This Data Processing Agreement ("DPA") is entered into between:
together the "Parties".
This DPA forms part of the Service Agreement between the Parties.
This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with website development, deployment, integration, and optional managed services.
The Parties agree that:
The Processor processes personal data only on documented instructions from the Controller.
The Processor may process personal data for the purpose of:
Depending on the Client's implementation, the Processor may process:
The Processor does not intentionally collect sensitive personal data unless instructed by the Controller.
Data subjects may include:
The Processor shall:
The Controller authorises the Processor to use third-party service providers ("Sub-processors") where necessary, including infrastructure providers such as hosting, database, analytics, and payment processors.
These may include services such as Supabase, Netlify, Stripe, YouTube, and Spotify.
The Processor shall ensure that any Sub-processors are subject to appropriate data protection obligations.
Personal data may be transferred or stored outside the United Kingdom or European Economic Area where Sub-processors operate. In such cases, appropriate safeguards will be implemented where required by law.
The Processor shall implement appropriate technical and organisational measures to protect personal data, including:
The Processor shall notify the Controller without undue delay upon becoming aware of a personal data breach affecting Client data.
Upon termination of services, the Processor shall:
The Processor shall reasonably assist the Controller in demonstrating compliance with applicable data protection laws, including UK GDPR.
The Controller is responsible for:
The Processor's liability under this DPA is subject to the limitations set out in the Service Agreement, except where such limitation is not permitted under applicable law.
This DPA terminates automatically upon termination of the Service Agreement, subject to any continuing obligations regarding data deletion or return.
This DPA is governed by the laws of England and Wales.
Charlie@archiva.tv