Data Processing Agreement (DPA)
Pursuant to Art. 28 GDPR · [CONFIGURE]
1. Parties & Roles
Processor: [CONFIGURE], [CONFIGURE], [CONFIGURE] [CONFIGURE], Österreich (UID ATU75614667).
Controller: the Customer (deployer of the platform).
This DPA governs processing of personal data by the Processor on behalf of the Controller under Art. 28 GDPR.
2. Subject Matter & Duration
The Processor processes personal data solely to provide the SovereignCity AI service for the duration of the subscription.
3. Nature & Purpose of Processing
Hosting, storage, computation of governance evaluations, audit logging, and user authentication. No civic governance data is used for commercial purposes — enforced by architectural zone isolation.
4. Categories of Data Subjects & Data
Platform users (administrators, auditors, viewers). Data: name, email, role, authentication credentials (hashed), audit metadata (IP, timestamps).
5. Technical & Organisational Measures (Art. 32)
bcrypt password hashing (cost 12); JWT with HS256; Fernet encryption of audit payloads; tamper-evident hash-chained audit log; role-based access control (6 roles); rate limiting; agent zone isolation; 7-year audit retention; documented H1–H18 hardening.
6. Sub-processors
The Processor engages infrastructure sub-processors (hosting). A current list is available on request. The Controller is notified of changes with a right to object.
7. Data Subject Rights
The Processor assists the Controller in fulfilling rights of access (Art. 15), erasure (Art. 17), and portability (Art. 20) via built-in GDPR tooling.
8. Data Breach Notification
The Processor notifies the Controller without undue delay (and within 72 hours where feasible) after becoming aware of a personal data breach.
9. Deletion & Return
Upon termination, personal data is deleted or returned per the Controller's choice, except where Union or Member State law requires retention (e.g. audit records under the EU AI Act).
10. Audits
The Processor makes available information necessary to demonstrate compliance and allows for audits per Art. 28(3)(h).