1. Subject matter and duration of processing
This DPA governs the processing of personal data carried out by the Processor on behalf of the Controller in the context of providing the SaaS analytics and corporate user management tools. Its duration matches the term of the principal SaaS Subscription Agreement.
2. Processor obligations
AGM undertakes to:
- Process personal data only on the documented instructions of the Controller.
- Ensure that personnel authorized to process personal data have given an express commitment of confidentiality.
- Implement the technical and organizational security measures (TOMs) required by Art. 32 GDPR (AES-256 encryption at rest, TLS 1.3 in transit, role-based access control).
- Notify the Controller without undue delay, and in any event within 48 hours, of any personal data breach.
- Assist the Controller in meeting its obligations to respond to data subject access requests (DSAR) and to carry out data protection impact assessments (DPIA).
- Delete or return all personal data at the end of the provision of services, at the Controller's choice.
3. Audit and inspection assistance
The Processor shall provide the Controller with all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and equivalent provisions under the UK GDPR, LGPD, LFPDPPP, Law 25 (Quebec) and Ley 1581, and shall allow for and contribute to audits, including inspections, conducted by the Controller or by an auditor mandated by the Controller, insofar as this is required to demonstrate compliance.
Audits are subject to the following conditions:
- Notice and frequency. The Controller shall give no less than thirty (30) days' prior written notice. One (1) audit per contract year is permitted. Additional audits may be required only where (i) a personal data breach affecting the Controller's data has occurred; (ii) a competent supervisory authority (for example an EU supervisory authority, the UK ICO, the CNIL, the CAI, the ANPD, the INAI or the SIC) requests or orders an audit; or (iii) the Processor materially changes its sub-processing arrangements or security architecture.
- Manner. Audits shall be conducted during business hours and in a manner that minimizes disruption to the Processor's operations and to other customers' confidentiality. At the Processor's discretion, an audit may initially be satisfied by completing the Controller's reasonable security questionnaire and by providing current third-party certifications and audit reports (for example SOC 2 Type II or ISO/IEC 27001). On-site or remote-system inspections are reserved for the cases listed above.
- Costs. Each Party bears its own costs of preparation and participation. Where an audit is triggered by a documented security incident attributable to the Processor, the Processor shall additionally bear the reasonable, itemized external costs of that audit.
- Confidentiality. Audit findings, reports and supporting materials constitute the Processor's Confidential Information, may be used solely to verify compliance, remain subject to the confidentiality provisions of this DPA, and shall not be disclosed to any third party except where required by law or to the mandated auditor under equivalent confidentiality terms.
- Remediation. Where non-conformities are identified, the Processor shall remediate them without undue delay and, for material findings, within thirty (30) days or such other period as the Parties reasonably agree.
- Sub-processors. Where an audit requires access to a Sub-processor's records or facilities, the Processor shall use its best contractual efforts to procure such access under conditions materially equivalent to this Section.
4. Authorized sub-processors
The Controller grants general authorization for the engagement of the following essential sub-processors:
| Sub-processor | Service provided | Server location | Transfer safeguard |
|---|---|---|---|
| Cloudflare Inc. | WAF, CDN, DDoS mitigation and edge analytics | Global / USA / EU | EU-US DPF / SCCs |
| Amazon Web Services (AWS) | Database storage and compute | USA / EEA (Ireland) | Standard Contractual Clauses (SCCs) |
| Stripe Inc. | Payment processing and secure billing | USA / Global | PCI-DSS Level 1 / DPF |
| Resend / SendGrid | Transactional email and alert delivery | USA | Standard Contractual Clauses (SCCs) |
Sub-processor change mechanism: AGM will give at least fifteen (15) days' notice of any addition or replacement of sub-processors, by notice in the control panel or by email, and the Controller may raise a reasoned objection.
