[{"data":1,"prerenderedAt":680},["ShallowReactive",2],{"navigation_docs":3,"-legal-data-processing-agreement":258,"-legal-data-processing-agreement-surround":675},[4,31,92,117,138,164,184,225,241],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":30},"Getting Started","i-lucide-rocket","\u002Fgetting-started","1.getting-started",[10,15,20,25],{"title":11,"path":12,"stem":13,"icon":14},"Basic Concepts","\u002Fgetting-started\u002Fconcepts","1.getting-started\u002F1.concepts","i-lucide-book-open",{"title":16,"path":17,"stem":18,"icon":19},"About Lucity","\u002Fgetting-started\u002Fabout","1.getting-started\u002F2.about","i-lucide-info",{"title":21,"path":22,"stem":23,"icon":24},"Self-Hosting","\u002Fgetting-started\u002Fself-hosting","1.getting-started\u002F3.self-hosting","i-lucide-server",{"title":26,"path":27,"stem":28,"icon":29},"Roadmap","\u002Fgetting-started\u002Froadmap","1.getting-started\u002F4.roadmap","i-lucide-map",false,{"title":32,"icon":33,"path":34,"stem":35,"children":36,"page":30},"Features","i-lucide-layers","\u002Ffeatures","2.features",[37,42,47,52,57,62,67,72,77,82,87],{"title":38,"path":39,"stem":40,"icon":41},"Projects","\u002Ffeatures\u002Fprojects","2.features\u002F1.projects","i-lucide-folder",{"title":43,"path":44,"stem":45,"icon":46},"Scaling","\u002Ffeatures\u002Fscaling","2.features\u002F10.scaling","i-lucide-scaling",{"title":48,"path":49,"stem":50,"icon":51},"Billing & Pricing","\u002Ffeatures\u002Fbilling","2.features\u002F11.billing","i-lucide-credit-card",{"title":53,"path":54,"stem":55,"icon":56},"Services","\u002Ffeatures\u002Fservices","2.features\u002F2.services","i-lucide-box",{"title":58,"path":59,"stem":60,"icon":61},"Environments","\u002Ffeatures\u002Fenvironments","2.features\u002F3.environments","i-lucide-git-branch-plus",{"title":63,"path":64,"stem":65,"icon":66},"Builds","\u002Ffeatures\u002Fbuilds","2.features\u002F4.builds","i-lucide-hammer",{"title":68,"path":69,"stem":70,"icon":71},"Deployments","\u002Ffeatures\u002Fdeployments","2.features\u002F5.deployments","i-lucide-upload",{"title":73,"path":74,"stem":75,"icon":76},"Promotion","\u002Ffeatures\u002Fpromotion","2.features\u002F6.promotion","i-lucide-arrow-right-left",{"title":78,"path":79,"stem":80,"icon":81},"GitHub Integration","\u002Ffeatures\u002Fgithub-integration","2.features\u002F7.github-integration","i-lucide-github",{"title":83,"path":84,"stem":85,"icon":86},"Eject","\u002Ffeatures\u002Feject","2.features\u002F8.eject","i-lucide-door-open",{"title":88,"path":89,"stem":90,"icon":91},"Environment Variables","\u002Ffeatures\u002Fvariables","2.features\u002F9.variables","i-lucide-variable",{"title":93,"icon":24,"path":94,"stem":95,"children":96,"page":30},"Infrastructure","\u002Finfrastructure","3.infrastructure",[97,102,107,112],{"title":98,"path":99,"stem":100,"icon":101},"Databases","\u002Finfrastructure\u002Fdatabases","3.infrastructure\u002F1.databases","i-lucide-database",{"title":103,"path":104,"stem":105,"icon":106},"Redis","\u002Finfrastructure\u002Fredis","3.infrastructure\u002F2.redis","i-lucide-zap",{"title":108,"path":109,"stem":110,"icon":111},"Cron Jobs","\u002Finfrastructure\u002Fcron-jobs","3.infrastructure\u002F3.cron-jobs","i-lucide-clock",{"title":113,"path":114,"stem":115,"icon":116},"Networking","\u002Finfrastructure\u002Fnetworking","3.infrastructure\u002F4.networking","i-lucide-network",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":30},"Architecture","i-lucide-workflow","\u002Farchitecture","4.architecture",[123,128,133],{"title":124,"path":125,"stem":126,"icon":127},"Philosophy","\u002Farchitecture\u002Fphilosophy","4.architecture\u002F1.philosophy","i-lucide-compass",{"title":129,"path":130,"stem":131,"icon":132},"How It