Data Processing Agreement (DPA)
Version 0.0.1 · effective 24 August 2026
Contents
- 1 · Subject matter, duration, nature, purpose
- 2 · Documented instructions
- 3 · Confidentiality
- 4 · Security (art. 32)
- 5 · Sub-processors
- 6 · Assistance to the controller
- 7 · Reciprocal deletion and revocations, flow-through (the distinctive clause)
- 8 · Breach notification
- 9 · Deletion and return
- 10 · Audits
- 11 · Liability and indemnity
- 12 · International transfers
- 13 · Regime modules
- Annex I · Processing detail
- Annex II · Technical and organizational measures (real state 2026-08-08)
- Annex III · Sub-processors (initial list)
- Annex IV · Art. 14 notice template for the Customer
Parties. "Datta" (DATTTA LLC, a Delaware limited liability company (United States), file 10563369, formed on 26 March 2026, trading as «Datta», with its address at 1201 N Orange St, Ste 7665, Wilmington, DE 19801-1186, United States), processor; and the "Customer" (the business identified in the account), controller. Where the Customer acts as a processor for a third party, Datta is a sub-processor and the Customer warrants its instructions are compatible with its controller's.
1 · Subject matter, duration, nature, purpose
Datta processes personal data on the Customer's behalf solely to provide the service described in Annex I: sealed data custody, identity verification of people the Customer invites (with each person's direct consent), grant-based access management, and the agenda/ network flows when the Customer enables them. Duration: the life of the Customer's account plus the section «Deletion and return» deletion cycle.
2 · Documented instructions
Datta processes only on the Customer's documented instructions (product configuration, invoked APIs, and this DPA are the instructions). If Datta believes an instruction violates the law, it informs without delay and may suspend that instruction.
2.0.1 House rule, explicit. Datta does not use Customer data for its own purposes. Not to sell it, not to train models, not to build products on it, ever.
2.0.2 Operational statistics. Datta does keep aggregate measurement of how the service runs (volumes, latencies, errors, availability, and billable consumption) without which it could not operate, secure, or invoice it. That measurement contains no Customer content, cannot be attributed to any particular individual, and is not shared with third parties. It is neither commercial analytics nor profiling.
2.1 Structural boundary: data a person keeps in THEIR personal vault belongs to that person under the Terms and privacy policy; the Customer reaches only what each subject granted. This DPA covers what the Customer processes; it grants no rights over personal vaults.
3 · Confidentiality
Authorized personnel under contractual confidentiality. Datta's administrative staff cannot see users' email or phone (stored encrypted; the admin context does not decrypt them) and every individual lookup is audited.
4 · Security (art. 32)
The measures in Annex II: described as they ARE today, gaps declared with their plan, because an aspirational security annex is a lawsuit with a future date. Datta notifies the Customer 30 days ahead of material changes that reduce protection.
5 · Sub-processors
General authorization with a live list (Annex III and datta.global/legal/subprocessors). Datta gives 30 days' notice of additions/changes for reasoned objection; unresolved objections let the Customer terminate the affected part of the service. Datta binds every sub-processor in writing to equivalent obligations and remains liable for them.
6 · Assistance to the controller
- Data subject rights: the product self-serves most (access, export, deletion, grant revocation); for the rest, Datta assists within ≤10 business days.
- Arts. 32–36: reasonable assistance with security, breach notification, DPIAs, and prior consultations, with the information only the processor holds.
- If a data subject contacts Datta about the Customer's processing, Datta redirects them to the Customer without answering on the merits (unless legally required).
7 · Reciprocal deletion and revocations, flow-through (the distinctive clause)
7.1 When a data subject exercises reciprocal deletion or revokes a grant, Datta executes it in its systems and the Customer undertakes to honor the same deletion/revocation in its internal systems fed from Datta within ≤15 days, save a documented legal retention duty.
7.2 The Customer's acknowledgment is recorded as evidence. Evidence never contains the deleted datum.
7.3 The Customer shall not re-acquire a deleted datum through other channels to circumvent the deletion (anti-circumvention rule).
8 · Breach notification
Datta notifies the Customer without undue delay and at the latest within 48 hours of confirming a breach affecting Customer data, with art. 33(3) content and updates as the investigation advances. Notifying authorities and data subjects is the Customer's role (controller); Datta assists. The audit schema already models incidents and notification records.
