Data Processing Addendum
Effective: [Date of your acceptance] · Version: 1.0
Draft pending legal review. This document is a structured starting point that satisfies the topics required by Article 28 GDPR. It has not yet been signed off by external counsel. Please have it reviewed against your specific processing arrangements before signature. The English text is the authoritative version; translations are provided for convenience.
1. Parties
This Data Processing Addendum (the "DPA") is entered into between:
- Atitic, MB, a company incorporated in Lithuania, registration number 308087362, registered at Statybininkų g. 1A-63, 03205, Vilnius (the "Processor", "Atitic"); and
- [Your organisation], registration number [Your registration number], registered at [Your registered address] (the "Controller", "Customer").
This DPA is incorporated into, and forms an integral part of, the Terms of Service between the Parties. In the event of conflict between the Terms of Service and this DPA on any data-protection matter, this DPA prevails.
2. Definitions
Capitalised terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679) or in the Terms of Service. "Data Protection Laws" means the GDPR, the EU e-Privacy Directive as implemented in each Member State, and any successor or supplementing national data-protection legislation applicable to the Processing under this DPA. "Personal Data", "Data Subject", "Processing", "Controller", "Processor", "Sub-processor" and "Supervisory Authority" have the meanings given in the GDPR.
3. Subject-matter, duration, nature and purpose of Processing
Subject-matter. Processing of Personal Data by the Processor in connection with providing the Service to the Controller under the Terms of Service.
Duration. For as long as the Controller's subscription to the Service is active, plus the retention window in Section 15 of this DPA.
Nature. Storage, retrieval, indexing, backup, transmission, restricted disclosure to Sub-processors, and any other operations necessary to operate the Service and comply with the Controller's documented instructions.
Purpose. Enabling the Controller to plan, evidence and audit its own compliance programme using the Service, and providing associated support.
4. Types of Personal Data
The Personal Data Processed under this DPA is determined by the Controller through its and its Authorised Users' use of the Service. It typically includes:
- Identification data of the Controller's staff, contractors, customers, and other data subjects listed in the Controller's records of processing activities (RoPA);
- Contact data (business email, phone) of the same individuals;
- Employment / role information relevant to the Controller's compliance programme (e.g. training assignments, policy acknowledgements);
- Content of security incidents, breach notifications, DSAR requests, DPIAs and other compliance workflows the Controller executes in the Service;
- Any other Personal Data the Controller chooses to upload as evidence or attachments.
The Processor does not require, and shall not intentionally Process, special categories of Personal Data (Art. 9 GDPR) or criminal-conviction data (Art. 10 GDPR). If the Controller uploads such data, it warrants it has a lawful basis for doing so.
5. Categories of Data Subjects
- Employees, workers, contractors and job applicants of the Controller;
- Customers, prospects, and business contacts of the Controller;
- Data subjects whose records appear in the Controller's own RoPA, DPIA, breach notifications, DSAR responses, or evidence uploads;
- Any other categories the Controller determines through its use of the Service.
6. Rights and obligations of the Controller
The Controller warrants that:
- It is entitled to disclose the Personal Data to the Processor and has a valid legal basis for the Processing;
- It has provided any notices and obtained any consents required by Data Protection Laws before uploading Personal Data to the Service;
- The instructions it gives to the Processor via the Service or otherwise are lawful and consistent with the Terms of Service and this DPA.
The Controller is responsible for the accuracy, quality and legality of the Personal Data it uploads, and for the means by which it acquired that data.
7. Obligations of the Processor
The Processor shall:
- (a) Process only on documented instructions. Process Personal Data only on the Controller's documented instructions, which are (i) the Terms of Service, (ii) this DPA, and (iii) any use of the Service by the Controller's Authorised Users. Additional written instructions may be given by email to [email protected]. If the Processor believes an instruction infringes Data Protection Laws, it shall notify the Controller without undue delay.
- (b) Confidentiality. Ensure that its personnel authorised to Process Personal Data are bound by contractual or statutory obligations of confidentiality.
