Data Processing Addendum (DPA)

How we process your data on your behalf.

This is a summary. The full signed DPA accompanies every Master Services Agreement.

Roles

You are Data Controller. We are Data Processor.

Sub-processors

Listed at /subprocessors. 30-day notice for additions.

Security measures

AES-256 at rest. TLS 1.3 in transit. Per-tenant isolation. MFA. Background checks. Quarterly training. Annual pen testing. SOC 2 Type II in flight.

Breach notification

Within 48 hours of confirmation.

Audit rights

Annual, 30-day notice. SOC 2 Type II report (when issued) satisfies in lieu.

Data deletion

Within 30 days of termination.