DPA

Data Processing Agreement.

A signed DPA is provided to every customer before any production data is uploaded. It is negotiated alongside the commercial agreement and is not a downloadable PDF, because procurement conditions vary by customer.

What our DPA contains

The DPA defines the scope, duration, nature, and purpose of the processing Calbarry performs on behalf of the customer; the categories of data subjects and personal data; and the rights and obligations of both parties under Article 28 of the GDPR.

It incorporates the EU Commission’s Standard Contractual Clauses (Decision 2021/914) where applicable, and is structured to be acceptable to enterprise procurement and the data-protection officers of EU customers.

Topics covered

  • Subject-matter, duration, nature, and purpose of processing.
  • Types of personal data processed and categories of data subjects.
  • Confidentiality commitments for all personnel with access to personal data.
  • Technical and organisational measures (TOMs), aligned with the controls described on the Security page.
  • Sub-processor list and the right of the customer to object to material changes.
  • Data subject request handling and timelines.
  • Personal data breach notification (within 72 hours of becoming aware, in line with GDPR Article 33).
  • Audit and inspection rights, including third-party audits.
  • Return or deletion of personal data at the end of the engagement.
  • EU-only data residency commitments.

Sub-processors

Our DPA includes an exhibit listing the sub-processors involved in providing the Service, the role of each, and the location of processing. The current list is provided on request and is updated in advance of any material change. Customers may object to a proposed change.

Request a copy

For procurement review, audit, or contract negotiation, request a copy of the DPA via the contact form. Please indicate the legal entity that will sign and your expected go-live date.

Request the DPA →