Data processing agreement
Last updated 1 August 2026
When Compliancy processes personal data on behalf of a customer, we act as a processor and the customer acts as controller. This page summarises the terms; the executed DPA governs.
Roles and scope
The customer determines the purposes and means of processing. Compliancy processes personal data only on documented instructions from the customer, as needed to provide the platform.
Security measures
We maintain technical and organisational measures appropriate to the risk, including access control, encryption in transit and at rest, logging, and change management.
Subprocessors
Subprocessors are engaged under written terms with equivalent obligations. The current list is published and customers are notified of changes.
International transfers
Where personal data is transferred internationally, we rely on an appropriate transfer mechanism, such as the European Commission standard contractual clauses.
Assistance and breach notification
We assist the customer with data subject requests and impact assessments as required, and notify the customer without undue delay after becoming aware of a personal data breach affecting their data.
This page is a summary of our current position. Contact legal@compliancy.example.com for the executed contractual documents that apply to your organisation.