- (c) Security. Implement the technical and organisational measures set out in Annex II (Section 18 below) to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
- (d) Sub-processors. Engage Sub-processors only under the conditions in Section 9 of this DPA.
- (e) Data Subject requests. Taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for exercising Data Subject rights.
- (f) Assistance with Articles 32-36. Assist the Controller in ensuring compliance with obligations pursuant to Articles 32 to 36 GDPR taking into account the nature of the Processing and the information available to the Processor.
- (g) Return or deletion. At the choice of the Controller, delete or return all Personal Data after the end of the provision of Services relating to Processing, and delete existing copies unless Union or Member State law requires storage.
- (h) Records + audits. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and allow for and contribute to audits, including inspections, as further set out in Section 12.
8. Personal Data breach notification
The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Controller's Personal Data. The notification shall, to the extent then known:
- describe the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
- state the name and contact details of the Processor's data-protection contact ([email protected]);
- describe the likely consequences of the breach; and
- describe the measures taken or proposed to address the breach and mitigate its adverse effects.
The Processor shall provide follow-up information in phases where all information is not available at the time of the initial notification. The Processor's notification is not an acknowledgement of fault or liability.
9. Sub-processors
General authorisation. The Controller grants the Processor a general authorisation to engage Sub-processors, provided that the Processor:
- (a) maintains a list of current Sub-processors (Section 17, Annex I);
- (b) notifies the Controller of any intended additions or replacements of Sub-processors at least 30 days in advance via in-product notice or email to the account owner, giving the Controller the opportunity to object;
- (c) imposes on each Sub-processor, by contract, data-protection obligations no less protective than those in this DPA; and
- (d) remains fully liable to the Controller for the performance of each Sub-processor's obligations.
Objections. If the Controller reasonably objects on data-protection grounds within 30 days of notification, the Parties shall discuss in good faith. If no resolution is reached, the Controller may terminate the affected Services and receive a pro-rata refund of pre-paid fees for the unused portion of the term.
10. International transfers
In the default deployment, Personal Data is Processed within the European Union and does not leave the EU. Where a Sub-processor Processes Personal Data outside the EU/EEA, the Processor shall put in place a valid transfer mechanism under Chapter V GDPR, which shall include:
- the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) in the appropriate module, incorporated by reference; and/or
- where applicable, the EU-US Data Privacy Framework certification of the recipient; and
- any supplementary measures identified by a transfer impact assessment.
Copies of the executed transfer safeguards are available on written request.
11. Data Subject requests
If a Data Subject contacts the Processor directly in relation to Personal Data Processed on the Controller's behalf, the Processor shall (a) promptly notify the Controller, and (b) not respond substantively without the Controller's written instructions, save to acknowledge receipt and refer the Data Subject to the Controller.
The Processor shall assist the Controller in responding to Data Subject requests within the timelines set by Article 12(3) GDPR by making available appropriate self-service tools in the Service (data-subject export, deletion, restriction, access log) and by providing reasonable ad-hoc assistance.
12. Audits and inspections
The Controller may verify the Processor's compliance with this DPA once per calendar year, and additionally following a Personal Data breach or on the reasonable request of a Supervisory Authority, by:
- reviewing the most recent audit reports, penetration-test executive summaries, and security policies made available by the Processor under NDA;
- submitting a documented written questionnaire that the Processor shall answer within a reasonable time; and/or
- where the above is insufficient, conducting an on-site audit at a mutually agreed date and time, subject to reasonable confidentiality and security arrangements. The Controller shall bear its own costs and any reasonable third-party costs of the audit; the Processor shall bear its internal personnel costs.
The Processor shall promptly rectify any material non-compliance identified by an audit at its own cost.
13. Deletion and return on termination
Following termination or expiry of the Services, the Controller may export its Personal Data self-service using the Portability Report (JSON, XLSX, PDF) for a period of 30 days. Following that window, and unless Union or Member State law requires further storage:
- the Processor shall delete Personal Data from primary systems within a further 30 days;
- backups containing Personal Data shall roll off on the standard backup rotation (currently 30 days);
- a deletion certificate is available on written request.
