Skip to content
Legal

Data Processing Agreement

This document has not been published yet.

Placeholder — no legal text on this page

This page exists so the link resolves. It deliberately contains no policy language: a generated privacy policy or set of terms would look authoritative while describing commitments your organisation has not actually made, which is a real legal exposure. Have counsel draft this before launch.

What this document needs to cover

  • Controller and processor roles — your customers control candidate data; InnoATS processes it on their instructions
  • Subject matter, duration, nature, and purpose of processing, and the categories of data subjects involved
  • The full sub-processor list, with a notification process for changes
  • Technical and organisational security measures, described specifically enough to be auditable
  • Assistance with data subject requests, impact assessments, and regulator enquiries
  • Breach notification timelines and the information provided
  • International transfer mechanism — Standard Contractual Clauses or equivalent, as applicable to your regions
  • Audit rights, and deletion or return of data on termination

Questions about data handling in the meantime? Contact us directly and we will answer specifically rather than pointing at a page.