Legal
Data Processing Agreement
The agreement covering our role as processor of the data inside your backups — the document your privacy team will ask for first.
This document is in preparation. It is not yet in force.
Below is the structure the final text will cover, published so you can see what will be in it. We have deliberately not filled it with generated legal wording — text that reads like a contract and binds nobody is worse than an honest gap. If you need the current draft for a review, email sales@securive.net.
Roles: controller and processor
You are the controller of the data inside your workloads; we process it on your documented instructions. Everything else follows from this.
Subject matter, duration and nature of processing
Backup, replication, retention and restore of customer data for the term of the subscription.
Categories of data and data subjects
Necessarily broad — backup content is whatever the customer's systems contain — and must say so rather than pretending to a precision that doesn't exist.
Processor obligations
Process only on instruction, confidentiality obligations on personnel, and assistance with data-subject requests.
Security measures
Technical and organisational measures, aligned to the controls published on /security. Must not claim a control the product does not implement.
Sub-processors
The current list, the notification mechanism for additions, and the customer's right to object.
International transfers
Transfer mechanism and safeguards, reconciled with the region selection the product actually offers.
Personal data breach notification
Notification without undue delay and within 72 hours of awareness, with what information the notification will contain.
Audit and inspection rights
What the customer may audit, how often, and what we provide in lieu of an on-site audit.
Deletion and return on termination
Export window, deletion timeline, and confirmation of deletion on request.
Liability under this agreement
How this interacts with the liability cap in the Terms.