Legal

Data Processing Agreement

Effective 3 August 2026 · Version 1.0 · GDPR Article 28

This is the agreement that governs personal data we handle on your behalf. It applies automatically to any DeployerProof engagement in which we process personal data for you, from the day the engagement starts.

If your legal team would rather work from your own paper, send it to hello@deployerproof.com and we will review and sign it. We are not attached to this template; we are attached to the substance in Annex II.

1. Parties and structure

Processor: Amiya Krishna Bera, trading as DeployerProof — a sole proprietorship established in India, registered trading address Basantia, East Midnapore, West Bengal, India, PIN 721442.

Controller: the client identified in the engagement, the scope confirmation, or the issued invoice.

Where this agreement conflicts with our general terms or the engagement description, this agreement wins on anything touching personal data. Where it conflicts with the Standard Contractual Clauses incorporated in section 8, the Clauses win.

2. Roles

You are the controller. You decide which of your systems we look at, what you send us, and what goes into your evidence log. We are the processor and act only on your instructions.

One exception, stated plainly so nobody has to guess: for your billing details, our invoicing records, and our own correspondence with you, we are a controller in our own right. That handling is described in the Privacy Policy, not here.

3. What we process, and why

ElementDetail
Subject matterDelivery of the compliance gap-scan, the disclosure pack, and the evidence-log service
DurationFor the duration of the engagement, plus the retention windows in section 10
Nature of processingStorage, review, structuring, hashing, timestamping, export, deletion
PurposeProducing the gap report; maintaining a tamper-evident record of your disclosure configuration and its changes
Categories of data subjectYour staff who act as our contacts and as account users
Categories of personal dataBusiness-contact data: name, work email, job title, employer, and login email for evidence-log accounts. Plus any personal data that happens to appear in material you choose to send us for the scan
Special category dataNone. Do not send it; we have no lawful basis to process it and no place to put it
Children's dataNone
Architectural exclusion. The evidence log stores configuration metadata only: disclosure text versions, placement and locale configuration, product public URLs, SHA-256 hash chains, RFC 3161 timestamp tokens, and event timestamps. It holds no conversation content, no session screenshots, and no personal data belonging to your end users. The schema has no columns for any of that. Storing it would require a redesign, not a settings change — which is the point of building it this way.

4. Your instructions

We process personal data only on your documented instructions, including on transfers to a third country. The engagement description and this agreement are your initial instructions; anything else you send in writing counts too.

If an instruction looks to us like it breaks the GDPR or another applicable data protection law, we tell you before acting, and we may pause that part of the work until it is resolved. If a law we are subject to compels us to process your data beyond your instructions, we tell you first unless that law forbids the notice.

5. Confidentiality

Everything you share is confidential and used only to deliver the engagement. Access is limited to the operator named in section 1, who is bound by this agreement personally. If that ever stops being true — if a contractor or employee is engaged — they get a written confidentiality undertaking before touching anything, and the sub-processor procedure in section 7 applies where relevant.

6. Security

We maintain the technical and organisational measures set out in Annex II, which meet Article 32. We may change individual measures as the service evolves, but not in a way that materially weakens the protection.

7. Sub-processors

You give general written authorisation for the sub-processors listed in Annex III. Before adding or replacing one, we give you at least 30 days' notice by email. If you object on reasonable data protection grounds within those 30 days, we work with you to find an alternative; if there is none, you may terminate the affected part of the engagement and receive a pro-rata refund of anything prepaid.

Every sub-processor is bound by data protection terms no weaker than these, and we remain fully liable to you for their performance.

8. International transfers

Evidence-log records are stored in the EU (Frankfurt). Correspondence is held by our email provider in a region we have not verified and do not claim, and material you send for a scan sits on the operator's workstation while the report is written. All of it is accessed by the operator from India, which has no European Commission adequacy decision, so that access is a restricted transfer and is treated as one.

For those transfers, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this agreement by reference, using Module Two (controller to processor). The following elections apply:

For UK transfers, the ICO's International Data Transfer Addendum applies to the Clauses above. For Swiss transfers, references to the GDPR read as references to the FADP and the competent authority is the FDPIC.

On the assessment those Clauses require: the material crossing the border is business-contact data and configuration metadata. There is no conversation content, no end-user personal data, and nothing of intelligence interest. We have never received a government request for client data, and we will tell you about any we can lawfully disclose.

9. Data subject requests, breaches, and your compliance obligations

If a data subject contacts us directly about data we hold for you — privacy@deployerproof.com is the route — we do not answer on the substance. We forward it to you without undue delay and let the person know we have.

Given how little we hold and how it is structured, we can help you meet access, correction, deletion, and portability requests quickly — usually by running an export or a deletion against your organization's records. There is no charge for reasonable assistance.

