Data Processing Agreement
This Data Processing Agreement ("DPA") is between Tyqra, Inc., a Delaware corporation ("Provider"), and the customer that enters into a written agreement incorporating this DPA ("Customer"). It applies only when Provider processes personal data on Customer's behalf in connection with a contracted service.
1. Roles and instructions
Customer is the controller or business, and Provider is the processor or service provider, unless applicable law assigns different roles. Provider will process personal data only on documented Customer instructions, including the applicable agreement, except where law requires otherwise.
2. Scope of processing
The subject matter, duration, nature, purpose, data categories, and data subjects are described in the applicable order form, service description, or processing schedule. Depending on the purchased service, data may include support-ticket content, business contact information, account identifiers, device information, audit events, and messages submitted through authorized integrations.
3. Confidentiality and security
Provider will ensure that personnel authorized to process personal data are subject to confidentiality obligations and will maintain reasonable administrative, technical, and organizational safeguards appropriate to the risk. Specific security commitments, if any, are stated in the applicable service agreement or security schedule.
4. Subprocessors
Customer authorizes Provider to use subprocessors to deliver the contracted service. Before production processing begins, Provider will make the then-current subprocessor list available to Customer and provide notice of material additions as required by the applicable agreement. Provider remains responsible for each subprocessor's processing to the extent required by applicable law.
5. Assistance and incidents
Taking into account the nature of processing and information available to Provider, Provider will reasonably assist Customer with data-subject requests, security obligations, impact assessments, and regulator inquiries. Provider will notify Customer without undue delay after confirming a personal-data breach affecting Customer data, as required by applicable law and the service agreement.
6. Return and deletion
At the end of the contracted service, Provider will return or delete Customer personal data as stated in the applicable agreement, unless law requires retention. Routine backup copies may remain until overwritten under Provider's normal retention cycle, subject to continued protection.
7. International transfers
If a restricted international transfer occurs, the parties will use a lawful transfer mechanism required by applicable law, which may include the applicable Standard Contractual Clauses and any required transfer addendum.
8. Information and audits
Provider will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Audit procedures, frequency, confidentiality, cost allocation, and use of independent reports are governed by the applicable agreement.
9. Priority and contact
If this DPA conflicts with a written service agreement, the provision that gives greater protection to personal data controls to the extent permitted by law. Questions may be sent to legal@tyqra.app.