Last updated: 2 October 2026

Data processing agreement

The agreement uses the European Commission’s controller–processor standard clauses, Decision (EU) 2021/915. The customer must complete the parties and confirm instructions, security measures and authorised subprocessors before signing. This is a draft, not an executed agreement or legal advice.

The annexes describe actual access controls, selected-field encryption, links, logs and retention gaps. Provider agreements, regions and backups need review before external customer data is processed. English is the contractual language of this draft.