Legal
Data Processing Agreement
This document has not been published yet.
Placeholder — no legal text on this page
This page exists so the link resolves. It deliberately contains no policy language: a generated privacy policy or set of terms would look authoritative while describing commitments your organisation has not actually made, which is a real legal exposure. Have counsel draft this before launch.
What this document needs to cover
- Controller and processor roles — your customers control candidate data; InnoATS processes it on their instructions
- Subject matter, duration, nature, and purpose of processing, and the categories of data subjects involved
- The full sub-processor list, with a notification process for changes
- Technical and organisational security measures, described specifically enough to be auditable
- Assistance with data subject requests, impact assessments, and regulator enquiries
- Breach notification timelines and the information provided
- International transfer mechanism — Standard Contractual Clauses or equivalent, as applicable to your regions
- Audit rights, and deletion or return of data on termination
Questions about data handling in the meantime? Contact us directly and we will answer specifically rather than pointing at a page.
