Last Updated: August 14, 2025
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between DataPlant (“Processor”) and the customer (“Controller”) and reflects the parties’ agreement regarding the processing of personal data in connection with the Services.
2. Definitions
“Controller” means the entity that determines the purposes and means of processing personal data.
“Processor” means the entity that processes personal data on behalf of the Controller.
“Personal Data” means any information relating to an identified or identifiable natural person.
“Processing” means any operation performed on personal data, whether automated or not.
3. Scope of Processing
Processor will process Personal Data solely for the purposes of providing the agreed Services and in accordance with Controller’s documented instructions, unless required to do so by law.
4. Controller Responsibilities
The Controller is responsible for ensuring that it has the necessary rights and consents to provide Personal Data to the Processor for processing.
5. Processor Obligations
- Process Personal Data only as instructed by the Controller.
- Implement appropriate technical and organizational measures to protect Personal Data.
- Ensure personnel involved in processing are bound by confidentiality obligations.
- Assist the Controller in fulfilling data subject requests under applicable laws.
6. Sub-Processors
The Controller authorizes the Processor to engage sub-processors to assist in delivering Services, provided that Processor ensures such sub-processors are bound by similar data protection obligations.
7. International Data Transfers
Where Personal Data is transferred outside the Controller’s jurisdiction, Processor will ensure appropriate safeguards are in place as required by applicable data protection laws.
8. Security Measures
Processor will maintain security measures designed to protect the confidentiality, integrity, and availability of Personal Data, including encryption, access control, and regular monitoring.
9. Data Breach Notification
Processor will notify Controller without undue delay upon becoming aware of a personal data breach and provide details to assist in meeting any legal obligations.
10. Data Retention & Deletion
Upon termination of Services, Processor will delete or return all Personal Data to the Controller unless otherwise required by law.
11. Audits & Compliance
Processor will make available to Controller all necessary information to demonstrate compliance with this DPA and applicable laws, and allow for audits, subject to reasonable notice.
12. Governing Law
This DPA will be governed by the laws specified in the main Terms and Conditions agreement.