Skip to main content

Voldemort

Legal

Data Processing Agreement

Last updated: August 14, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Prokurit, Inc. (“Prokurit,” “Processor”) and the business that has subscribed to the Prokurit Service (“Customer,” “Controller”), and governs Prokurit’s processing of personal data contained in Customer Data on Customer’s behalf. Capitalized terms not defined here have the meaning given in our Terms of Service.
On This Page
1. Definitions

“Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” and “Supervisory Authority” have the meanings given in the GDPR, applied correspondingly under other applicable data protection law. “Subprocessor” means a third party Prokurit engages to process Personal Data in order to provide the Service.

2. Roles of the Parties

For Personal Data contained in Customer Data, Customer is the Controller and Prokurit is the Processor. Prokurit processes Personal Data only as a Processor acting on Customer’s behalf and does not determine the purposes or means of processing Customer Data.

3. Processing Instructions

Prokurit will process Personal Data only on Customer’s documented instructions, including as necessary to provide the Service under the parties’ agreement, unless required to do otherwise by law — in which case Prokurit will inform Customer of that legal requirement before processing, unless the law prohibits doing so.

4. Confidentiality of Personnel

Prokurit ensures that personnel authorized to process Personal Data are subject to confidentiality obligations, whether contractual or statutory.

5. Security Measures

Prokurit maintains technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, consistent with its SOC 2 Type II certification and ISO 27001 certification. See our Security & Trust page for a summary of these measures; a full description is available on request under appropriate confidentiality terms.

6. Subprocessors

Customer authorizes Prokurit to engage Subprocessors to support delivery of the Service — for example, Cloudflare, which provides infrastructure and security services.

Prokurit will impose data-protection terms on each Subprocessor that are no less protective than this DPA, remains responsible for each Subprocessor’s performance, and will give Customer at least 30 days’ notice before engaging a new Subprocessor, with an opportunity to object on reasonable data-protection grounds.

7. Assistance with Data Subject Requests

Taking into account the nature of the processing, Prokurit will assist Customer, through appropriate technical and organizational measures, in responding to requests from Data Subjects seeking to exercise their rights, and in Customer’s compliance with its obligations regarding security, breach notification, and data protection impact assessments.

8. Personal Data Breach Notification

Prokurit will notify Customer without undue delay, and in any event within 72 hours after becoming aware, of a confirmed Personal Data breach affecting Customer Data, and will provide information reasonably available to Prokurit to help Customer meet its own notification obligations.

9. International Transfers

Where Prokurit transfers Personal Data out of the EEA, UK, or Switzerland, it relies on an appropriate transfer mechanism, namely the European Commission’s Standard Contractual Clauses.

10. Audits

On reasonable request, no more than once per year absent a Personal Data breach or a legal requirement, Prokurit will make available its most recent SOC 2 Type II report and ISO 27001 certificate to support Customer’s compliance obligations. These reports satisfy Customer’s audit rights under this DPA; Prokurit does not offer a separate on-site or third-party audit beyond report-sharing, except where a regulatory requirement specific to Customer requires one, in which case the parties will agree on reasonable scope, timing, and confidentiality terms.

11. Return or Deletion of Data

On termination of the Service, Prokurit will, at Customer’s choice, delete or return Customer Data within 30 days of termination, except where retention is required by law.

12. Liability

Each party’s liability arising out of this DPA is subject to the limitations of liability set out in our Terms of Service.

13. Term

This DPA remains in effect for as long as Prokurit processes Personal Data on Customer’s behalf under the parties’ agreement.

14. Contact Us

Questions about this DPA, or requests for an executed copy referencing your organization by name, can be directed to [email protected].