Works","\u002Farchitecture\u002Fhow-it-works","4.architecture\u002F2.how-it-works","i-lucide-cpu",{"title":134,"path":135,"stem":136,"icon":137},"GitOps","\u002Farchitecture\u002Fgitops","4.architecture\u002F3.gitops","i-lucide-git-commit",{"title":139,"icon":140,"path":141,"stem":142,"children":143,"page":30},"Security","i-lucide-shield","\u002Fsecurity","5.security",[144,148,152,156,160],{"title":145,"path":146,"stem":147},"Overview","\u002Fsecurity\u002Foverview","5.security\u002F1.overview",{"title":149,"path":150,"stem":151},"Build Isolation","\u002Fsecurity\u002Fbuild-isolation","5.security\u002F2.build-isolation",{"title":153,"path":154,"stem":155},"Network Policies","\u002Fsecurity\u002Fnetwork-policies","5.security\u002F3.network-policies",{"title":157,"path":158,"stem":159},"Pod Security","\u002Fsecurity\u002Fpod-security","5.security\u002F4.pod-security",{"title":161,"path":162,"stem":163},"Registry Authentication","\u002Fsecurity\u002Fregistry-auth","5.security\u002F5.registry-auth",{"title":165,"icon":166,"path":167,"stem":168,"children":169,"page":30},"Use Cases","i-lucide-lightbulb","\u002Fuse-cases","6.use-cases",[170,175,179],{"title":171,"path":172,"stem":173,"icon":174},"Agencies","\u002Fuse-cases\u002Fagencies","6.use-cases\u002F1.agencies","i-lucide-building-2",{"title":176,"path":177,"stem":178,"icon":6},"Startups & Small Teams","\u002Fuse-cases\u002Fstartups","6.use-cases\u002F2.startups",{"title":180,"path":181,"stem":182,"icon":183},"Platform Teams","\u002Fuse-cases\u002Fplatform-teams","6.use-cases\u002F3.platform-teams","i-lucide-users",{"title":185,"icon":186,"path":187,"stem":188,"children":189,"page":30},"Comparisons","i-lucide-scale","\u002Fcomparisons","7.comparisons",[190,195,200,205,210,215,220],{"title":191,"path":192,"stem":193,"icon":194},"PaaS Comparison: Lucity vs Railway, Render, Heroku, Fly.io, Coolify","\u002Fcomparisons\u002Foverview","7.comparisons\u002F1.overview","i-lucide-table",{"title":196,"path":197,"stem":198,"icon":199},"vs Railway","\u002Fcomparisons\u002Fvs-railway","7.comparisons\u002F2.vs-railway","i-lucide-train",{"title":201,"path":202,"stem":203,"icon":204},"vs Render","\u002Fcomparisons\u002Fvs-render","7.comparisons\u002F3.vs-render","i-lucide-layout-template",{"title":206,"path":207,"stem":208,"icon":209},"vs Heroku","\u002Fcomparisons\u002Fvs-heroku","7.comparisons\u002F4.vs-heroku","i-lucide-cloud",{"title":211,"path":212,"stem":213,"icon":214},"vs Vercel","\u002Fcomparisons\u002Fvs-vercel","7.comparisons\u002F5.vs-vercel","i-lucide-triangle",{"title":216,"path":217,"stem":218,"icon":219},"vs Fly.io","\u002Fcomparisons\u002Fvs-fly-io","7.comparisons\u002F6.vs-fly-io","i-lucide-plane",{"title":221,"path":222,"stem":223,"icon":224},"vs Coolify","\u002Fcomparisons\u002Fvs-coolify","7.comparisons\u002F7.vs-coolify","i-lucide-snowflake",{"title":226,"icon":227,"path":228,"stem":229,"children":230},"Changelog","i-lucide-scroll-text","\u002Fchangelog","8.changelog",[231,233,237],{"title":226,"path":228,"stem":232},"8.changelog\u002Findex",{"title":234,"path":235,"stem":236},"Workspaces, Billing, Scaling, Custom Domains, Variables","\u002Fchangelog\u002Fcontinued-development","8.changelog\u002F1.continued-development",{"title":238,"path":239,"stem":240},"Projects, Builds, Deployments, Environments, Databases, Ejection","\u002Fchangelog\u002Finitial-development","8.changelog\u002F2.initial-development",{"title":242,"path":243,"stem":244,"children":245,"page":30},"Legal","\u002Flegal","legal",[246,250,254],{"title":247,"path":248,"stem":249},"Data Processing Agreement","\u002Flegal\u002Fdata-processing-agreement","legal\u002Fdata-processing-agreement",{"title":251,"path":252,"stem":253},"Privacy