Data Processing Agreement
Version 1.0 · Last updated: May 31, 2026
This Data Processing Agreement forms part of the agreement between the customer using the service for business purposes (the Controller) and Tafugti (the Processor). It applies when the Processor handles personal data on the Controller's behalf while providing the service.
1. Parties and scope
The Controller determines the purposes and means of processing personal data. The Processor processes personal data only to provide, maintain, secure, and support the service. The processing may concern customer account data, service content, and support information relating to the Controller’s personnel, customers, or other data subjects.
2. Documented instructions
The Processor will process personal data only on the Controller’s documented instructions, including instructions given through the agreement and use of the service, unless applicable law requires otherwise. If legally permitted, the Processor will inform the Controller before processing required by law.
3. Confidentiality
The Processor ensures that people authorised to process personal data are bound by confidentiality obligations and access personal data only as necessary for their duties.
4. Security
The Processor maintains appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures are reviewed in light of the nature of processing and the risks to data subjects.
5. Subprocessors
The Controller authorises the Processor to engage subprocessors as needed to provide the service. The Processor will impose data-protection obligations on subprocessors that are no less protective than this agreement and remains responsible for their performance. The Processor will provide notice of material subprocessor changes and allow the Controller to raise reasonable data-protection objections.
6. Data-subject requests
Taking into account the nature of processing, the Processor will reasonably assist the Controller with requests from data subjects to exercise their rights. If the Processor receives a request directly, it will forward the request to the Controller unless prohibited by law.
7. Personal data incidents
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data. The Processor will provide reasonably available information and assistance needed for the Controller to meet applicable notification obligations.
8. Compliance and audit support
The Processor will provide information reasonably necessary to demonstrate compliance with this agreement and assist with applicable data-protection impact assessments and regulator consultations. On reasonable notice, the Processor will support proportionate audits while protecting other customers, confidential information, and service security.
9. Deletion or return
When the service agreement ends, the Processor will delete or return personal data at the Controller’s choice, unless applicable law requires retention. Backup copies will be isolated from further processing and deleted in accordance with the Processor’s retention cycle.
10. International transfers
If personal data is transferred internationally, the Processor will use a legally recognised transfer mechanism and apply any supplementary measures required by applicable data-protection law.