Data Processing Agreement
Our DPA is being finalized and will be published here before general availability. Contact us if you need it sooner.
Template — not yet reviewed by counsel. Replace every
[placeholder]before publishing.
Data Processing Agreement
Last updated: [date]
This Data Processing Agreement ("DPA") forms part of the agreement between [legal entity name] ("Processor") and the customer ("Controller") for use of the Service, where Sahabti processes personal data on the customer's behalf.
1. Subject matter and duration
[Scope of processing and duration — tied to the underlying Terms of Service.]
2. Nature and purpose of processing
Sahabti processes personal data solely to provide, maintain, and support the Service, as instructed by the Controller.
3. Categories of data and data subjects
[e.g. account holders, end users of Controller's applications hosted on the Service.]
4. Subprocessors
Sahabti may engage subprocessors listed at [link to subprocessor list]. We'll notify the Controller of material changes with [N] days' notice.
5. Security measures
[Reference to technical/organizational measures — encryption at rest/in transit, access controls, audit logging.]
6. Data subject requests
Sahabti will assist the Controller in responding to data subject requests (access, deletion, portability) within [timeframe].
7. Data breach notification
Sahabti will notify the Controller without undue delay, and no later than [N] hours, after becoming aware of a personal data breach.
8. International transfers
[Transfer mechanism — SCCs, adequacy decision, etc.]
9. Deletion or return of data
Upon termination, Sahabti will delete or return all personal data within [timeframe], except as required by law.
10. Audit rights
[Scope of audit rights the Controller has, and how they're exercised.]
11. Contact
Questions about this DPA: [legal contact email].