Policy","\u002Flegal\u002Fprivacy-policy","legal\u002Fprivacy-policy",{"title":255,"path":256,"stem":257},"Terms of Use","\u002Flegal\u002Fterms-of-use","legal\u002Fterms-of-use",{"id":259,"title":247,"body":260,"description":668,"extension":669,"links":670,"meta":671,"navigation":672,"path":248,"seo":673,"stem":249,"__hash__":674},"docs\u002Flegal\u002Fdata-processing-agreement.md",{"type":261,"value":262,"toc":654},"minimark",[263,267,279,286,289,292,295,298,303,334,338,408,411,415,418,474,478,481,550,553,557,560,564,570,574,577,581,584,588,595,597,601,604],[264,265,247],"h1",{"id":266},"data-processing-agreement",[268,269,270,274,275,278],"p",{},[271,272,273],"strong",{},"Effective date:"," July 24, 2026\n",[271,276,277],{},"Last updated:"," July 24, 2026",[268,280,281,282,285],{},"This Data Processing Agreement (\"DPA\") forms part of the ",[283,284,255],"a",{"href":256}," between you (\"Customer\", \"Controller\") and the operator of Lucity (\"Processor\", \"we\", \"us\"):",[268,287,288],{},"zeitlos.software Inh. Christian Blättler\nCHE‑439.475.468\nMattenhofstrasse 5, 3007 Bern, Switzerland",[268,290,291],{},"It governs the processing of personal data that we carry out on your behalf when you use lucity.cloud to build, deploy, and run your applications. It applies where you are subject to the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP\u002FnDSG), or both.",[268,293,294],{},"Where you act as a processor for your own customers, references to \"Controller\" also cover your role as their processor, and we act as your sub-processor.",[296,297],"hr",{},[299,300,302],"h2",{"id":301},"_1-roles-and-scope","1. Roles and Scope",[304,305,306,318,321,324],"ul",{},[307,308,309,310,313,314,317],"li",{},"You are the ",[271,311,312],{},"controller"," of the personal data your applications process (for example, data about your end users). We are the ",[271,315,316],{},"processor",", acting only on your documented instructions.",[307,319,320],{},"Your use of the platform, including the configuration of your workloads, environment variables, and services, constitutes your documented instructions. Additional instructions must be agreed in writing.",[307,322,323],{},"We process personal data only to provide the service described in the Terms of Use and do not process it for our own purposes.",[307,325,326,327,330,331,333],{},"We handle your ",[271,328,329],{},"account and billing data"," as a controller in our own right; that processing is described in the ",[283,332,251],{"href":252}," and is outside the scope of this DPA.",[299,335,337],{"id":336},"_2-subject-matter-of-processing","2. Subject Matter of Processing",[339,340,341,354],"table",{},[342,343,344],"thead",{},[345,346,347,351],"tr",{},[348,349,350],"th",{},"Item",[348,352,353],{},"Description",[355,356,357,368,378,388,398],"tbody",{},[345,358,359,365],{},[360,361,362],"td",{},[271,363,364],{},"Subject matter",[360,366,367],{},"Hosting and running the Customer's applications and their data on the platform",[345,369,370,375],{},[360,371,372],{},[271,373,374],{},"Duration",[360,376,377],{},"For the term of the Customer's use of the service",[345,379,380,385],{},[360,381,382],{},[271,383,384],{},"Nature and purpose",[360,386,387],{},"Building, deploying, storing, and executing the Customer's workloads, databases, key-value stores, and object storage",[345,389,390,395],{},[360,391,392],{},[271,393,394],{},"Types of personal data",[360,396,397],{},"Determined by the Customer. Any personal data the Customer's applications store or process on the platform",[345,399,400,405],{},[360,401,402],{},[271,403,404],{},"Categories of data subjects",[360,406,407],{},"Determined by the Customer. Typically the Customer's own users and contacts",[268,409,410],{},"We have no control