The Controller may also request return or deletion of specific Personal Data at any time during the subscription by using the in-product tools or by written request to [email protected].
14. Liability
Liability under this DPA is subject to the limitation of liability set out in the Terms of Service, save that neither party excludes or limits liability where such exclusion or limitation is prohibited by Data Protection Laws.
15. Term and termination
This DPA takes effect on the date accepted by the Controller and remains in force for as long as the Processor Processes Personal Data on the Controller's behalf. Sections 8 (breach notification), 12 (audits), 13 (deletion), 14 (liability), and this Section 15 survive termination for as long as necessary to give them effect.
16. Governing law and jurisdiction
This DPA is governed by Lithuanian law. The courts of the courts of Vilnius, Lithuania have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to any statutory rights of Data Subjects.
17. Annex I – List of Sub-processors
The following Sub-processors are engaged as of the effective date of this version. Changes are notified per Section 9.
| Sub-processor | Purpose | Region |
|---|---|---|
| EU datacenter provider (EU) | Compute + primary Postgres hosting | EU |
| S3-compatible object storage (Locally hosted Minio) | Encrypted evidence + attachment storage | EU |
| Stripe Payments Europe | Payment processing, invoicing, subscription lifecycle | EU + Ireland |
| Mailjet (Sinch) | Transactional and branded outbound email | EU (France) |
| Google – Gemini API | Optional AI features (Ask Atitic, evidence proposals) | Model calls routed to EU endpoints where available |
| Cloudflare | Edge CDN, DNS, TLS termination, bot mitigation | Global anycast; Personal Data in HTTP headers only |
| HashiCorp Vault (self-hosted) | Secrets and encryption-key management | EU (same datacenter as primary) |
18. Annex II – Technical and organisational measures
The Processor shall implement the following measures, which may be updated from time to time provided the level of protection is not diminished.
Access control. Role-based access control (RBAC) with per-module permissions at read / manage / approve granularity. MFA available for all Customer users; SAML 2.0 and OIDC single sign-on supported; SCIM 2.0 provisioning on eligible plans. Privileged Atitic staff access to production requires MFA, uses short-lived credentials, and is fully logged.
Tenant isolation. PostgreSQL row-level security (RLS) with a per-request tenant context. Every tenant-scoped table has RLS forced, so no privileged application role can bypass it. Object storage segregates tenant data by prefix and per-object access policy.
Encryption in transit. TLS 1.2+ enforced for all client and service-to-service traffic. HSTS on the platform hosts. Certificates rotated automatically.
Encryption at rest. Postgres data files and object-storage buckets encrypted with AES-256 or equivalent. Backups encrypted independently. Secrets stored in HashiCorp Vault with envelope encryption.
Backups and disaster recovery. Continuous point-in-time WAL streaming plus daily base backups retained for 30 days. Object storage versioned with a 30-day lifecycle window. Backups stored in an EU region separate from the primary. RTO 4 hours, RPO 15 minutes, tested at least annually.
Vulnerability management. Third-party penetration test at least annually and after material architectural changes. Remediation SLA: critical – 72 hours, high – 14 days, medium – 60 days, low – 180 days. Automated dependency scanning of first-party and container images.
Audit logging. Tamper-evident audit log capturing actor, target, timestamp, and payload for every mutation. Exportable via API and included in the Portability Report.
Personnel. Personnel authorised to Process Personal Data are bound by contractual confidentiality obligations that survive termination of their engagement.
Physical security. Data-centre facilities operated by the EU datacenter provider hold ISO 27001 (or equivalent) certification; badge-controlled access, 24/7 monitored perimeters, and environmental controls.
19. Contact
Data-protection queries relating to this DPA: [email protected].
Security queries: [email protected].
Postal: Atitic, MB, Statybininkų g. 1A-63, 03205, Vilnius.