If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any case within 48 hours, with what we know at the time: what happened, which categories and roughly how many records, the likely consequences, and what we are doing about it. Updates follow as the picture firms up. The Article 33 notification to your supervisory authority is yours to make; we give you what you need to make it.

We also assist with data protection impact assessments and prior consultations to the extent the information is ours to give.

10. Return and deletion

When the engagement ends, you choose: we return your data in a machine-readable export, or we delete it. Absent a choice, we export and delete on the timetable in the Privacy Policy — evidence-log records 30 days after the subscription ends, scan input material 90 days after delivery.

Backups age out on their own cycle, within 30 days. We keep what tax, accounting, or other law requires us to keep, and nothing beyond that.

11. Audit and information

You can ask for the information needed to demonstrate our compliance with Article 28, and we answer written security questionnaires within 30 days at no charge. That is the route we expect most clients to use.

You also have the right to audit or inspect, exercisable once per year on 30 days' written notice, or at any time following a breach affecting your data. Audits happen remotely by default given a one-person practice, during business hours, without disrupting the service, and under confidentiality. You bear your own costs and any third-party auditor's fees.

12. Term and general

This agreement runs for as long as we process personal data for you, and the confidentiality and transfer obligations survive it. If a provision is unenforceable, the rest stands. Changes are made in writing, and material changes are emailed to active clients rather than quietly republished.

13. How this gets signed

Buying an engagement puts this agreement in place — no signature ceremony required. If your process needs a countersigned copy or a DPA on your own template, email hello@deployerproof.com and we will turn it around in a working day or two.

Annex I — Parties and description of processing

A. Parties. Data exporter: the controller identified in section 1, acting as the client. Data importer: Amiya Krishna Bera, trading as DeployerProof, a sole proprietorship established in India, providing compliance-engineering services. Contact for both roles at DeployerProof: hello@deployerproof.com; data-protection contact privacy@deployerproof.com.

B. Description of transfer. Categories of data subject, categories of personal data, nature, purpose, and duration are as set out in section 3. Frequency: continuous for the evidence log, one-off for the gap-scan. Sub-processors: as listed in Annex III, for the duration of the engagement.

C. Competent supervisory authority. The supervisory authority of the Member State in which you are established, or where you are not established in the EU, the authority of the Member State in which your Article 27 representative sits.

Annex II — Technical and organisational measures

Data minimisation by design

The first and strongest measure is that the sensitive categories are never collected. The evidence log has no schema for conversation content, screenshots, end-user identifiers, or IP addresses of your users. A total compromise of our database would expose disclosure texts, hashes, timestamps, and public URLs.

Location and infrastructure

Managed Postgres on Supabase, EU region (Frankfurt), for the evidence log. No replication outside the EU. No customer data on local machines beyond what is needed to draft a report, which is deleted on delivery.

The EU-region commitment is stated for the evidence log rather than for everything we touch, because that is where it is true. Business correspondence runs through Hostinger Business Email and we do not currently assert a storage region for the mailbox — see Annex III.

Access control

Row-level security scoped per organization on every table holding client data, so one client's records are unreachable from another's session. Multi-factor authentication on every administrative account. No shared credentials. Access limited to the single named operator.

Encryption

TLS in transit. Encryption at rest through the managed platform. Client accounts authenticate by magic link, so there are no user passwords for us to store or lose.

Integrity

Evidence-log entries are chained with SHA-256 — each record hashes its own canonical payload together with the previous record's hash — and attested by RFC 3161 timestamp tokens from an independent timestamping authority. Tampering with a historical entry breaks the chain and is detectable on export.

Availability and recovery

Automated daily backups within the EU region, retained for 30 days. Exports are available on demand so you are never dependent on our uptime for evidence you need in a procurement cycle.

Breach handling

Notification to affected clients without undue delay and within 48 hours of awareness, per section 9.

Annex III — Approved sub-processors

Sub-processorPurposeLocation of processing
SupabaseDatabase, authentication, file storageEU — Frankfurt (eu-central-1)
SkydoCross-border invoice collection and settlementIndia · funds routed through Skydo's banking partners
Hostinger Business EmailBusiness correspondence and delivery of reportsDetermined by Hostinger; we make no EU-residency claim for mailbox storage

Hosting of the public website itself involves no client personal data and is not listed as a sub-processor.

On the mailbox specifically: we have not verified which region Hostinger stores mail in, so we do not state one. Saying “EU” without having checked would be the same failure we are hired to find in other people's products. Assume correspondence may be stored outside the EU, and send scan material accordingly — which is another reason the scan is built not to need your users' data in the first place. If the region is confirmed later, this row gets updated and active clients get told, per section 12.