9 · Deletion and return
At termination the Customer chooses return (export) or deletion. The real deletion and backup cycle: retention policy, immediate operational deletion, backups clear within ≤14 days by rotation, evidence without the datum. Exception: whatever law requires keeping, isolated and blocked.
10 · Audits
Once a year (or after a material breach), 30 days' notice, business hours, no access to other customers' data or to secrets that would compromise security: documentation and reports first (Datta holds no SOC 2 or ISO 27001 certification today), inspection second if that does not suffice. Customer's cost unless a material finding.
11 · Liability and indemnity
11.1 Each party's liability under this DPA is subject to the limits in the business services agreement, which sets an enhanced cap for breach of the data protection obligations. If the Customer has not accepted that agreement, the limits in the Terms apply.
11.2 The Customer holds Datta harmless for: unlawful instructions; processing without its own legal basis; uploading third-party data without authorization or notice (art. 14, Annex IV provides the template); and breaching the section «Reciprocal deletion and revocations, flow-through (the distinctive clause)» flow-through.
11.3 Datta holds the Customer harmless for breaches of this DPA caused by Datta's willful misconduct or gross negligence.
12 · International transfers
Actual locations and residency policy (Canada/US/Europe only): privacy policy. For EEA/UK/Swiss customers, the SCCs (2021/914), module 2 or 3 per the Customer's role, are incorporated by reference with the UK Addendum and Swiss annex Annexes I to III of this DPA operate as the appendices to those modules.
13 · Regime modules
- CCPA/CPRA (California): Datta is a "service provider"; it does not sell or share personal information; does not retain/use/disclose it outside the service; does not combine it except as permitted; and certifies it understands these restrictions. Consumer rights: the section «Assistance to the controller».
- Colombia (Ley 1581, Decreto 1377 art. 25): this DPA is the transmission/transfer contract; the Customer warrants each subject's prior authorization; processor duties per arts. 17–18.
- Mexico (LFPDPPP): Datta as encargado under the current law; the Customer answers for its privacy notice; remission clauses included.
- Ecuador / Panama / El Salvador: mirror clauses.
Annex I · Processing detail
| Field | Value |
|---|---|
| Data subjects | The Customer's employees, candidates, clients, and contacts; people the Customer invites to verify |
| Data categories | Identification and contact; documents; employment; financial data the Customer requests; verification result (the face is processed only on the subject's device) |
| Special categories | Verification biometrics (on-device); others only if the Customer requests them under its own basis |
| Operations | Encrypted custody, verification, grant management, deletion with evidence, export |
| Duration | Account life + retention cycle |
Annex II · Technical and organizational measures (real state 2026-08-08)
Operating: TLS 1.3 + 2-year HSTS; Argon2id; AES-256-GCM envelope encryption for sensitive catalog fields, account email, the address book (double envelope), and push tokens; HMAC blind indexes instead of identifiers; 15-minute tokens with rotation and denylist; passkeys and device binding; per-IP/user/identifier rate limiting; append-only, cryptographically chained audit verified against production, with actor attribution (including AI agents); disclosure records without identifiers; read-only admin without email/phone access, every individual lookup audited; GPG-encrypted backups with an offsite copy at a different provider/country; CORS allowlist; admin surface off the public vhost.
In deployment, declared (not counted as a measure until it ships): field-level encryption of the generic payload; dedicated KMS for master keys (today environment variables on the VM); retention engine; physical purge; OS keychain in the console; certifications (none today).
Annex III · Sub-processors (initial list)
| Sub-processor | Function | Location |
|---|---|---|
| Server infrastructure | Hosts the service | Canada, the United States or Europe |
| Offsite backup | Keeps an encrypted copy | Canada |
| Transactional email | Delivers the service's emails | United States |
| Messaging and voice | Delivers verification codes | Global (carriers) |
| Google (FCM) | Push | Global |
Annex IV · Art. 14 notice template for the Customer
For when the Customer uploads data about people who are not Datta users. Deliver within one month, or at first communication, whichever comes first.
"[Customer] uses Datta to hold and verify contact data securely. We store your [categories] under [Customer's legal basis], for [purpose]. Datta keeps it encrypted; neither Datta nor other users can read it. You can request access, correction, or deletion from [Customer contact], or delete yourself directly from Datta without creating an account at [non-user notice URL]. Complaint authority: [the subject's]."
Version 0.0.1 · Last updated: 24 August 2026 · Controller: DATTTA LLC (trading as «Datta») · Contact: datta.global/contact