Data Processing Agreement (DPA)
1. Definitions
“Controller” means the entity that determines the purposes and means of personal data processing.
“Processor” means Terracode, which processes personal data on behalf of the Controller.
“Personal Data” means any information relating to an identified or identifiable individual.
“Sub-processor” means third-party entities engaged by Terracode to process personal data.
2. Roles and Responsibilities
Controller is responsible for ensuring lawful collection and transfer of personal data.
Terracode acts only on documented instructions from the Controller.
Terracode will not process personal data for its own purposes without consent.
3. Categories of Data Processed
Contact information (name, email, phone, company details)
Authentication and account details
Payment-related information (processed by third-party gateways; Terracode does not store card data)
Usage data (logs, device data, IP addresses, SaaS interactions)
4. Purpose of Processing
Deliver SaaS and software services
Manage accounts, billing, and subscriptions
Provide customer support and troubleshooting
Improve product performance and security
Comply with legal obligations
5. Sub-processing
Terracode may engage trusted sub-processors, including:
Cloud providers (e.g., AWS, GCP, Azure)
Payment gateways (e.g., Stripe, PayPal, local payment processors)
Analytics providers (e.g., Google Analytics)
Sub-processors will be bound by obligations equivalent to this DPA.
Terracode will notify the Controller of significant changes to sub-processors.
6. International Data Transfers
Terracode may transfer personal data outside the country of origin.
For EU customers, transfers outside the EEA will rely on:
Adequacy Decisions (where applicable), or
Standard Contractual Clauses (SCCs) approved by the European Commission.
For U.S. customers, transfers comply with CCPA and applicable state laws.
7. Data Security
Terracode implements technical and organizational measures, including:
Encryption in transit (TLS/SSL) and at rest
Role-based access controls
Logging and monitoring
Regular penetration testing and audits
Secure development lifecycle (SDLC) practices
8. Data Subject Rights
Terracode will assist the Controller in fulfilling user rights requests, including:
Right of access, rectification, and deletion
Right to restrict or object to processing
Right to data portability
Right to withdraw consent
9. Breach Notification
Terracode will notify the Controller of any personal data breach within 72 hours of discovery.
Notification will include details of the breach, mitigation steps, and corrective measures.
10. Data Retention & Deletion
Personal data is retained only as long as necessary to provide Services or comply with legal obligations.
Upon termination of the agreement, data will be securely deleted or returned upon request.
11. Audits & Compliance
Controller has the right to request information or conduct audits (subject to confidentiality).
Terracode will provide relevant certifications or reports (e.g., ISO, SOC 2, if applicable).
12. Governing Law
This DPA shall be governed by the laws of Companies act no.7 of 2007, unless otherwise agreed.
