1. Definitions
Capitalized terms not defined here have the meanings given in the Terms, GDPR, or applicable law. “Personal Data” means any information relating to an identified or identifiable natural person processed by us on Controller's behalf under the Terms. “Subprocessor” means a third party engaged by us to process Personal Data.
2. Roles & Scope
Controller determines the purposes and means of processing. Processor processes Personal Data only on Controller's documented instructions, including as reflected in the Terms and Controller's configuration of the Services. Processing is limited to the duration of the Services, the categories of data submitted by Controller, and the following purposes: providing, securing, monitoring, supporting, and improving the Services.
3. Confidentiality
Processor ensures that personnel authorized to process Personal Data are bound by written confidentiality obligations and have received appropriate privacy and security training.
4. Security Measures
Processor implements and maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, including: encryption in transit (TLS 1.2+); encryption at rest; role-based access control and least privilege; per-tenant row-level security in the database; centralized secret management; production access logging and monitoring; vulnerability scanning; secure software development lifecycle; hardened cloud infrastructure with reputable providers; documented incident-response procedures; and mandatory security training for personnel.
5. Subprocessors
Controller authorizes Processor to engage Subprocessors to perform specific processing activities, provided that Processor: (a) enters into a written contract imposing data-protection obligations no less protective than this DPA; (b) remains responsible for Subprocessor performance; and (c) maintains a current list of Subprocessors available on request. Processor will provide advance notice of new Subprocessors and, where reasonably objected to on legitimate data-protection grounds, work in good faith to resolve the objection or permit Controller to terminate the affected portion of the Services.
6. Data Subject Rights
Taking into account the nature of the processing, Processor will provide reasonable assistance to Controller to enable Controller to respond to requests from data subjects seeking to exercise their rights (access, rectification, deletion, restriction, portability, objection). Where Processor receives a request directly from a data subject, Processor will promptly forward it to Controller and will not respond substantively without Controller's instruction.
7. Security Incidents
Processor will notify Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Controller's Personal Data, and will provide information reasonably necessary for Controller to comply with its own notification obligations. Notification is not an acknowledgment of fault or liability.
8. Data Protection Impact Assessments
Processor will provide reasonable assistance to Controller with data protection impact assessments and prior consultations with supervisory authorities to the extent required by law.
9. Return and Deletion
Upon termination or expiration of the Services, Processor will, at Controller's choice, delete or return all Personal Data, unless applicable law requires continued storage. Backup copies will be purged in accordance with Processor's documented retention schedule.
10. Audits
Processor will make available information necessary to demonstrate compliance with this DPA, including summaries of independent third-party audits and security certifications, where obtained. On-site audits by Controller are permitted no more than once every twelve (12) months, with at least thirty (30) days' prior written notice, during business hours, subject to reasonable confidentiality and safety controls, and at Controller's expense, unless a Personal Data Breach or material non-compliance is identified.
11. International Transfers
Where Processor transfers Personal Data outside the EEA, UK, or Switzerland, the parties agree that the Standard Contractual Clauses (Modules Two and Three) and, where applicable, the UK IDTA/Addendum, apply and are incorporated herein by reference. Docking clauses, governing law, and forum selections default to those of the Controller's establishing member state unless the parties agree otherwise in writing.
12. U.S. State Privacy Laws
Where Processor acts as a “Service Provider,” “Processor,” or “Contractor” under CCPA/CPRA, CPA, CTDPA, VCDPA, UCPA, TDPSA, or similar laws, Processor certifies that it: (a) will not sell or share Personal Data; (b) will not retain, use, or disclose Personal Data outside the direct business relationship or for any purpose other than the specific purpose of performing the Services; (c) will not combine Personal Data with information received from other sources except as permitted by law; and (d) will notify Controller if it can no longer meet these obligations.
13. Liability
Liability under this DPA is subject to the limitations of liability in the Terms.
14. Order of Precedence
In case of conflict, the SCCs prevail over this DPA on matters they cover, this DPA prevails over the Terms on data-protection matters, and the Terms prevail otherwise.
15. Execution
By accepting the Terms and enabling the Services on personal data subject to the laws above, Controller and Processor are deemed to have entered into this DPA. A counter-signed copy is available on written request via our contact page.