Data Processing Agreement
Version 2026-09-02 · in effect from 2 September 2026
Required by Article 28 GDPR. You are the controller of the data you put into DPP Build; [REGISTERED COMPANY NAME] is the processor. This forms part of the Terms of Service.
1. Subject matter and duration
We process personal data on your behalf only to provide DPP Build, for as long as your account is open and for the retention period stated in the Privacy Policy thereafter.
2. Nature and purpose
Storing, retrieving and publishing the product, material and supply-chain data you enter; authenticating the people you give access to; and delivering transactional email to them.
3. Categories of data and data subjects
Contact details of your staff who use the service, and any personal data contained in the supply-chain information you choose to enter — for example a named supplier contact. Data subjects are your personnel and, where you enter it, your suppliers' personnel.
4. Our obligations
- We process personal data only on your documented instructions.
- Everyone with access is bound by confidentiality obligations.
- We apply the security measures in clause 6 and will help you meet your own obligations under Articles 32 to 36 GDPR.
- On request at the end of the agreement we delete or return the personal data, unless we are required to keep it by law.
- We make available the information needed to demonstrate compliance and allow audits, including inspections, by you or an auditor you appoint.
5. Sub-processors
You give general authorisation for the sub-processors below. We will tell you before adding or replacing one, giving you the opportunity to object.
- Amazon Web Services EMEA SARL — Hosting, database, authentication, email delivery and content distribution. Located in Ireland (eu-west-1); email sending from the same region.
6. Security measures
Article 32 requires these to be specific rather than generic, so:
- Tenant isolation. Every data access is scoped by a tenant identifier taken from the authentication token, never from the request body. The one deliberate exception is resolving a published passport by its public GS1 identifier, which returns only what that passport already shows publicly.
- Encryption. In transit over TLS; at rest by the storage services in Ireland (AWS eu-west-1).
- Authentication. A managed identity provider; passwords are never stored by us.
- Backups. Point-in-time recovery on the primary datastore.
- Least privilege. Each service component holds only the permissions its own function requires.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notification under Article 33.
8. International transfers
Personal data is processed in Ireland (AWS eu-west-1) and is not transferred outside the European Economic Area in the normal course of operating the service. Should that change, we will rely on an appropriate Article 46 transfer mechanism and tell you beforehand.
9. Assistance with data subject requests
The service lets you access, correct, export and delete the data you hold. Where a request cannot be met through the product, write to [privacy@yourdomain] and we will assist.
10. Signature
Accepting the Terms of Service accepts this agreement; the acceptance is recorded against your account with the version and date. If your procurement process needs a countersigned copy, write to [hello@yourdomain].