Draft - not legal advice. This document is a placeholder prepared for platform launch. It has not been reviewed by a solicitor. A licensed legal professional should finalise the binding version before it is relied upon.

Data Processing Agreement (DPA)

1. Subject matter

This DPA supplements the Terms of Service and governs the processing by Eazi-Business Ltd ("Processor") of personal data controlled by the Partner ("Controller").

2. Details of processing

  • Nature of processing: storage, retrieval, analysis, and transmission of personal data on behalf of the Controller for the purpose of operating the Platform.
  • Categories of data subjects: Controller’s customers, leads, and contacts.
  • Categories of personal data: names, email addresses, telephone numbers, company data, engagement metrics, communication metadata.
  • Duration: for the duration of the subscription, plus retention periods detailed in the Privacy Policy.

3. Processor obligations

  • Process personal data only on documented instructions from the Controller.
  • Ensure authorised personnel are bound by confidentiality obligations.
  • Implement appropriate technical and organisational measures (encryption at rest and in transit, tenant isolation, access controls, audit logging, MFA for administrative access).
  • Notify the Controller without undue delay (target: 72 hours) of any personal data breach.
  • Assist the Controller with data subject requests and regulatory obligations.
  • Engage sub-processors only with prior notification and under contractually equivalent obligations.

4. Sub-processors

A current list of sub-processors is maintained on request. Changes are communicated with 30 days’ notice.

5. International transfers

Where personal data is transferred outside the UK/EEA, Standard Contractual Clauses or an equivalent transfer mechanism will apply.

6. Deletion and return

On termination, the Controller may export their data within 30 days. After that, the Processor will delete or anonymise the data unless retention is required by law.

7. Audits

The Processor will make reasonable information available to demonstrate compliance and will, on reasonable request, allow audits subject to confidentiality obligations.

This page is a drafting aid only and must be replaced with a solicitor-reviewed version before launch.