Home/Data Processing Agreement

Data Processing Agreement

Last updated: March 27, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between DataProjects ("Processor") and the client ("Controller") for the provision of data products and annotation services. This DPA sets out the terms under which we process personal data on your behalf.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on personal data, including collection, storage, use, and deletion.
  • "Data Subject" means the individual whose personal data is being processed.
  • "Sub-processor" means any third party engaged by the Processor to process personal data.

3. Scope of Processing

The Processor shall process personal data only:

  • On documented instructions from the Controller
  • To the extent necessary to perform the agreed services
  • In compliance with applicable data protection laws

4. Data Security

The Processor implements appropriate technical and organizational measures including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and updates
  • Employee training on data protection
  • Incident response and breach notification procedures

5. Confidentiality

The Processor ensures that all personnel authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Sub-processors

The Processor shall not engage any sub-processor without prior written authorization from the Controller. Where sub-processors are engaged, the Processor shall impose the same data protection obligations on the sub-processor as set out in this DPA.

7. Data Subject Rights

The Processor shall assist the Controller in responding to requests from data subjects exercising their rights under applicable data protection laws, including the right to access, rectification, erasure, and data portability.

8. Data Breach Notification

The Processor shall notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach. The notification shall include the nature of the breach, categories of data affected, and measures taken to address the breach.

9. Data Deletion

Upon termination of the services or at the Controller's request, the Processor shall delete or return all personal data processed on behalf of the Controller, unless retention is required by applicable law.

10. International Transfers

Where personal data is transferred outside the jurisdiction of the Controller, the Processor shall ensure appropriate safeguards are in place in accordance with applicable data protection laws.

11. Duration

This DPA shall remain in effect for the duration of the processing activities. Obligations regarding confidentiality and data security shall survive the termination of this DPA.

12. Contact

For questions about this Data Processing Agreement or to request a signed copy, please contact us at:

DataProjects — Data Protection

Email: [email protected]

Website: dataprojects.net