Legal
Data Processing Agreement
Last updated: 1 March 2026
1. Scope and purpose
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and DevOps-Prime ("Processor"). It governs the processing of personal data by DevOps-Prime on behalf of the Customer in connection with the DevOps-Prime Service, in accordance with GDPR Article 28.
2. Definitions
"Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR. "Customer Data" means all data submitted to or generated by the Service on the Customer's behalf.
3. Processing instructions
DevOps-Prime processes Personal Data only on documented instructions from the Customer, as set out in this DPA and the main agreement. DevOps-Prime will inform the Customer if it believes an instruction infringes applicable data protection law.
4. Confidentiality of processing
DevOps-Prime ensures that persons authorised to process Personal Data are subject to appropriate confidentiality obligations. Access to Customer Data is limited to personnel who need access to perform the Service.
5. Security measures (Article 32)
DevOps-Prime implements technical and organisational measures including: AES-256 encryption at rest; TLS 1.3 in transit; customer-scoped credential isolation; immutable audit logging; regular penetration testing; SOC 2 Type II controls (in progress). A full technical and organisational measures (TOM) document is available on request.
6. Sub-processors
DevOps-Prime uses the following categories of sub-processors: cloud infrastructure providers (AWS, GCP, Azure) for compute and storage; monitoring vendors for platform observability. A full sub-processor list is available at devops-prime.com/sub-processors. We provide 30 days notice before adding new sub-processors.
7. Data subject rights
DevOps-Prime assists the Customer in fulfilling Data Subject rights requests (access, erasure, restriction, portability) within 5 business days of receiving a request. DevOps-Prime will not respond directly to Data Subject requests without Customer authorisation.
8. Data breach notification
In the event of a Personal Data breach, DevOps-Prime will notify the Customer without undue delay, and no later than 72 hours after becoming aware of the breach, with sufficient information to allow the Customer to meet its own notification obligations.
9. Data transfers
Any transfer of Personal Data outside the EEA is governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission. DevOps-Prime's SCCs are incorporated into this DPA by reference and available on request.
10. Return and deletion
Upon termination of the Service, DevOps-Prime will, at the Customer's option, return or securely delete all Personal Data within 30 days, and provide written confirmation of deletion. Audit logs required for legal compliance are retained for the legally mandated period.
11. Audits
DevOps-Prime makes available all information necessary to demonstrate compliance with GDPR Article 28. DevOps-Prime may satisfy audit requests by providing its current SOC 2 report under NDA. On-site audits are available on request with 30 days notice, at the Customer's cost.