Legal
Data Processing Addendum.
The DPA forms part of our Master Services Agreement when we process personal data on your behalf.
Last updated · 2026-10-02
Definitions
Capitalized terms used here have the meaning given in the GDPR, UK GDPR, and the underlying Master Services Agreement (MSA). For convenience: 'Controller', 'Processor', 'Data Subject', 'Personal Data', and 'Processing' have the meanings given in Article 4 GDPR. 'Customer' means the entity entering the MSA with Diviteb. 'Customer Personal Data' means Personal Data that Diviteb processes on Customer's behalf under the MSA. 'Sub-processor' means a third party engaged by Diviteb to process Customer Personal Data.
Roles
Customer is the Controller (or Processor acting on behalf of an upstream Controller). Diviteb acts as a Processor (or Sub-processor) when it processes Customer Personal Data on Customer's behalf under the MSA. Each party is responsible for compliance with its respective obligations under applicable Data Protection Laws.
Scope and purpose of processing
Diviteb processes Customer Personal Data only for the purposes described in the SOW, work order, or specific written instruction from Customer. Diviteb doesn't process Customer Personal Data for its own purposes, sell or share it with third parties (other than Sub-processors as permitted), or move it across regions without Customer's prior written instruction.
Categories of data and data subjects
The categories of Personal Data and Data Subjects vary by engagement and are set out in the SOW. Typical categories include:
- Customer's end-users (where Diviteb works on Customer's customer-facing systems) — name, email, account identifiers, behavioral data limited to what's needed for the engagement.
- Customer's employees and contractors (where Diviteb works on Customer's internal systems) — name, work email, role, organizational unit.
- Customer's prospects and customers (advertising engagements) — lead-form submissions, conversion events, and hashed contact details used for custom audiences.
- Special-category data — only where the SOW explicitly contemplates it, with corresponding controls.
Duration
Diviteb processes Customer Personal Data for the duration of the MSA and any wind-down period explicitly agreed in writing. Within 30 days of termination, Diviteb returns or deletes Customer Personal Data per Customer's instruction, unless retention is required by applicable law (e.g., for tax records).
Sub-processors
Diviteb may engage Sub-processors to perform specific processing activities. The current list of Sub-processors is below. Diviteb gives Customer 30 days' notice of any new or replacement Sub-processor; Customer may object in writing within that window for legitimate data-protection reasons.
- Cloud infrastructure — Customer's chosen cloud provider (AWS, GCP, Azure, Vercel, Cloudflare). We operate within Customer's accounts unless otherwise agreed.
- Source control — GitHub or Customer's chosen platform.
- Communication and project management — Slack, Linear, Notion, Google Workspace (or Customer's chosen platforms).
- Credentials and secrets — 1Password, AWS Secrets Manager, or Customer's chosen secret manager.
- Advertising platforms — Meta, Google, TikTok, LinkedIn, Microsoft, and others named in the SOW. Where Diviteb manages advertising, data is processed in Customer's own ad accounts under Customer's agreements with those platforms.
- Engagement-specific Sub-processors are listed in the SOW.
Technical and organizational measures
Diviteb maintains technical and organizational measures appropriate to the risk, including:
- Encryption — TLS 1.2+ in transit, AES-256 (or equivalent) at rest for Personal Data Diviteb stores or controls.
- Access controls — least-privilege, hardware-key MFA, scoped per engagement, reviewed quarterly, revoked at engagement end.
- Pseudonymization and anonymization — applied to Personal Data used in development or test environments wherever practical.
- Resilience — backup, disaster-recovery procedures with quarterly tested restores.
- Confidentiality — every Diviteb individual processing Personal Data has signed a confidentiality undertaking and received Data Protection training.
- Vulnerability management — secret scanning, dependency scanning, and SAST in CI; critical findings triaged within 48 hours.
- Incident response — 24-hour acknowledgement, 72-hour notification of confirmed incidents to affected Customers; written post-mortem within 14 days.
Cross-border transfers
Where Customer Personal Data is transferred outside the EEA, UK, or Switzerland, the parties rely on:
- The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller-to-Processor) or Module Three (Processor-to-Processor), as applicable.
- The UK International Data Transfer Addendum (issued by the ICO), where the UK GDPR applies.
- Equivalent safeguards under the Swiss FADP where applicable.
- Supplementary measures (encryption, pseudonymization, contractual rights to challenge requests) where a transfer-impact assessment requires them.
Data subject rights
Diviteb assists Customer in fulfilling Data Subject requests, including access, rectification, erasure, restriction, portability, and objection. We forward requests received directly to Customer within 5 business days and don't respond on Customer's behalf without Customer's instruction.
Personal data breaches
Diviteb notifies Customer without undue delay (and in any case within 72 hours) of becoming aware of a Personal Data breach affecting Customer Personal Data. The notification includes the nature of the breach, categories and approximate number of Data Subjects and records concerned, likely consequences, and measures taken or proposed.
Audits
Customer (or an independent auditor on Customer's behalf) may audit Diviteb's compliance with this DPA once per calendar year, with 30 days' written notice and during normal business hours, subject to reasonable confidentiality and security restrictions. For audits requested more frequently, in response to a documented incident, or in lieu of Diviteb's own SOC 2 / ISO 27001 attestation when those become available, Customer covers reasonable costs.
Liability and term
The MSA's liability framework applies to this DPA. This DPA is effective from the start of the MSA and terminates on the later of MSA termination or final return/deletion of Customer Personal Data.
Conflicts
If a conflict exists between this DPA and the MSA in respect of the processing of Customer Personal Data, this DPA controls. If a conflict exists between this DPA and the SCCs / UK Addendum, the SCCs / UK Addendum control.
Contact
DPA questions, requests for the latest sub-processor list, or audit coordination: [email protected] (cc [email protected]).
Legal questions
Reach out before you sign.
We'll redline your master agreement, sign your NDA, and clear procurement before kickoff.