Data Processing Agreement (DPA)
Rasiya — Processor Terms Version: [FILL: v1.0] · Last updated: [FILL: date]
Draft for review — must be reviewed by counsel before offering to clients. This DPA is the agreement Rasiya enters into as a processor when it processes personal data on behalf of a client (the controller) while delivering AI agents, automation, and related services. It is the document linked from the footer and the security page. It is not the website privacy policy (see privacy-policy.md).
This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or order ("Agreement") between the Client ("Controller") and Rasiya ([FILL: legal entity name], "Processor"). Where Rasiya processes personal data on the Controller's behalf, this DPA applies and prevails over conflicting terms in the Agreement on the subject of data protection.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", and "sub-processor" have the meanings given in the GDPR (Regulation (EU) 2016/679).
2. Roles and scope of processing
The Controller determines the purposes and means of processing; Rasiya processes personal data only on the Controller's documented instructions. The subject matter, duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects are set out in Annex 1.
3. Rasiya's obligations
Rasiya shall:
a. process personal data only on the Controller's documented instructions, including for transfers, unless required by law (in which case it will inform the Controller unless legally prohibited); b. ensure persons authorised to process the data are bound by confidentiality; c. implement the technical and organisational security measures in Annex 2 (Art. 32 GDPR); d. respect the conditions in Section 5 for engaging sub-processors; e. assist the Controller, by appropriate measures, in responding to data-subject requests (access, rectification, erasure, etc.); f. assist the Controller with security, breach notification, data protection impact assessments, and prior consultation (Arts. 32–36); g. at the Controller's choice, delete or return all personal data at the end of the services and delete existing copies, unless retention is required by law; and h. make available information necessary to demonstrate compliance and allow for and contribute to audits, as set out in Section 7.
4. Personal data breach
Rasiya will notify the Controller without undue delay, and in any case within [FILL: e.g. 48] hours, after becoming aware of a personal data breach affecting the Controller's data, with the information reasonably available to support the Controller's own notification obligations.
5. Sub-processors
The Controller provides general written authorisation for Rasiya to engage sub-processors, provided Rasiya (a) imposes data-protection obligations on each sub-processor equivalent to this DPA, and (b) remains liable for their performance. The current sub-processors are listed in Annex 3. Rasiya will inform the Controller of intended changes and give the Controller a chance to object on reasonable data-protection grounds.
6. International transfers
Rasiya will not transfer personal data outside the EEA except under an appropriate safeguard (e.g. Standard Contractual Clauses, an adequacy decision, or the EU–US Data Privacy Framework). [FILL: note any transfer to the Dubai entity and the safeguard relied upon.]
7. Audits
Rasiya will make available the information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits, including inspections, by the Controller or an auditor it mandates, on reasonable notice, no more than [FILL: once] per year (or following a breach), subject to confidentiality and Rasiya's security policies.
8. Liability and term
The liability of each party under this DPA is subject to the limitations of liability in the Agreement. This DPA remains in effect for as long as Rasiya processes personal data on the Controller's behalf.
Annex 1 — Details of processing
- Subject matter: [FILL: e.g. delivery and operation of AI agents and automation workflows for the Controller]
- Duration: for the term of the Agreement
- Nature & purpose: [FILL: e.g. ingesting, classifying, generating, and routing data through AI agents]
- Types of personal data: [FILL: e.g. names, business contact details, support-ticket content, etc.]
- Categories of data subjects: [FILL: e.g. the Controller's customers, leads, and employees]
Annex 2 — Security measures
See Rasiya's security overview at https://rasiya.ai/security, including: encryption in transit and at rest, role-based access control, least-privilege, logging and monitoring, secure development practices, vendor due diligence, and incident response. [FILL: align with the controls actually described on /security.]
Annex 3 — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| [FILL: e.g. Vercel] | Hosting / infrastructure | [FILL] |
| [FILL: model/API providers, e.g. Anthropic] | AI model inference | [FILL] |
| [FILL: …] | [FILL] | [FILL] |