Controller in respect of your own Freelancer account data — your name, email, credentials, subscription status, and security logs relating to your account. That processing is governed by our Privacy Policy and is outside the scope of this DPA.

4. Our Obligations as Processor

We will:

  • Process Client Personal Data only for the purpose of providing, maintaining, and securing the Service, and only on your instructions. Your use of the Service constitutes your instruction to process Client Personal Data as necessary to operate the features you use.
  • Not use Client Personal Data for our own purposes, and in particular not sell it, share it for advertising, use it for profiling, or use it to develop or train machine-learning models.
  • Inform you if, in our opinion, an instruction you give infringes Data Protection Laws, and not be obliged to comply with such an instruction.
  • Ensure that any person authorized to process Client Personal Data on our behalf is subject to a duty of confidentiality, and limit access to those who need it to operate the Service.
  • Not proactively monitor, scan, or review the content of your files or portal messages. We access such content only where necessary to investigate a report, resolve a technical fault, enforce our Terms, or comply with a legal obligation.
  • Notify you if we receive a legally binding request from a public authority for Client Personal Data, unless prohibited from doing so by law, and challenge requests that appear unlawful or excessive.

5. Your Obligations as Controller

You are responsible for, and warrant that:

  • You have a valid legal basis for collecting Client Personal Data and for making it available to us for processing, and you have given your clients any notice or obtained any consent required by Data Protection Laws.
  • The Client Personal Data you upload is accurate, relevant, and limited to what is necessary for your projects.
  • You will not upload special-category personal data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation), criminal offence data, financial account or payment card data, or government identification numbers to the Service. The Service is not designed for, assessed for, or offered for such data.
  • You will not enter data relating to any person under 18 years of age.
  • You will respond to your clients' data subject requests, since you hold the relationship with them and we do not.
  • You will keep portal passcodes confidential, transmit them only to the intended recipient, choose a transmission channel appropriate to the sensitivity of the content, and regenerate a passcode promptly if you suspect it has been compromised. You acknowledge that we do not send passcodes and have no control over how you transmit them.
  • You will delete projects, files, and Client Personal Data that you no longer need, using the controls in the application.

6. Security Measures

We implement and maintain the technical and organizational measures described in Annex II below, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. We may update these measures provided the level of protection is not materially reduced.

7. Sub-processors

You give us general authorization to engage the Sub-processors listed in Annex III below. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.

We will notify you at least 30 days before adding or replacing a Sub-processor, by email to your account address or by notice within the Service. If you object on reasonable data protection grounds, you may notify us within that period; we will work with you in good faith to address the objection, and if we cannot, you may terminate your subscription without further charge and receive a pro-rata refund for any prepaid period remaining.

8. Data Subject Requests

The Service gives you direct access to Client Personal Data through your account, so that you can locate, correct, export, or delete records yourself in order to respond to a data subject request. Where a request requires a copy of the data, the Service lets you download a project's files, or all of them, as ZIP archives, and export the associated records as CSV, vCard and PDF.

If we receive a request directly from one of your clients, we will not respond to it substantively. We will inform them that we act as processor and refer them to you, and we will notify you of the request without undue delay. Where you cannot fulfil a request using the application's own controls, we will provide reasonable assistance at your request; we may charge for assistance that is disproportionate in scope.

We will also provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent these relate to our processing and the information is available to us.

9. Personal Data Breach

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Client Personal Data. Our notification will describe, so far as known at the time: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. We will supply further information as our investigation progresses.

As Controller, you are responsible for assessing whether the breach must be notified to a supervisory authority or to affected data subjects, and for making any such notification. Our notice to you is not an admission of fault or liability.

Notifications will be sent to the email address registered on your account. Keeping that address current is your responsibility.

10. Deletion and Return of Data

  • You may delete Client Personal Data at any time during the term using the deletion controls in the application. Deletion through the application is permanent and irreversible.
  • On termination or expiry of your subscription, you have 30 days to sign in and download your files, per project or in bulk from Account Settings. We do not compile or send copies of your data on request. After 30 days, all files stored in your account are permanently deleted. Other Client Personal Data - project records, Client names and email addresses, messages, and feedback - is retained so that your account remains usable on the free plan, and is deleted when you delete the project concerned or your account.
  • Where your account is terminated for breach of our Terms or Acceptable Use Policy, we may delete data immediately and without providing a download window.
  • Backups. Our server is snapshotted weekly. Deleted Client Personal Data may persist in the most recent snapshot for up to 7 days after deletion before being overwritten. We do not restore deleted data from snapshots at your request.
  • We may retain Client Personal Data for longer only where required by law, and in that case we will continue to protect it under this DPA and process it only for that purpose.

11. International Transfers

We are established in Sri Lanka and our infrastructure is located primarily in the United States, as set out in Annex III. Client Personal Data will therefore be transferred outside the European Economic Area and the United Kingdom.

