Data Processing Agreement
Last Updated: January 20, 2024 | Version: 1.0.0
For Business Partners Only
This Data Processing Agreement ("DPA") is intended for business partners, vendors, and third-party service providers who process personal data on behalf of Digital Dram. Regular users of the Service are governed by our Terms of Service and Privacy Policy.
1. Definitions
For the purposes of this DPA:
- "Controller": Digital Dram, the entity that determines the purposes and means of processing Personal Data
- "Processor": The party to this agreement processing Personal Data on behalf of the Controller
- "Data Subject": An identified or identifiable natural person whose Personal Data is processed
- "Personal Data": Any information relating to a Data Subject
- "Processing": Any operation performed on Personal Data
- "Sub-processor": Any third party engaged by the Processor to process Personal Data
- "Data Protection Laws": All applicable laws relating to data protection, including GDPR and CCPA
- "Security Incident": Any breach of security leading to unauthorized access to Personal Data
2. Scope and Application
This DPA applies when the Processor processes Personal Data on behalf of the Controller as part of providing services under the main service agreement ("Principal Agreement"). This DPA supplements and forms part of the Principal Agreement.
In case of conflict between this DPA and the Principal Agreement regarding data protection matters, this DPA shall prevail.
3. Data Processing Details
3.1 Nature and Purpose of Processing
The Processor shall process Personal Data only as necessary to provide the services specified in the Principal Agreement, which may include:
- Data storage and hosting services
- Analytics and reporting services
- Communication and notification services
- Payment processing services
- Customer support services
- Marketing and advertising services
3.2 Categories of Data Subjects
- Users of the Digital Dram Service
- Prospective users and leads
- Business partners and vendors
- Website visitors
3.3 Types of Personal Data
- Identity data (name, username, date of birth)
- Contact data (email address, phone number)
- Account data (account credentials, preferences)
- Usage data (service usage, feature interactions)
- Technical data (IP address, device information, browser data)
- Location data (GPS coordinates, approximate location)
- Marketing data (communication preferences, interests)
3.4 Duration of Processing
The Processor shall process Personal Data for the duration of the Principal Agreement, unless otherwise agreed in writing or required by applicable law.
4. Processor Obligations
The Processor shall:
4.1 Lawful Processing
- Process Personal Data only on documented instructions from the Controller
- Immediately inform the Controller if instructions violate Data Protection Laws
- Not process Personal Data for any purpose other than providing the agreed services
4.2 Confidentiality
- Ensure all personnel authorized to process Personal Data are bound by confidentiality obligations
- Maintain the confidentiality of Personal Data even after the agreement ends
4.3 Security Measures
Implement and maintain appropriate technical and organizational measures, including:
- Encryption of Personal Data in transit and at rest
- Ongoing confidentiality, integrity, availability, and resilience of systems
- Ability to restore availability and access to Personal Data in case of incidents
- Regular testing and evaluation of security measures
- Pseudonymization where appropriate
- Access controls and authentication mechanisms
- Regular security audits and assessments
4.4 Sub-processors
- Not engage Sub-processors without prior written consent from the Controller
- Maintain a list of approved Sub-processors
- Ensure Sub-processors are bound by equivalent data protection obligations
- Remain fully liable for Sub-processor compliance
- Inform the Controller of any intended changes to Sub-processors
4.5 International Transfers
- Not transfer Personal Data outside the EEA without appropriate safeguards
- Implement Standard Contractual Clauses or other approved transfer mechanisms
- Ensure adequacy decisions are in place where applicable
4.6 Data Subject Rights
- Assist the Controller in responding to Data Subject requests
- Implement appropriate measures to facilitate rights exercises
- Forward any Data Subject requests to the Controller immediately
- Not respond directly to Data Subjects unless authorized
4.7 Compliance Assistance
- Assist with data protection impact assessments
- Provide information necessary for compliance demonstrations
- Cooperate with supervisory authorities
- Maintain records of processing activities
5. Security Incident Management
5.1 Notification Requirements
The Processor shall:
- Notify the Controller without undue delay (within 24 hours) upon becoming aware of a Security Incident
- Provide detailed information about the nature and scope of the incident
- Document all Security Incidents regardless of severity
5.2 Incident Information
Notification shall include:
- Nature of the Security Incident
- Categories and approximate number of Data Subjects affected
- Categories and approximate number of Personal Data records affected
- Likely consequences of the incident
- Measures taken or proposed to address the incident
- Contact details for further information
5.3 Cooperation
- Cooperate fully in investigating and remediating the incident
- Not notify Data Subjects or authorities without Controller approval
- Preserve evidence and maintain incident logs
- Implement measures to prevent recurrence
6. Audits and Inspections
6.1 Audit Rights
The Controller has the right to:
- Conduct audits and inspections of processing activities
- Request certifications and audit reports
- Verify compliance with this DPA and Data Protection Laws
- Engage independent third-party auditors
6.2 Processor Cooperation
The Processor shall:
- Provide reasonable access to facilities and systems
- Make available all necessary information
- Allow interviews with relevant personnel
- Cooperate in remediation of identified issues
6.3 Audit Procedures
- Audits shall be conducted with reasonable notice (minimum 30 days)
- Audits shall be during normal business hours
- Auditors must sign confidentiality agreements
- Controller bears audit costs unless breaches are discovered
7. Data Return and Deletion
7.1 Upon Termination
Upon termination of the Principal Agreement, the Processor shall:
- Cease all processing of Personal Data
- Return all Personal Data to the Controller in an agreed format
- Delete all copies of Personal Data unless retention is required by law
- Provide certification of deletion
7.2 Data Format
- Data shall be returned in commonly used, machine-readable formats
- Include all metadata and documentation
- Ensure secure transfer methods
7.3 Retention Exceptions
If law requires retention, the Processor shall inform the Controller and ensure continued protection of retained data.
8. Liability and Indemnification
8.1 Processor Liability
The Processor shall be liable for:
- Damages caused by processing in violation of this DPA
- Failure to comply with Data Protection Laws
- Processing beyond or contrary to Controller instructions
- Breaches by Sub-processors
8.2 Indemnification
The Processor shall indemnify and hold harmless the Controller against all claims, losses, damages, and expenses arising from the Processor's breach of this DPA or Data Protection Laws.
8.3 Limitation of Liability
Nothing in this DPA limits liability for damages caused by willful misconduct, gross negligence, or violations of Data Protection Laws.
9. Term and Termination
9.1 Duration
This DPA remains in effect for the duration of the Principal Agreement and any period during which the Processor processes Personal Data on behalf of the Controller.
9.2 Termination Rights
The Controller may terminate this DPA immediately if:
- The Processor materially breaches this DPA
- The Processor violates Data Protection Laws
- The Processor cannot provide adequate guarantees of compliance
9.3 Survival
Obligations regarding confidentiality, security, and data deletion shall survive termination of this DPA.
10. General Provisions
10.1 Amendments
Amendments to this DPA require written agreement from both parties, except for updates required by changes in Data Protection Laws.
10.2 Governing Law
This DPA is governed by the laws of [Jurisdiction], without regard to conflict of law principles.
10.3 Dispute Resolution
Disputes arising under this DPA shall be resolved through the dispute resolution mechanisms in the Principal Agreement.
10.4 Severability
If any provision is found invalid or unenforceable, the remaining provisions shall continue in full force and effect.
10.5 Priority
In case of conflict regarding data protection matters:
- Mandatory Data Protection Laws
- This DPA
- The Principal Agreement
11. Approved Sub-processors
The following Sub-processors are pre-approved:
| Sub-processor | Service | Location | Purpose |
|---|---|---|---|
| Google Cloud Platform | Cloud Infrastructure | United States | Hosting and storage |
| Firebase (Google) | Authentication | United States | User authentication |
| SendGrid (Twilio) | Email Service | United States | Email communications |
12. Contact Information
12.1 Controller Contact
Digital Dram
Data Protection Officer: [email protected]
Legal Department: [email protected]
Address: 1900 Reston Metro Plaza, Suite 600
Reston, Virginia 20190
12.2 Processor Contact
[To be completed by Processor]
Company Name: _________________
Contact Person: _________________
Email: _________________
Phone: _________________
Address: _________________
Signature Block
For the Controller (Digital Dram):
Signature: _______________________
Name: _______________________
Title: _______________________
Date: _______________________
For the Processor:
Signature: _______________________
Name: _______________________
Title: _______________________
Date: _______________________
This Data Processing Agreement is supplemental to the Principal Agreement between the parties and is effective as of the date of last signature above.