over, and do not inspect, the categories of personal data or data subjects the Customer chooses to process through their workloads.",[299,412,414],{"id":413},"_3-our-obligations","3. Our Obligations",[268,416,417],{},"We will:",[304,419,420,426,432,438,444,450,456,462,468],{},[307,421,422,425],{},[271,423,424],{},"Process only on instructions."," Process personal data solely on your documented instructions, including regarding international transfers, unless required otherwise by applicable law, in which case we will inform you unless the law prohibits it.",[307,427,428,431],{},[271,429,430],{},"Confidentiality."," Ensure that personnel authorized to process the data are bound by confidentiality.",[307,433,434,437],{},[271,435,436],{},"Security."," Implement appropriate technical and organizational measures as described in Annex 1.",[307,439,440,443],{},[271,441,442],{},"Sub-processors."," Use sub-processors only under the conditions in Section 4.",[307,445,446,449],{},[271,447,448],{},"Assist with data-subject rights."," Taking into account the nature of the processing, assist you by appropriate measures in responding to requests from data subjects exercising their rights.",[307,451,452,455],{},[271,453,454],{},"Assist with compliance."," Assist you in ensuring compliance with your security, breach-notification, and data-protection-impact-assessment obligations, taking into account the information available to us.",[307,457,458,461],{},[271,459,460],{},"Breach notification."," Notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to us.",[307,463,464,467],{},[271,465,466],{},"Deletion or return."," On termination, delete or return the personal data as described in Section 5.",[307,469,470,473],{},[271,471,472],{},"Audits."," Make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and no undue disruption to our operations.",[299,475,477],{"id":476},"_4-sub-processors","4. Sub-processors",[268,479,480],{},"You provide general authorization for us to engage the sub-processors listed below to process personal data on your behalf. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.",[339,482,483,496],{},[342,484,485],{},[345,486,487,490,493],{},[348,488,489],{},"Sub-processor",[348,491,492],{},"Purpose",[348,494,495],{},"Location",[355,497,498,511,524,537],{},[345,499,500,505,508],{},[360,501,502],{},[271,503,504],{},"Hetzner",[360,506,507],{},"Core infrastructure hosting (compute, workloads, databases)",[360,509,510],{},"Germany (EU)",[345,512,513,518,521],{},[360,514,515],{},[271,516,517],{},"OVHcloud",[360,519,520],{},"Object storage hosting",[360,522,523],{},"France (EU)",[345,525,526,531,534],{},[360,527,528],{},[271,529,530],{},"Bunny",[360,532,533],{},"Content delivery for public buckets and custom-domain TLS",[360,535,536],{},"EU company; global edge network",[345,538,539,544,547],{},[360,540,541],{},[271,542,543],{},"Stripe",[360,545,546],{},"Payment processing (account and billing data only)",[360,548,549],{},"EU and international, under Standard Contractual Clauses",[268,551,552],{},"We will give you at least 30 days' notice, by email or platform notification, before adding or replacing a sub-processor. If you reasonably object on data-protection grounds, we will work with you in good faith to address the concern, and if we cannot, you may terminate the affected service.",[299,554,556],{"id":555},"_5-deletion-and-return","5. Deletion and Return",[268,558,559],{},"On termination of the service, or on your request, we will delete the personal data we process on your behalf within 30 days, unless applicable law requires us to retain it. When you delete a project or account, the associated data is removed within 30 days. Because the platform is ejectable, you can export