Where you are subject to the GDPR or UK GDPR and no adequacy decision covers the transfer, the SCCs are hereby incorporated into this DPA by reference, on the following basis:

  • Module Two (controller to processor) applies, with you as data exporter and Company as data importer.
  • Clause 7 (docking clause) does not apply. In Clause 9, Option 2 (general written authorization for sub-processors) applies, with the 30-day notice period in Section 7 above.
  • In Clause 11, the optional independent dispute resolution language does not apply. In Clause 17, the SCCs are governed by the law of Ireland. In Clause 18(b), the courts of Ireland have jurisdiction.
  • Annexes I, II, and III below serve as Annexes I and II to the SCCs.
  • For UK transfers, the UK International Data Transfer Addendum to the SCCs applies, with Tables 1 to 3 completed by reference to this DPA and its Annexes, and the exporter selected as the party that may end the Addendum in Table 4.

Our supplementary measures for these transfers include encryption in transit, hashed credentials, and the practice of challenging and notifying you of any government access request, as described in Section 4.

12. Audits and Information

On your reasonable written request, and no more than once in any twelve-month period, we will provide information reasonably necessary to demonstrate our compliance with this DPA. Given the scale of our operation, we satisfy audit rights primarily by providing written responses and documentation rather than by hosting on-site inspections. Any on-site audit required by a supervisory authority will be conducted at your cost, on at least 30 days' notice, during business hours, without disrupting the Service or the confidentiality of other customers' data.

13. Liability

Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service. Nothing in this DPA limits any liability of either party to a data subject under Data Protection Laws.

14. Term and Changes

This DPA takes effect when you create a FreelioPro account and continues for as long as we process Client Personal Data on your behalf. We may update this DPA where necessary to reflect changes in law or in our processing; if a change is material we will give at least 30 days' notice by email or in the Service. Except where stated otherwise in this DPA, it is governed by the laws of Sri Lanka.

Annex I — Details of Processing

  • Subject matter: provision of the FreelioPro project management and client portal Service.
  • Duration: the term of your subscription, plus the retention periods in Section 10.
  • Nature and purpose: hosting, storage, transmission, display, organization, retrieval, and deletion of project data so that you can deliver work to and communicate with your clients.
  • Categories of data subjects: your clients, and individuals employed or engaged by your clients whom you invite to a portal.
  • Categories of personal data: names; email addresses; hashed portal passcodes; session tokens, IP addresses, and browser user-agent strings; message content, display names, and read receipts; revision feedback, submitted links, project ratings, and final feedback; files and deliverables uploaded by you or your clients, and any personal data contained within them; invoice activity timestamps; and portal access records comprising project identifier, project name, and the email address used to sign in.
  • Special-category data: none. Uploading such data is prohibited under Section 5.
  • Frequency: continuous, for the duration of the subscription.
  • Competent supervisory authority (SCCs Annex I.C): the supervisory authority of the EEA Member State in which you, as exporter, are established, or where you are not established in the EEA, the authority of the Member State in which your representative is established or where the relevant data subjects are located.

Annex II — Technical and Organizational Measures

  • Encryption in transit: all traffic to and from the Service is encrypted using TLS.
  • Credential protection: account passwords and portal passcodes are stored only as cryptographic hashes and cannot be recovered or disclosed by us once set.
  • Access control and isolation: each project portal is isolated and its passcode grants access only to that single project. Administrative access to production systems is restricted to personnel who require it and is protected by authentication.
  • Session management: portal and account sessions expire and can be revoked. Expired and revoked session records are deleted.
  • Abuse resistance: rate limiting and lockout on repeated failed authentication and portal access attempts.
  • Logging and monitoring: authentication events and portal access events are logged for security review and retained for a maximum of 90 days.
  • Data minimization in analytics: usage analytics store no cookie and no raw IP address, using instead a salted, daily-rotating cryptographic hash that cannot be reversed or linked across days.
  • Resilience: weekly server snapshots retained by our hosting provider in the same region as the server.
  • Deletion: user-initiated deletion is permanent and takes effect immediately within the application. Two short-lived residuals apply: database records may persist in the weekly server snapshot described in Section 10, and a deleted file remains in object storage until an automated job confirms its removal - usually within minutes. Defined retention periods are applied to logs and analytics.
  • Sub-processor governance: a limited, published sub-processor list with 30 days' advance notice of change.
  • No secondary use: Client Personal Data is not sold, shared for advertising, profiled, or used to train machine-learning models. The Service integrates no artificial intelligence provider.

Annex III — Authorized Sub-processors

Sub-processorProcessing activityLocation
Hostinger International LtdVirtual private server hosting the application and database; weekly snapshotsUnited States (Boston)
Cloudflare, Inc.R2 object storage for uploaded files and deliverables; network and DNS servicesEastern North America (ENAM)
Brevo (Sendinblue SAS)Transactional email delivery (password resets, one-time codes, service notices)European Union
Lemon Squeezy, LLCMerchant of Record for subscription billing (Freelancer data only; no Client Personal Data)United States

Contact

  • Entity: Swift Byte Solutions (Private) Limited
  • Registration No: PV 00347854
  • Location: No:22/6A, Sri Sarananda Road, Hingurugamuwa, Badulla, Uva Province, Sri Lanka
  • Data Protection Contact: legal@freeliopro.com