Data Processing Agreement

Effective date: [Effective Date] · Last updated: [Last Updated Date]

This Data Processing Agreement ("DPA") is a standard template that, when executed, forms part of the agreement (the "Agreement") between Twin Raven Studios, Inc. ("we," "us," "Processor") and the customer organization that subscribes to the Portanus platform ("Customer," "Controller"). It governs our processing of personal data on the Customer's behalf in the course of providing the Service.

This DPA addresses controller-to-processor obligations under the EU and UK General Data Protection Regulation (in particular Article 28) and comparable data protection laws. Where the Customer is a HIPAA covered entity or business associate and the Service is used to process protected health information, a separate HIPAA Business Associate Agreement (BAA) is available and governs that processing; this DPA does not replace the BAA.

1. Definitions

  • Controller — the party that determines the purposes and means of processing personal data (the Customer).
  • Processor — the party that processes personal data on behalf of the Controller (us).
  • Personal data — any information relating to an identified or identifiable natural person that is processed under the Agreement.
  • Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
  • Sub-processor — a third party engaged by us to process personal data in connection with the Service.
  • Data subject — the identified or identifiable natural person to whom personal data relates.

Terms such as "supervisory authority," "personal data breach," and "appropriate technical and organizational measures" have the meanings given in applicable data protection law.

2. Subject matter, nature, purpose, and duration

The subject matter of the processing is the provision of the Portanus platform to the Customer. The nature and purpose of the processing is to host, operate, secure, and support the Service so that the Customer can manage its operations. We process personal data only for that purpose and as instructed by the Customer. Processing continues for the duration of the subscription term and until data is deleted or returned in accordance with Section 9.

3. Categories of data subjects and personal data

The categories of data subjects and personal data are determined by the Customer through its use of the Service and may include, by way of example: [list categories of data subjects, e.g. applicants, clients, staff, volunteers, donors] and [list categories of personal data, e.g. contact details, application records, and any special-category data the Customer elects to store]. The categories actually processed are described further in our Privacy Policy and the Customer's configuration of the Service.

4. Processor obligations

We will:

  • process personal data only on the Customer's documented instructions, including the Agreement and this DPA, unless legally required otherwise (in which case we will inform the Customer unless prohibited by law);
  • ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations;
  • implement appropriate technical and organizational security measures, as described in our security program, taking into account the state of the art, the costs of implementation, and the nature and risk of the processing;
  • engage sub-processors only as permitted in Section 5 and impose data protection obligations on them that are substantially the same as those in this DPA (flow-down);
  • taking into account the nature of the processing, assist the Customer by appropriate measures in responding to requests from data subjects exercising their rights;
  • assist the Customer in ensuring compliance with its obligations regarding security of processing, personal data breach notification, and data protection impact assessments (DPIAs); and
  • at the Customer's choice, delete or return all personal data at the end of the provision of the Service, and delete existing copies unless retention is required by law.

5. Sub-processors

The Customer provides general authorization for us to engage sub-processors to support the Service. We maintain a list of current sub-processors and will give notice of intended additions or replacements so that the Customer has the opportunity to object on reasonable data protection grounds. Where the Customer reasonably objects, the parties will work in good faith to address the concern.

6. International transfers

Where processing involves a transfer of personal data to a country without an adequacy decision, we will ensure an appropriate transfer safeguard is in place, such as Standard Contractual Clauses or another mechanism recognized under applicable law ([transfer mechanism / SCC reference]).

7. Audits and information rights

We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, and security and operational constraints. Where available, we may satisfy audit requests through third-party reports or summaries of our security program.

8. Personal data breach notification

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide information reasonably available to us to help the Customer meet its own notification obligations. Our notification is not an acknowledgment of fault or liability.

9. Return and deletion of data

On termination or expiry of the Service, we will, at the Customer's choice, return or delete the Customer's personal data within 30 days and delete remaining copies, except where retention is required by law. Data handling on termination is also described in our Privacy Policy.

10. Liability and order of precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. In the event of a conflict, this DPA prevails over the Agreement with respect to the subject matter of data protection, and any executed HIPAA Business Associate Agreement prevails over this DPA with respect to protected health information.

11. Governing law and contact

This DPA is governed by the laws of [Governing Jurisdiction], except where applicable data protection law requires otherwise. Questions or data protection requests can be directed to [data protection contact email].


This document is a standard template provided for transparency and is not legal advice. It should be reviewed and tailored by qualified counsel, completed with order-specific details, and executed before being relied upon.