Data Processing Agreement
Data processing terms between Sovern Cloud (the data processor) and your organization (the data controller).
Last updated: TBD · Operator: Sovern Cloud
Status
This Data Processing Agreement (DPA) is currently a route shell. Substantive DPA copy — including sub-processor list, data categories, transfer mechanisms (SCCs / adequacy decisions / DPF), security measures (Annex II), and audit rights — is authored by Sovern Cloud legal counsel post-incorporation. See /trust/legal-entities for the canonical operator registry, and /trust/sub-processors for the live sub-processor disclosure.
Roles
Data Controller: your organization (the customer). Determines the purposes and means of processing personal data.
Data Processor: Sovern Cloud. Processes personal data only on documented instructions from the controller.
Substantive clauses (placeholder)
The following clauses will be populated by counsel and rendered in this section: subject matter and duration; nature and purpose of processing; categories of data and data subjects; controller and processor obligations; security of processing (Article 32 GDPR); sub-processors and prior authorization; international transfers; audits and inspections; assistance with data subject rights and breach notification; deletion or return of data; liability; governing law and jurisdiction.
Execution
DPA execution flow (signature ceremony, version stamp, counterparty disclosure) will land via the substrate-canonical signed-bundle primitive once substantive content is ratified by Sovern Cloud counsel.