Data Processing Agreement
Effective 3 August 2026 · Version 1.0 · GDPR Article 28
This is the agreement that governs personal data we handle on your behalf. It applies automatically to any DeployerProof engagement in which we process personal data for you, from the day the engagement starts.
If your legal team would rather work from your own paper, send it to hello@deployerproof.com and we will review and sign it. We are not attached to this template; we are attached to the substance in Annex II.
1. Parties and structure
Processor: Amiya Krishna Bera, trading as DeployerProof — a sole proprietorship established in India, registered trading address Basantia, East Midnapore, West Bengal, India, PIN 721442.
Controller: the client identified in the engagement, the scope confirmation, or the issued invoice.
Where this agreement conflicts with our general terms or the engagement description, this agreement wins on anything touching personal data. Where it conflicts with the Standard Contractual Clauses incorporated in section 8, the Clauses win.
2. Roles
You are the controller. You decide which of your systems we look at, what you send us, and what goes into your evidence log. We are the processor and act only on your instructions.
One exception, stated plainly so nobody has to guess: for your billing details, our invoicing records, and our own correspondence with you, we are a controller in our own right. That handling is described in the Privacy Policy, not here.
3. What we process, and why
| Element | Detail |
|---|---|
| Subject matter | Delivery of the compliance gap-scan, the disclosure pack, and the evidence-log service |
| Duration | For the duration of the engagement, plus the retention windows in section 10 |
| Nature of processing | Storage, review, structuring, hashing, timestamping, export, deletion |
| Purpose | Producing the gap report; maintaining a tamper-evident record of your disclosure configuration and its changes |
| Categories of data subject | Your staff who act as our contacts and as account users |
| Categories of personal data | Business-contact data: name, work email, job title, employer, and login email for evidence-log accounts. Plus any personal data that happens to appear in material you choose to send us for the scan |
| Special category data | None. Do not send it; we have no lawful basis to process it and no place to put it |
| Children's data | None |
4. Your instructions
We process personal data only on your documented instructions, including on transfers to a third country. The engagement description and this agreement are your initial instructions; anything else you send in writing counts too.
If an instruction looks to us like it breaks the GDPR or another applicable data protection law, we tell you before acting, and we may pause that part of the work until it is resolved. If a law we are subject to compels us to process your data beyond your instructions, we tell you first unless that law forbids the notice.
5. Confidentiality
Everything you share is confidential and used only to deliver the engagement. Access is limited to the operator named in section 1, who is bound by this agreement personally. If that ever stops being true — if a contractor or employee is engaged — they get a written confidentiality undertaking before touching anything, and the sub-processor procedure in section 7 applies where relevant.
6. Security
We maintain the technical and organisational measures set out in Annex II, which meet Article 32. We may change individual measures as the service evolves, but not in a way that materially weakens the protection.
7. Sub-processors
You give general written authorisation for the sub-processors listed in Annex III. Before adding or replacing one, we give you at least 30 days' notice by email. If you object on reasonable data protection grounds within those 30 days, we work with you to find an alternative; if there is none, you may terminate the affected part of the engagement and receive a pro-rata refund of anything prepaid.
Every sub-processor is bound by data protection terms no weaker than these, and we remain fully liable to you for their performance.
8. International transfers
Evidence-log records are stored in the EU (Frankfurt). Correspondence is held by our email provider in a region we have not verified and do not claim, and material you send for a scan sits on the operator's workstation while the report is written. All of it is accessed by the operator from India, which has no European Commission adequacy decision, so that access is a restricted transfer and is treated as one.
For those transfers, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this agreement by reference, using Module Two (controller to processor). The following elections apply:
- Clause 7 (docking clause): applies
- Clause 9 (sub-processors): Option 2, general written authorisation, with the 30-day notice period in section 7
- Clause 11 (redress): the optional independent dispute resolution paragraph does not apply
- Clause 17 (governing law): the law of Ireland, unless you ask us in writing to use the law of your own Member State, which we will accept
- Clause 18(b) (forum): the courts of Ireland, subject to the same election
- Annexes I, II and III of the Clauses are populated by the corresponding annexes below
For UK transfers, the ICO's International Data Transfer Addendum applies to the Clauses above. For Swiss transfers, references to the GDPR read as references to the FADP and the competent authority is the FDPIC.
On the assessment those Clauses require: the material crossing the border is business-contact data and configuration metadata. There is no conversation content, no end-user personal data, and nothing of intelligence interest. We have never received a government request for client data, and we will tell you about any we can lawfully disclose.
9. Data subject requests, breaches, and your compliance obligations
If a data subject contacts us directly about data we hold for you — privacy@deployerproof.com is the route — we do not answer on the substance. We forward it to you without undue delay and let the person know we have.
