# Data Processing Agreement (DPA) — Template

> **This is a template, ready to send.** Fill the `{{PLACEHOLDERS}}`, review with your own counsel,
> and attach it to the master agreement. It reflects how BeyondCore actually processes data (Zero
> Data Retention, DLP allowlist, EU hosting). It is not legal advice.

This Data Processing Agreement ("**DPA**") forms part of the agreement between:

- **Controller:** {{CUSTOMER_LEGAL_NAME}}, {{CUSTOMER_ADDRESS}} ("**Customer**"), and
- **Processor:** BeyondCore, Org.nr 559155-2129, Sweden ("**BeyondCore**"),

each a "party" and together the "parties", and governs BeyondCore's processing of Personal Data on
behalf of the Customer in connection with the BeyondCore service (the "**Service**").

## 1. Roles and scope
1.1 The Customer is the **controller** and BeyondCore is the **processor** of the Personal Data
processed under the Service. Where the Customer is itself a processor, BeyondCore is a sub-processor.
1.2 BeyondCore processes Personal Data only on the Customer's **documented instructions**, including
those set out in this DPA and the Customer's use of the Service, unless required by EU or member-state
law (in which case BeyondCore informs the Customer unless legally prohibited).

## 2. Nature and purpose of processing
Data quality assessment of the Customer's master data: detecting duplicates, invalid records, missing
fields and inconsistencies, and returning explained, recommend-only suggestions. Processing is
**recommend-only**; BeyondCore does not write back to the Customer's source systems.

## 3. Duration
Processing lasts for the term of the underlying agreement. On termination, Section 9 applies.

## 4. Zero Data Retention (data minimisation)
4.1 The Customer's raw master-data **extract is processed in memory and discarded** at the end of each
assessment request. It is **not** persisted by BeyondCore.
4.2 BeyondCore persists only the **assessment result** (scores, counts, per-finding evidence snippets,
and record identifiers) needed for the Customer to act on and track quality over time.
4.3 Where the optional AI Engine is used, only a **positive allowlist of non-identifying fields** is
transmitted to the AI sub-processor (Annex III), which is configured for **no training and no
retention**. Identifiers (VAT/tax IDs, email, phone, bank/IBAN, credit limits, payment terms) are
withheld.

## 5. Confidentiality
BeyondCore ensures that persons authorised to process the Personal Data are bound by confidentiality.

## 6. Security (technical and organisational measures)
BeyondCore implements the measures in **Annex II**, appropriate to the risk, including encryption in
transit, access controls, tenant isolation, the data-minimisation measures in Section 4, and audit
logging of steward decisions.

## 7. Sub-processors
7.1 The Customer provides **general authorisation** for BeyondCore to engage the sub-processors listed
in **Annex III** (also published at `/security`).
7.2 BeyondCore imposes data-protection obligations on each sub-processor no less protective than this
DPA, and remains liable for their performance.
7.3 BeyondCore gives the Customer prior notice of any intended addition or replacement of a
sub-processor, and the Customer may object on reasonable data-protection grounds.

## 8. Assistance to the Customer
Taking into account the nature of processing, BeyondCore assists the Customer with: (a) responding to
**data-subject requests**; (b) **security**, **breach notification** (without undue delay after
becoming aware, and in any event consistent with Art. 33 GDPR), **DPIAs**, and prior consultation.

## 9. Return and deletion
On termination, at the Customer's choice, BeyondCore **deletes or returns** all Personal Data and
deletes existing copies, unless EU/member-state law requires storage. Deleting an assessment removes
its findings (cascade). Any Customer-owned learned knowledge can be exported or deleted on request.

## 10. Audits
BeyondCore makes available information necessary to demonstrate compliance and allows for and
contributes to audits, including inspections, conducted by the Customer or an auditor it mandates,
subject to reasonable confidentiality and frequency limits.

## 11. International transfers
Where Personal Data is transferred outside the EEA (e.g. to the default AI sub-processor in Annex III),
the transfer is governed by the EU **Standard Contractual Clauses**, and only the allowlisted,
non-identifying fields in Section 4.3 are transferred. Full EU residency with no external AI
sub-processor is available on Customer-Managed Cloud and on-premise deployments.

## 12. Liability and precedence
This DPA is subject to the liability provisions of the underlying agreement. In case of conflict on
data-protection matters, this DPA prevails.

---

## Annex I — Details of processing
- **Categories of data subjects:** the Customer's business partners and their representatives — e.g.
  supplier, customer and employee contacts referenced in master-data records.
- **Categories of Personal Data:** business-contact and organisation data present in the master-data
  domain assessed (e.g. names, addresses, business identifiers). The Customer controls which fields
  are included in the extract.
- **Special categories:** none intended. The Customer should not include special-category data.
- **Frequency:** continuous / per-assessment, as directed by the Customer's use.
- **Subject matter/duration:** as set out above and in the underlying agreement.

## Annex II — Technical and organisational measures
- **Data minimisation / Zero Data Retention:** raw extracts processed in memory and discarded; only
  assessment results and findings persisted (Section 4).
- **DLP allowlist for AI:** only non-identifying, allowlisted fields transmitted to the AI
  sub-processor; a qualification "eval gate" verifies the boundary before a model serves real data.
- **Encryption:** TLS in transit; hosting-provider encryption at rest.
- **Access control:** authenticated access (password and/or SSO via OIDC/SAML); least-privilege;
  single-tenant isolation of the data & knowledge plane.
- **Hosting:** EU — Frankfurt, Germany (Fly.io `fra`).
- **Auditability:** steward decisions (approve/reject) recorded; assessment history retained for trend.
- **Resilience:** managed database backups per hosting configuration.

## Annex III — Approved sub-processors
As published at `/security` and in `docs/subprocessors.md`:
1. **Fly.io, Inc.** — hosting, compute, managed PostgreSQL — EU (Frankfurt).
2. **Anthropic, PBC** — AI Engine (allowlisted non-identifying fields only; no training/retention) — US.
3. **Transactional email (SMTP provider)** — contact-form message delivery only.

---

**Signatures**

For the Customer: __________________________  Name/Title: ____________  Date: __________

For BeyondCore: ___________________________  Name/Title: ____________  Date: __________
