Legal

Data Processing Agreement

Last updated: 1 March 2026

1. Scope and purpose

This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and DevOps-Prime ("Processor"). It governs the processing of personal data by DevOps-Prime on behalf of the Customer in connection with the DevOps-Prime Service, in accordance with GDPR Article 28.

2. Definitions

"Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR. "Customer Data" means all data submitted to or generated by the Service on the Customer's behalf.

3. Processing instructions

DevOps-Prime processes Personal Data only on documented instructions from the Customer, as set out in this DPA and the main agreement. DevOps-Prime will inform the Customer if it believes an instruction infringes applicable data protection law.

4. Confidentiality of processing

DevOps-Prime ensures that persons authorised to process Personal Data are subject to appropriate confidentiality obligations. Access to Customer Data is limited to personnel who need access to perform the Service.

5. Security measures (Article 32)

DevOps-Prime implements technical and organisational measures including: AES-256 encryption at rest; TLS 1.3 in transit; customer-scoped credential isolation; immutable audit logging; regular penetration testing; SOC 2 Type II controls (in progress). A full technical and organisational measures (TOM) document is available on request.

6. Sub-processors

DevOps-Prime uses the following categories of sub-processors: cloud infrastructure providers (AWS, GCP, Azure) for compute and storage; monitoring vendors for platform observability. A full sub-processor list is available at devops-prime.com/sub-processors. We provide 30 days notice before adding new sub-processors.

7. Data subject rights

DevOps-Prime assists the Customer in fulfilling Data Subject rights requests (access, erasure, restriction, portability) within 5 business days of receiving a request. DevOps-Prime will not respond directly to Data Subject requests without Customer authorisation.

8. Data breach notification

In the event of a Personal Data breach, DevOps-Prime will notify the Customer without undue delay, and no later than 72 hours after becoming aware of the breach, with sufficient information to allow the Customer to meet its own notification obligations.

9. Data transfers

Any transfer of Personal Data outside the EEA is governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission. DevOps-Prime's SCCs are incorporated into this DPA by reference and available on request.

10. Return and deletion

Upon termination of the Service, DevOps-Prime will, at the Customer's option, return or securely delete all Personal Data within 30 days, and provide written confirmation of deletion. Audit logs required for legal compliance are retained for the legally mandated period.

11. Audits

DevOps-Prime makes available all information necessary to demonstrate compliance with GDPR Article 28. DevOps-Prime may satisfy audit requests by providing its current SOC 2 report under NDA. On-site audits are available on request with 30 days notice, at the Customer's cost.