Given how little we hold and how it is structured, we can help you meet access, correction, deletion, and portability requests quickly — usually by running an export or a deletion against your organization's records. There is no charge for reasonable assistance.
If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any case within 48 hours, with what we know at the time: what happened, which categories and roughly how many records, the likely consequences, and what we are doing about it. Updates follow as the picture firms up. The Article 33 notification to your supervisory authority is yours to make; we give you what you need to make it.
We also assist with data protection impact assessments and prior consultations to the extent the information is ours to give.
10. Return and deletion
When the engagement ends, you choose: we return your data in a machine-readable export, or we delete it. Absent a choice, we export and delete on the timetable in the Privacy Policy — evidence-log records 30 days after the subscription ends, scan input material 90 days after delivery.
Backups age out on their own cycle, within 30 days. We keep what tax, accounting, or other law requires us to keep, and nothing beyond that.
11. Audit and information
You can ask for the information needed to demonstrate our compliance with Article 28, and we answer written security questionnaires within 30 days at no charge. That is the route we expect most clients to use.
You also have the right to audit or inspect, exercisable once per year on 30 days' written notice, or at any time following a breach affecting your data. Audits happen remotely by default given a one-person practice, during business hours, without disrupting the service, and under confidentiality. You bear your own costs and any third-party auditor's fees.
12. Term and general
This agreement runs for as long as we process personal data for you, and the confidentiality and transfer obligations survive it. If a provision is unenforceable, the rest stands. Changes are made in writing, and material changes are emailed to active clients rather than quietly republished.
13. How this gets signed
Buying an engagement puts this agreement in place — no signature ceremony required. If your process needs a countersigned copy or a DPA on your own template, email hello@deployerproof.com and we will turn it around in a working day or two.
Annex I — Parties and description of processing
A. Parties. Data exporter: the controller identified in section 1, acting as the client. Data importer: Amiya Krishna Bera, trading as DeployerProof, a sole proprietorship established in India, providing compliance-engineering services. Contact for both roles at DeployerProof: hello@deployerproof.com; data-protection contact privacy@deployerproof.com.
B. Description of transfer. Categories of data subject, categories of personal data, nature, purpose, and duration are as set out in section 3. Frequency: continuous for the evidence log, one-off for the gap-scan. Sub-processors: as listed in Annex III, for the duration of the engagement.
C. Competent supervisory authority. The supervisory authority of the Member State in which you are established, or where you are not established in the EU, the authority of the Member State in which your Article 27 representative sits.
Annex II — Technical and organisational measures
Data minimisation by design
The first and strongest measure is that the sensitive categories are never collected. The evidence log has no schema for conversation content, screenshots, end-user identifiers, or IP addresses of your users. A total compromise of our database would expose disclosure texts, hashes, timestamps, and public URLs.
Location and infrastructure
Managed Postgres on Supabase, EU region (Frankfurt), for the evidence log. No replication outside the EU. No customer data on local machines beyond what is needed to draft a report, which is deleted on delivery.
The EU-region commitment is stated for the evidence log rather than for everything we touch, because that is where it is true. Business correspondence runs through Hostinger Business Email and we do not currently assert a storage region for the mailbox — see Annex III.
Access control
Row-level security scoped per organization on every table holding client data, so one client's records are unreachable from another's session. Multi-factor authentication on every administrative account. No shared credentials. Access limited to the single named operator.
Encryption
TLS in transit. Encryption at rest through the managed platform. Client accounts authenticate by magic link, so there are no user passwords for us to store or lose.
Integrity
Evidence-log entries are chained with SHA-256 — each record hashes its own canonical payload together with the previous record's hash — and attested by RFC 3161 timestamp tokens from an independent timestamping authority. Tampering with a historical entry breaks the chain and is detectable on export.
Availability and recovery
Automated daily backups within the EU region, retained for 30 days. Exports are available on demand so you are never dependent on our uptime for evidence you need in a procurement cycle.
Breach handling
Notification to affected clients without undue delay and within 48 hours of awareness, per section 9.
Annex III — Approved sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Supabase | Database, authentication, file storage | EU — Frankfurt (eu-central-1) |
| Skydo | Cross-border invoice collection and settlement | India · funds routed through Skydo's banking partners |
| Hostinger Business Email | Business correspondence and delivery of reports | Determined by Hostinger; we make no EU-residency claim for mailbox storage |
Hosting of the public website itself involves no client personal data and is not listed as a sub-processor.
On the mailbox specifically: we have not verified which region Hostinger stores mail in, so we do not state one. Saying “EU” without having checked would be the same failure we are hired to find in other people's products. Assume correspondence may be stored outside the EU, and send scan material accordingly — which is another reason the scan is built not to need your users' data in the first place. If the region is confirmed later, this row gets updated and active clients get told, per section 12.