Data Processing Agreement
This DPA forms part of the agreement between the customer (controller) and SVARA (processor) under the GDPR.
Last updated: [placeholder — date]
1. Roles
The customer is the controller of personal data contained in customer conversations. SVARA acts as processor and processes such data only on documented instructions from the controller.
2. Subject matter and duration
Processing lasts for the term of the subscription plus the deletion period. Subject matter: drafting and delivering replies to customer messages.
3. Categories of data and data subjects
Data subjects: the customer's end customers and staff. Data: message content, contact identifiers such as social handles, email addresses and phone numbers, and conversation metadata. [placeholder — confirm categories].
4. Sub-processors
The controller grants general authorisation for the sub-processors listed on our Security page. We give prior notice of additions and allow reasonable objection.
5. Security measures
Technical and organisational measures per Article 32: encryption in transit and at rest, access control with MFA, logging, backup and restore procedures, and personnel confidentiality obligations.
6. Assistance
We assist the controller with data subject requests, DPIAs and breach notification, and will notify the controller without undue delay after becoming aware of a personal data breach.
7. International transfers
Standard Contractual Clauses apply where required. [placeholder — attach SCC module and annexes].
8. Deletion and audit
On termination we delete or return personal data at the controller's choice. We make available information necessary to demonstrate compliance and allow audits subject to reasonable notice.