Data Processing Agreement
DPA designed to align with GDPR Article 28, defining data-processing terms, security obligations, and sub-processor arrangements for enterprise clients. Not a third-party certification.
Executive Summary
Compliance & Certifications
Data Classification Levels
Non-sensitive business information
Examples: Marketing materials, public APIs
Standard business data
Examples: Usage analytics, support logs
Sensitive business information
Examples: Research data, client information
Highly sensitive personal data
Examples: Medical records, genetic data
Technical & Organizational Measures (TOM)
TLS 1.3 in transit, AES-256 at rest
All data encrypted with industry-leading algorithms
MFA, RBAC, zero-trust architecture
Principle of least privilege enforced
Hosted on SOC 2-audited providers
Geo-redundant infrastructure targets
24/7 monitoring, quarterly penetration tests
Continuous compliance verification
Biometric, hardware tokens, SSO
Multi-layered identity verification
Encrypted backups, 15-minute RPO
4-hour RTO with automated failover
Data Subject Rights
Right of Access
Request a copy of personal data we process
Response: 30 daysRight to Rectification
Correct inaccurate or incomplete data
Response: 14 daysRight to Erasure
Request deletion of personal data
Response: 30 daysRight to Restrict
Limit how we process your data
Response: 72 hoursRight to Portability
Receive data in machine-readable format
Response: 30 daysRight to Object
Object to processing for specific purposes
Response: 72 hours1. Definitions and Interpretation
This Data Processing Agreement ("DPA") forms part of the Master Service Agreement between PlanckChron Inc. ("Processor") and Customer ("Controller"). This DPA is effective upon the date the Customer accepts the Terms of Service.
- Personal Data: Any information relating to an identified or identifiable natural person ("Data Subject")
- Processing: Any operation or set of operations performed on Personal Data
- Data Subject: The individual to whom Personal Data relates
- Sub-processor: Third party engaged by Processor to process Personal Data
2. Scope of Processing
This DPA applies to all Processing of Personal Data by PlanckChron on behalf of Customer in connection with the Services. The scope includes:
Data Categories Processed
- • User account information and credentials
- • Research data and experimental results
- • Clinical trial participant information
- • Analytics and usage telemetry
Processing Activities
- • Collection, storage, and retrieval
- • Analysis and aggregation
- • Transfer and transmission
- • Deletion and anonymization
3. Processor Obligations
PlanckChron, as the Processor, commits to the following binding obligations:
4. Authorized Sub-Processors
Customer authorizes PlanckChron to engage the following Sub-processors. Changes will be notified 30 days in advance.
| Sub-processor | Service | Location | Safeguards | Data Types |
|---|---|---|---|---|
| AWS | Cloud Hosting | United States | SCCs, SOC 2, ISO 27001 | All customer data |
| Supabase | Database Services | United States | SCCs, SOC 2, GDPR | Application data |
| Vercel | Application Hosting | United States | SCCs, SOC 2 | Frontend assets |
| Stripe | Payment Processing | United States | PCI-DSS, SCCs | Payment information |
| Cloudflare | CDN & Security | Global | SOC 2, ISO 27001 | Traffic data |
| SendGrid | Email Delivery | United States | SOC 2, SCCs | Email addresses |
Customer may object to Sub-processor changes within 15 business days of notification.
5. International Data Transfers
Personal Data may be transferred to and processed in the United States and other jurisdictions. Such transfers are protected by:
Standard Contractual Clauses (SCCs)
EU Commission-approved clauses for controller-to-processor transfers
Binding Corporate Rules
Internal policies ensuring consistent data protection across entities
Adequacy Decisions
Transfers to countries with adequate protection levels
Supplementary Measures
Additional technical safeguards including encryption and pseudonymization
6. Data Breach Notification
In the event of a Personal Data breach, PlanckChron will notify Customer without undue delay and no later than 48 hours after becoming aware of the breach.
Notification Will Include:
- • Description of breach nature and scope
- • Categories and volume of data affected
- • Number of Data Subjects impacted
- • Likely consequences and risk assessment
Remediation Actions:
- • Immediate containment measures
- • Ongoing mitigation steps
- • Contact point for further information
- • Support for regulatory notification
7. Audit Rights
Controller has the right to audit Processor's compliance with this DPA, subject to the following:
8. Term, Termination & Data Retention
This DPA remains in effect for the duration of the Service Agreement. Upon termination:
Data Return Options:
- Export in standard formats (JSON, CSV, XML)
- API access for 30 days post-termination
Data Deletion:
- Secure deletion within 90 days
- Certificate of destruction provided
Related Documents
Privacy Policy
Data protection and privacy practices
Terms of Service
Comprehensive service terms and conditions
Cookie Policy
Information about cookies and tracking
California Privacy Notice
CCPA/CPRA disclosures and consumer rights
Subprocessors
Current subprocessors and processing purposes
Corporate Governance
Board structure and compliance framework
Contact Information
For questions or concerns, please contact the appropriate department:
Privacy Team
DPA inquiries and data protection requests
Data Protection Officer
GDPR compliance and regulatory matters
Legal Affairs
Contract negotiations and enterprise DPAs
Corporate Headquarters
Planckchron Inc
11601 Wilshire Boulevard, Suite 500
Los Angeles, CA 90025
United States
Registered Office
Corporation Trust Company
1209 Orange Street
Wilmington, DE 19801
