Data processing agreement (DPA) template
Use this template ONLY if the TokenVeil vendor (Joopin’s Lab) provides a support service that involves potential access to the data (assisted installation, support with access to the instance, managed operations). In a standard self-hosted deployment with no vendor access, this DPA is not needed: the vendor is then not a processor (see GDPR dossier, section 1).
This template is a starting point to have reviewed by legal counsel. Bracketed fields are to be filled in.
Personal data processing agreement
Section titled “Personal data processing agreement”Between:
- [Customer organization name], hereinafter “the Controller”,
- Joopin’s Lab, hereinafter “the Processor”,
pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR).
1. Purpose
Section titled “1. Purpose”This agreement frames the processing of personal data that the Processor may carry out on behalf of the Controller as part of [describe the service: installation, technical support, managed operations of the TokenVeil instance].
2. Nature and purpose of the processing
Section titled “2. Nature and purpose of the processing”- Nature: [installation / maintenance / technical support] of the TokenVeil solution.
- Purpose: ensure the operation of the pseudonymization tool deployed at the Controller’s site.
- Duration: the duration of the service contract.
3. Categories of data and data subjects
Section titled “3. Categories of data and data subjects”- Categories of data that may be approached during the service: [to specify. In principle none, since the vendor does not access the pseudonymized data or the mapping in normal operation].
- Categories of individuals: the Controller’s staff and people mentioned in the processed content.
4. Processor obligations
Section titled “4. Processor obligations”The Processor undertakes to:
- process the data only on the Controller’s documented instructions;
- ensure the confidentiality of the persons authorized to process the data;
- implement the security measures of Article 32 (see the annex
security-measures.md); - not engage a further sub-processor without prior written authorization;
- assist the Controller with rights requests and impact assessments;
- delete or return the data at the end of the service;
- notify any data breach as soon as possible (and at the latest within [24/48] hours).
5. Data location
Section titled “5. Data location”The data stays hosted on the Controller’s infrastructure ([location: France / EU]). The Processor performs no transfer and no copy outside that infrastructure.
6. Further sub-processors
Section titled “6. Further sub-processors”The AI provider chosen by the Controller (Anthropic, Google, OpenAI, Mistral, and so on) is a further sub-processor of the Controller itself, under its own contract/DPA. It only receives pseudonymized data. This agreement does not cover that relationship.
7. Security
Section titled “7. Security”The applicable technical and organizational measures are described in the annexed security-measures.md document, which forms an integral part of this agreement.
8. Fate of the data at the end of the contract
Section titled “8. Fate of the data at the end of the contract”At the end of the service, the Processor [deletes / returns] any data it may have accessed and destroys existing copies, unless a legal retention obligation applies.
Done at [place], on [date].
For the Controller: ______________________
For the Processor: ______________________