Data Processing Agreement
- 1. Definitions
- 2. Roles of the Parties
- 3. Processing Instructions
- 4. Confidentiality of Personnel
- 5. Security Measures
- 6. Subprocessors
- 7. Assistance with Data Subject Requests
- 8. Personal Data Breach Notification
- 9. International Transfers
- 10. Audits
- 11. Return or Deletion of Data
- 12. Liability
- 13. Term
- 14. Contact Us
“Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” and “Supervisory Authority” have the meanings given in the GDPR, applied correspondingly under other applicable data protection law. “Subprocessor” means a third party Prokurit engages to process Personal Data in order to provide the Service.
For Personal Data contained in Customer Data, Customer is the Controller and Prokurit is the Processor. Prokurit processes Personal Data only as a Processor acting on Customer’s behalf and does not determine the purposes or means of processing Customer Data.
Prokurit will process Personal Data only on Customer’s documented instructions, including as necessary to provide the Service under the parties’ agreement, unless required to do otherwise by law — in which case Prokurit will inform Customer of that legal requirement before processing, unless the law prohibits doing so.
Prokurit ensures that personnel authorized to process Personal Data are subject to confidentiality obligations, whether contractual or statutory.
Prokurit maintains technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, consistent with its SOC 2 Type II certification and ISO 27001 certification. See our Security & Trust page for a summary of these measures; a full description is available on request under appropriate confidentiality terms.
Customer authorizes Prokurit to engage Subprocessors to support delivery of the Service — for example, Cloudflare, which provides infrastructure and security services.
Prokurit will impose data-protection terms on each Subprocessor that are no less protective than this DPA, remains responsible for each Subprocessor’s performance, and will give Customer at least 30 days’ notice before engaging a new Subprocessor, with an opportunity to object on reasonable data-protection grounds.
Taking into account the nature of the processing, Prokurit will assist Customer, through appropriate technical and organizational measures, in responding to requests from Data Subjects seeking to exercise their rights, and in Customer’s compliance with its obligations regarding security, breach notification, and data protection impact assessments.
Prokurit will notify Customer without undue delay, and in any event within 72 hours after becoming aware, of a confirmed Personal Data breach affecting Customer Data, and will provide information reasonably available to Prokurit to help Customer meet its own notification obligations.
Where Prokurit transfers Personal Data out of the EEA, UK, or Switzerland, it relies on an appropriate transfer mechanism, namely the European Commission’s Standard Contractual Clauses.
On reasonable request, no more than once per year absent a Personal Data breach or a legal requirement, Prokurit will make available its most recent SOC 2 Type II report and ISO 27001 certificate to support Customer’s compliance obligations. These reports satisfy Customer’s audit rights under this DPA; Prokurit does not offer a separate on-site or third-party audit beyond report-sharing, except where a regulatory requirement specific to Customer requires one, in which case the parties will agree on reasonable scope, timing, and confidentiality terms.
On termination of the Service, Prokurit will, at Customer’s choice, delete or return Customer Data within 30 days of termination, except where retention is required by law.
Each party’s liability arising out of this DPA is subject to the limitations of liability set out in our Terms of Service.
This DPA remains in effect for as long as Prokurit processes Personal Data on Customer’s behalf under the parties’ agreement.
Questions about this DPA, or requests for an executed copy referencing your organization by name, can be directed to [email protected].