DATA PROCESSING ADDENDUM

This Data Processing Addendum (“DPA”) forms part of the Terms of Service (“Agreement”) between xxx (“Controller”) and Dia Partners OÜ (“Processor”).

Effective Date: xx.yy.zzzz

1. Roles

The parties acknowledge that, for the limited processing described herein, the Controller is the data controller and the Processor is the data processor as defined under applicable data protection laws (including GDPR and any equivalent legislation).

2. Subject Matter & Duration

The Processor may process certain personal data provided by the Controller in connection with the Agreement, for the sole purpose of providing the services described in the Agreement. Processing will continue for the term of the Agreement unless otherwise agreed or required by law.

3. Nature & Purpose of Processing

Processing is incidental to the provision of the services and may include storage, transmission, or deletion of data necessary to operate the platform and facilitate interactions between the Controller and third parties. 

Purpose: to enable the operation of the Controller’s account and related reporting within the Processor’s platform.

4. Categories of Data & Data Subjects

Data Subjects: the Controller’s employees, contractors, or customers.

Data Types: email addresses, names, and other similar contact details.

5. Processor Obligations

The Processor shall:

  1. a) Process personal data only on documented instructions from the Controller.
  2. b) Ensure persons authorised to process personal data are bound by confidentiality.
  3. c) Implement appropriate technical and organisational measures to protect data.
  4. d) Assist Controller in responding to data subject requests.
  5. e) Notify Controller without undue delay of any personal data breach
  6. f) Assist Controller with any required data protection impact assessments.

6. Sub-Processors

The Processor may use sub-processors (e.g., hosting providers) to process data. The Processor will ensure such sub-processors are bound by written terms offering at least the same level of protection. The Controller gives general authorisation to such sub-processing.

7. International Transfers

Any transfer of personal data outside the country of origin will be subject to appropriate safeguard.

8. Return or Deletion

Upon termination of the Agreement, the Processor will delete or return all personal data to the Controller, unless retention is required by law.

9. Audit

Upon reasonable request, the Processor will provide information necessary to demonstrate compliance and allow for audits, subject to reasonable notice and confidentiality.

10. Liability

The liability provisions in the Agreement apply to this DPA. In case of conflict, this DPA prevails with respect to data protection obligations.

Signed for and on behalf of:

[Partner Name] (Controller)

Name: ___________________
Title: ____________________
Date: ____________________

Dia Partners OÜ (Processor)
Name: ___________________
Title: ____________________
Date: ____________________