Data Processing Agreement
[DRAFT — pending review by qualified legal counsel. Replace all bracketed placeholders (legal entity, jurisdiction, address, contact emails) before publishing.]
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and [PRV Technologies legal entity] ("Processor") and applies where we process personal data on your behalf in providing the Services.
1. Scope and roles
For Customer Content, you act as Controller (or processor on behalf of a third party) and we act as Processor. We process personal data only on your documented instructions, including as set out in the Terms and this DPA.
2. Details of processing
Subject matter: provision of the Services.
Duration: the term of your subscription plus legally required retention.
Nature and purpose: hosting, compute, storage, and networking as configured by you.
Types of data: any personal data contained in Customer Content you choose to process.
Data subjects: any individuals whose data you choose to process.
3. Processor obligations
We will: process only on documented instructions; ensure persons authorized to process are bound by confidentiality; implement appropriate technical and organizational security measures; and assist you, taking into account the nature of processing, with data-subject requests and your compliance obligations.
4. Sub-processors
You authorize us to engage sub-processors to provide the Services. We impose data-protection obligations on sub-processors no less protective than this DPA and remain responsible for their performance. We will make available a list of sub-processors and notify you of changes.
5. International transfers
Where processing involves transfers outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses.
6. Security measures
We maintain measures including encryption in transit, access controls, network isolation, logging, and monitoring, appropriate to the risk.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your Customer Content and provide information reasonably required for your notification obligations.
8. Audit
We will make available information necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable confidentiality and security conditions.
9. Return and deletion
On termination, we will delete or return Customer Content in accordance with the Terms, subject to legal retention requirements.
10. Liability and contact
Liability under this DPA is subject to the limitations in the Terms. Contact: [privacy@prvtechnologies.com].