DPA
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of any service agreement between InventiveLabs Ltd (“Processor”) and the client (“Controller”).
1. Purpose
The Processor will process personal data only for the purpose of delivering services, fulfilling contractual obligations, and supporting platform functionality.
2. Roles
Controller: Determines the purpose and means of processing.
Processor: Processes data on behalf of the Controller.
3. Processor Obligations
The Processor agrees to:
Process data only on documented instructions from the Controller
Maintain confidentiality
Implement appropriate technical and organizational security measures
Assist the Controller with data access, correction, and deletion requests
Notify the Controller of any data breach without undue delay
4. Sub‑Processors
The Processor may engage trusted sub‑processors (e.g., hosting providers, analytics tools). A list is available upon request.
5. International Transfers
Data may be stored or processed outside the Controller’s country. The Processor ensures adequate protection for all transfers.
6. Security
The Processor uses industry‑standard security measures to protect personal data from unauthorized access, loss, or misuse.
7. Data Subject Rights
The Processor will assist the Controller in responding to requests related to:
Access
Correction
Deletion
Restriction
Objection
8. Data Breach Notification
In the event of a breach, the Processor will notify the Controller promptly and provide relevant details.
9. Return or Deletion of Data
Upon termination of services, the Processor will delete or return all personal data, unless retention is required by law.
10. Governing Law
This DPA is governed by the same jurisdiction as the main service agreement.
