Data Processing Agreement
This DPA applies when you process end users’ personal data through Adetio. You are the controller; the Adetio operating entity (to be published before launch) is your processor under Article 28 GDPR. It is incorporated into our Terms of Service.
1. Roles & scope
You determine the purposes and means of processing (controller); Adetio processes personal data only to provide the platform on your documented instructions (processor). Subject matter is identity and authentication; data subjects are your end users; categories include identifiers, credentials, and authentication metadata.
2. Processing instructions
We process personal data only on your documented instructions, including this DPA and your configuration, unless EU or member-state law requires otherwise — in which case we will inform you first, where legally permitted.
3. Confidentiality & security
Personnel with access to personal data are bound by confidentiality. We implement the technical and organisational measures set out in our Security page, appropriate to the risk under Article 32 GDPR, including encryption, access control, and resilience.
4. Subprocessors
You authorise the subprocessors listed on our Subprocessors page, all located in the EU. We impose equivalent data-protection obligations on each, remain liable for their performance, and give at least 30 days’ notice of changes so you may object.
5. International transfers
We do not transfer personal data outside the EU/EEA. Should that ever change, we will rely on an adequacy decision or EU Standard Contractual Clauses and notify you in advance.
6. Data subject requests & breaches
We assist you in responding to data-subject requests and, taking account of the nature of processing, in meeting your security and impact-assessment obligations. We notify you without undue delay — and within 72 hours where feasible — of any personal-data breach affecting your data.
7. Return, deletion & audits
On termination, we return or delete personal data at your choice within 90 days, save where retention is legally required. We make available the information needed to demonstrate compliance and allow for audits, including inspections, on reasonable notice.