Data processing agreement — readiness
No executed DPA is represented here. This page identifies what the operator and customer must settle before personal data is used in production.
1. Parties and processing instructions
The agreement must identify both legal parties, their roles, authorized instructions, purpose and duration, categories of data and data subjects, and each party’s responsibilities. Workspace settings and product features do not replace contractual instructions.
2. Technical and organizational measures
The product implements workspace-scoped permissions, database row-level security, encrypted integration secrets, hashed API keys and audit records. The final security annex must describe the deployed infrastructure, operator access, personnel confidentiality, restore tests, incident response and verified controls. Implementation alone is not independent assurance.
3. Subprocessors and transfers
The parties must approve the actual subprocessor inventory, change-notice and objection process, processing locations and required international-transfer safeguards. Provider names on an integrations page do not establish a signed subprocessing contract or an approved transfer mechanism.
4. Assistance, return and deletion
The DPA must specify assistance with rights requests and impact assessments, incident-notification procedures and timelines, audit rights, return/deletion upon termination and any legally required retention. No statutory deadline or contractual guarantee is invented by this readiness notice.