your configuration and data before termination.",[299,561,563],{"id":562},"_6-international-transfers","6. International Transfers",[268,565,566,567,569],{},"Personal data processed on your behalf is stored in the European Union (see the ",[283,568,251],{"href":252},"). Where a sub-processor transfers personal data outside the EU or Switzerland, that transfer is covered by an appropriate safeguard, such as the EU Standard Contractual Clauses together with, for data subject to the FADP, the recognition of those clauses by the Swiss Federal Data Protection and Information Commissioner.",[299,571,573],{"id":572},"_7-swiss-fadp","7. Swiss FADP",[268,575,576],{},"Where the FADP applies, references to the GDPR are read as references to the equivalent provisions of the FADP, \"personal data\" includes data relating to legal entities to the extent protected by the FADP, and the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).",[299,578,580],{"id":579},"_8-liability-and-precedence","8. Liability and Precedence",[268,582,583],{},"The liability limitations in the Terms of Use apply to this DPA. If there is a conflict between this DPA and the Terms of Use regarding the processing of personal data, this DPA prevails.",[299,585,587],{"id":586},"_9-contact","9. Contact",[268,589,590,591],{},"For data-protection matters and to exercise controller rights under this DPA: ",[283,592,594],{"href":593},"mailto:privacy@lucity.cloud","privacy@lucity.cloud",[296,596],{},[299,598,600],{"id":599},"annex-1-technical-and-organizational-measures","Annex 1: Technical and Organizational Measures",[268,602,603],{},"We maintain measures appropriate to the risk, including:",[304,605,606,612,618,624,630,636,642,648],{},[307,607,608,611],{},[271,609,610],{},"Encryption in transit"," using TLS for all connections to and within the platform.",[307,613,614,617],{},[271,615,616],{},"Encryption at rest"," for stored data, including databases and object storage.",[307,619,620,623],{},[271,621,622],{},"Tenant isolation"," through namespace-level separation of workspaces in Kubernetes, with network policies restricting cross-tenant access.",[307,625,626,629],{},[271,627,628],{},"Access control"," on a least-privilege, role-based basis, with authentication through our self-hosted identity provider.",[307,631,632,635],{},[271,633,634],{},"Secrets handling"," through Kubernetes secrets, kept separate from application code and logs.",[307,637,638,641],{},[271,639,640],{},"Resilience"," through replicated databases and backups of managed database services.",[307,643,644,647],{},[271,645,646],{},"Monitoring and logging"," of platform activity to detect and respond to security events.",[307,649,650,653],{},[271,651,652],{},"Self-hosted core services"," (identity, container registry, deployment tooling) within our own cluster, limiting exposure to external processors.",{"title":655,"searchDepth":656,"depth":656,"links":657},"",2,[658,659,660,661,662,663,664,665,666,667],{"id":301,"depth":656,"text":302},{"id":336,"depth":656,"text":337},{"id":413,"depth":656,"text":414},{"id":476,"depth":656,"text":477},{"id":555,"depth":656,"text":556},{"id":562,"depth":656,"text":563},{"id":572,"depth":656,"text":573},{"id":579,"depth":656,"text":580},{"id":586,"depth":656,"text":587},{"id":599,"depth":656,"text":600},"How Lucity processes personal data on your behalf.","md",null,{},true,{"title":247,"description":668},"KtEj5A9D5aS-MUIj_hCfXAu0F0jrsEo3iuidSeGjp-w",[676,678],{"title":238,"path":239,"stem":240,"description":677,"children":-1},"Everything built during the first week, from empty repository to functional PaaS.",{"title":251,"path":252,"stem":253,"description":679,"children":-1},"How Lucity handles your data.",1785130475472]