Terracode

Data Processing Agreement (DPA)

2 November 2024

1. Definitions

“Controller” means the entity that determines the purposes and means of personal data processing.

“Processor” means Terracode, which processes personal data on behalf of the Controller.

“Personal Data” means any information relating to an identified or identifiable individual.

“Sub-processor” means third-party entities engaged by Terracode to process personal data.

2. Roles and Responsibilities

Controller is responsible for ensuring lawful collection and transfer of personal data.

Terracode acts only on documented instructions from the Controller.

Terracode will not process personal data for its own purposes without consent.

3. Categories of Data Processed

Contact information (name, email, phone, company details)

Authentication and account details

Payment-related information (processed by third-party gateways; Terracode does not store card data)

Usage data (logs, device data, IP addresses, SaaS interactions)

4. Purpose of Processing

Deliver SaaS and software services

Manage accounts, billing, and subscriptions

Provide customer support and troubleshooting

Improve product performance and security

Comply with legal obligations

5. Sub-processing

Terracode may engage trusted sub-processors, including:

Cloud providers (e.g., AWS, GCP, Azure)

Payment gateways (e.g., Stripe, PayPal, local payment processors)

Analytics providers (e.g., Google Analytics)

Sub-processors will be bound by obligations equivalent to this DPA.

Terracode will notify the Controller of significant changes to sub-processors.

6. International Data Transfers

Terracode may transfer personal data outside the country of origin.

For EU customers, transfers outside the EEA will rely on:

Adequacy Decisions (where applicable), or

Standard Contractual Clauses (SCCs) approved by the European Commission.

For U.S. customers, transfers comply with CCPA and applicable state laws.

7. Data Security

Terracode implements technical and organizational measures, including:

Encryption in transit (TLS/SSL) and at rest

Role-based access controls

Logging and monitoring

Regular penetration testing and audits

Secure development lifecycle (SDLC) practices

8. Data Subject Rights

Terracode will assist the Controller in fulfilling user rights requests, including:

Right of access, rectification, and deletion

Right to restrict or object to processing

Right to data portability

Right to withdraw consent

9. Breach Notification

Terracode will notify the Controller of any personal data breach within 72 hours of discovery.

Notification will include details of the breach, mitigation steps, and corrective measures.

10. Data Retention & Deletion

Personal data is retained only as long as necessary to provide Services or comply with legal obligations.

Upon termination of the agreement, data will be securely deleted or returned upon request.

11. Audits & Compliance

Controller has the right to request information or conduct audits (subject to confidentiality).

Terracode will provide relevant certifications or reports (e.g., ISO, SOC 2, if applicable).

12. Governing Law

This DPA shall be governed by the laws of Companies act no.7 of 2007, unless otherwise agreed.