Data Processing Agreement (Template)
This DPA under Art. 28 GDPR is concluded between the tenant ("Controller") and the Userdeck operator named in the imprint("Processor") and forms part of the service agreement.
1. Subject matter and nature of processing
The Processor operates a dashboard through which the Controller views its end users' data, handles support conversations, and dispatches email. Persistent processing is limited to: pseudonymous user identifiers, product events, support conversation content (including contact addresses supplied by anonymous requesters), and hashed suppression lists. Name and email data is processed transiently at display and send time only.
2. Duration, categories, data subjects
Duration: the term of the service agreement. Data subjects: the Controller's end users and leads. Categories: identifiers, usage events, communication content.
3. Obligations of the Processor
- Process personal data only on documented instructions of the Controller;
- Ensure confidentiality commitments of all persons authorized to process;
- Implement appropriate technical and organizational measures (encryption of credentials at rest, TLS in transit, hashed suppression storage, no plaintext customer emails at rest);
- Support the Controller in answering data subject requests;
- Notify the Controller without undue delay of personal data breaches;
- Delete or return all personal data at the end of the engagement;
- Make available information necessary to demonstrate compliance (Art. 28(3)(h)).
4. Sub-processors
General authorization with prior notice of changes. Current sub-processors: hosting provider of the Userdeck infrastructure (EU).
5. Transfers
Processing takes place within the EU/EEA.
This template is provided for the beta. A countersigned copy is available on request.