Data Processing Agreement

Last Updated: July 2026 · Version 2.0

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Deznot SRL ("Processor") and the customer entity ("Controller") for the processing of personal data in connection with the Deznot platform.

1. Scope and Applicability

This DPA applies to all processing of personal data Subject to Regulation (EU) 2016/679 (GDPR) conducted by Processor on behalf of Controller in performance of the services.

2. Processing Instructions

Processor shall process personal data solely on documented instructions from Controller, including with respect to transfers of personal data to a third country, unless required by EU or Member State law.

3. Security Measures

Processor implements technical and organizational measures to ensure security:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Role-based access controls (RBAC) with principle of least privilege
  • Automated vulnerability scanning and security audit logging
  • Regular backup procedures with encrypted offsite storage

4. Sub-Processors

Controller grants general authorization to Processor to engage sub-processors. Processor maintains a list of active sub-processors at /subprocessors. Processor will notify Controller 30 days prior to engaging any new sub-processor.

5. International Data Transfers

Transfers outside the EU/EEA are conducted under European Commission Standard Contractual Clauses (SCCs) as approved by the European Commission (Implementing Decision 2021/914), supplemented by transfer impact assessments where required.

6. Data Breach Notification

We will notify the Controller of any personal data breach within 48 hours of becoming aware of it, providing: (a) nature of the breach, (b) categories and approximate number of data subjects and records, (c) likely consequences, (d) measures taken or proposed.

7. Deletion of Data

Upon termination of services, we will delete all personal data processed on behalf of the Controller within 90 days, except where retention is required by law. A deletion certificate will be provided upon request.

8. Audit Rights

The Controller may audit our compliance with this DPA upon reasonable notice (not less than 14 days). Audits may be conducted by the Controller's internal team or a third-party auditor under NDA, not more than once per calendar year.

9. Contact

For DPA-related inquiries: legal@deznot.com