Stratify
Legal and compliance

Data Processing Agreement — Template

docs/compliance/isms/privacy/PRIV-05-data-processing-agreement-template.md

Source updated 03. Aug. 2026

Data Processing Agreement — Template

Net new: no equivalent exists today. This is Stratify's own paper, structured against GDPR Art. 28, to be offered to a counterparty when a B2B partner relationship or a future processor arrangement requires terms Stratify issues, as opposed to the DPAs Stratify signs as a customer of its own sub-processors (tracked in PRIV-06 / register/suppliers.yaml). This is a fill-in template, not a signed instance — every bracketed field is completed per counterparty at execution.

As PRIV-02 documents, no live processor-role activity exists yet, so this template has not been executed against any counterparty as of this version. It exists so that when the trigger PRIV-02 § "What would flip this determination" fires, Stratify is not drafting DPA terms from scratch under time pressure.

1. Subject matter and duration

[Counterparty] engages Stratify to process personal data on its behalf for the purpose described in §2, for the duration of the underlying commercial agreement between the parties, or as otherwise specified in the applicable order form / statement of work.

2. Nature and purpose of processing

[Description of the specific processing activity — e.g., "processing partner end-customer identifiers for personalized signal routing"]. General processing purpose: to provide the service described in the commercial agreement; Stratify processes personal data only as necessary to deliver that service.

3. Categories of data subjects and data

  • Data subjects: [e.g., the counterparty's end-customers]
  • Categories of personal data: `[e.g., identifiers, transaction metadata — no card/IBAN data,

consistent with Stratify's existing architecture where payment data never reaches Stratify infrastructure, PRIV-01 row 3]`

4. Processor obligations (Art. 28(3)(a)–(h))

  • (a) Documented instructions. Stratify processes personal data only on the counterparty's

documented instructions, including regarding international transfers, unless required otherwise by applicable law (in which case Stratify informs the counterparty before processing, unless prohibited).

  • (b) Confidentiality. Personnel authorized to process the data are bound by confidentiality.

At Stratify's current team size this is the ISMS Owner and DPO/Privacy Owner (GOV-03); this clause scales as the team grows.

  • (c) Security (Art. 32). Stratify implements the technical and organisational measures

documented in PRIV-04 — RLS access control, append-only chain-hashed audit logging, hardened OTP authentication, Tailscale-only host firewalling — and keeps that document current as the baseline this clause references.

  • (d) Sub-processor engagement. See §5 below.
  • (e) Assistance with data subject rights. Stratify assists the counterparty in responding to

Art. 12–22 requests to the extent the processing under this agreement is involved, using the export/erasure mechanisms documented in PRIV-09 (pending) and already implemented in apps/web/lib/admin/gdpr-export.ts and eraseSubscriberData.

  • (f) Assistance with Art. 32–36 obligations. Stratify assists with security, breach

notification, DPIA, and prior-consultation obligations to the extent it holds information the counterparty needs.

  • (g) Deletion or return on termination. On termination, Stratify deletes or returns all

personal data processed under this agreement, and deletes existing copies, unless law requires storage (e.g., the audit-trail retention already applied to gdpr.erasure.completed events under Stratify's own controller-role processing, PRIV-01 row 7, is not disturbed by this clause — it concerns Stratify's own audit obligations, not the counterparty's data).

  • (h) Audit rights. Stratify makes available information necessary to demonstrate compliance

with this article and allows for, and contributes to, audits including inspections conducted by the counterparty or an auditor it mandates, on reasonable notice.

5. Sub-processor authorization

Recommended position: general authorization with a notification right, not per-sub-processor consent — consistent with how Stratify's own sub-processor list (PRIV-06) already operates and avoids a contractual bottleneck on routine vendor changes. Stratify:

  • maintains the current sub-processor list at PRIV-06 / register/suppliers.yaml;
  • commits to the change-notification period stated there (proposed 30 days, pending Antonios

confirmation);

  • reviews sub-processor status on the cadence set by procedures/PRO-10 (Sub-processor onboarding

& review, pending) — this clause should be read together with that procedure once it exists;

  • gives the counterparty the right to object to a new sub-processor on reasonable grounds within

the notice period, escalating to termination rights if unresolved.

6. Liability

[Standard liability allocation — cap, carve-outs for data protection breaches, indemnification — to be filled per counterparty and reviewed against the commercial agreement's own liability terms. Not pre-populated here since it is deal-specific, unlike the operational clauses above.]

7. International transfers

Where processing under this agreement involves a transfer outside the EEA/Switzerland, Standard Contractual Clauses (or an equivalent adequacy mechanism) apply, consistent with the approach already documented for Stratify's own sub-processors in dsgvo-data-flow.md §6.

Review

This template is reviewed whenever PRIV-04's TOM baseline changes materially, whenever PRO-10 is written and gives it a concrete review cadence to point to, and before its first actual use against a counterparty.