Skip to content
SVARA logo
Get started
Legal

Data Processing Agreement

This DPA forms part of the agreement between the customer (controller) and SVARA (processor) under the GDPR.

[placeholder — replace with lawyer-reviewed copy] This is a standard SaaS template provided for structure only. It is not legal advice and must be reviewed by qualified counsel before publication.

Last updated: [placeholder — date]

1. Roles

The customer is the controller of personal data contained in customer conversations. SVARA acts as processor and processes such data only on documented instructions from the controller.

2. Subject matter and duration

Processing lasts for the term of the subscription plus the deletion period. Subject matter: drafting and delivering replies to customer messages.

3. Categories of data and data subjects

Data subjects: the customer's end customers and staff. Data: message content, contact identifiers such as social handles, email addresses and phone numbers, and conversation metadata. [placeholder — confirm categories].

4. Sub-processors

The controller grants general authorisation for the sub-processors listed on our Security page. We give prior notice of additions and allow reasonable objection.

5. Security measures

Technical and organisational measures per Article 32: encryption in transit and at rest, access control with MFA, logging, backup and restore procedures, and personnel confidentiality obligations.

6. Assistance

We assist the controller with data subject requests, DPIAs and breach notification, and will notify the controller without undue delay after becoming aware of a personal data breach.

7. International transfers

Standard Contractual Clauses apply where required. [placeholder — attach SCC module and annexes].

8. Deletion and audit

On termination we delete or return personal data at the controller's choice. We make available information necessary to demonstrate compliance and allow audits subject to reasonable notice.