Skip to main content

Data Processing Agreement

Last updated: January 15, 2026

Data Processing Agreement

Document owner: Chief Privacy Officer (CPO) and General Counsel Version: 3.0 Effective date: January 1, 2026 Last updated: January 15, 2026 Classification: Public — Trust Center Review cadence: Annual, and upon changes to data protection law or processing activities Company: Acme Cloud, Inc. Address: 1200 Market Street, Suite 400, San Francisco, CA 94103, USA Primary contacts: trust@acmecloud.com | security@acmecloud.com | privacy@acmecloud.com


Definitions

TermDefinition
Applicable Data Protection LawAll laws and regulations relating to the processing of Personal Data applicable to the parties, including GDPR, UK GDPR, LGPD, CCPA/CPRA, and other jurisdictional requirements
ControllerThe party that determines the purposes and means of Processing Personal Data
Customer Personal DataPersonal Data Processed by Acme Cloud on behalf of Customer pursuant to the Agreement
Data ExporterThe party transferring Personal Data to a third country
Data ImporterThe party receiving Personal Data from a Data Exporter
Data SubjectThe identified or identifiable natural person to whom Personal Data relates
DPIAData Protection Impact Assessment as required by GDPR Article 35
DPOData Protection Officer appointed pursuant to GDPR Articles 37-39
EEAEuropean Economic Area (EU member states plus Iceland, Liechtenstein, Norway)
GDPRRegulation (EU) 2016/679 (General Data Protection Regulation)
InstructionsCustomer's documented instructions regarding Processing of Customer Personal Data
Personal DataAny information relating to an identified or identifiable natural person
Personal Data BreachA breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data
ProcessingAny operation performed on Personal Data (collection, storage, use, disclosure, deletion, etc.)
ProcessorThe party that Processes Personal Data on behalf of the Controller
SCCsStandard Contractual Clauses for international data transfers adopted by the European Commission
Security MeasuresTechnical and organizational measures to protect Personal Data
Sensitive Personal DataSpecial categories of Personal Data under GDPR Article 9, including health data, biometric data, racial/ethnic origin, religious beliefs, and similar categories under other laws
SubprocessorA third party engaged by Acme Cloud to Process Customer Personal Data
Supervisory AuthorityThe data protection authority with jurisdiction over a party's Processing activities
UK GDPRThe retained EU law version of the GDPR as incorporated into UK law
UK IDTAUK International Data Transfer Agreement

Scope and Applicability

1.1 Agreement Incorporation

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other agreement between Acme Cloud, Inc. ("Acme Cloud") and Customer governing Customer's use of Acme Cloud services (the "Agreement"). This DPA applies to all Processing of Customer Personal Data by Acme Cloud in connection with the Agreement.

1.2 Order of Precedence

In the event of conflict, the following order of precedence applies:

Precedence LevelDocumentPurpose
1 (Highest)SCCs/UK IDTA AppendicesMandatory data transfer terms
2This DPAData protection terms
3AgreementGeneral service terms
4Privacy PolicyAcme Cloud controller processing

1.3 Scope of Processing

This DPA applies when Acme Cloud Processes Customer Personal Data:

Processing ActivityCovered by DPAAcme Cloud Role
Platform data storage and processingYesProcessor
Customer support with data accessYesProcessor
Analytics on customer usage (aggregated)No (anonymized)Controller
Account management and billingNoController
Security monitoringYesProcessor
Backup and disaster recoveryYesProcessor

1.4 Data Processing Details

CategoryDetails
Subject matterProviding the Acme Cloud SaaS platform services
DurationTerm of the Agreement plus data retention period
Nature of ProcessingCollection, storage, organization, retrieval, use, transmission, deletion
PurposePerforming services under the Agreement
Types of Personal DataAs determined by Customer (see Annex I)
Categories of Data SubjectsAs determined by Customer (see Annex I)

Controller and Processor Roles

2.1 Role Determination

Processing ContextCustomer RoleAcme Cloud RoleGoverning Terms
Customer Personal Data in platformControllerProcessorThis DPA
Customer employee/user dataControllerProcessorThis DPA
Acme Cloud account dataData SubjectControllerPrivacy Policy
Marketing interactionsData SubjectControllerPrivacy Policy
Aggregated/anonymized analyticsN/AControllerPrivacy Policy

2.2 Joint Controller Scenarios

Where Acme Cloud and Customer are Joint Controllers for specific Processing activities:

ActivityRespective ResponsibilitiesDocumentation
Customer support (with PII access)Customer: data accuracy; Acme Cloud: secure handlingSupport terms
Collaborative troubleshootingCustomer: authorization; Acme Cloud: limited useSupport ticket
Shared analytics for improvementCustomer: consent; Acme Cloud: anonymizationAnalytics addendum

2.3 Processor Obligations Matrix

GDPR ArticleRequirementAcme Cloud Implementation
Art. 28(3)(a)Process only on documented instructionsSection 3.1
Art. 28(3)(b)Personnel confidentialitySection 3.3
Art. 28(3)(c)Security measuresSection 4
Art. 28(3)(d)Subprocessor conditionsSection 5
Art. 28(3)(e)Data subject rights assistanceSection 6
Art. 28(3)(f)Breach notification assistanceSection 7
Art. 28(3)(g)DPIA and prior consultation assistanceSection 6.4
Art. 28(3)(h)Deletion or returnSection 8
Art. 28(3)(h)Audit and inspectionSection 9

Processing Instructions and Restrictions

3.1 Customer Instructions

Acme Cloud shall Process Customer Personal Data only in accordance with:

3.1.1. The documented instructions set forth in this DPA and the Agreement 3.1.2. Additional written instructions provided by Customer through authorized channels 3.1.3. As required by Applicable Data Protection Law (with notice to Customer where permitted)

Instruction TypeCommunication MethodAuthorization Level
Standard processingAgreement and DPAIncorporated
Configuration changesPlatform settingsAccount administrator
Additional instructionsSigned addendumAuthorized signatory
Urgent instructionsEmail to designated contactVerified administrator

3.2 Instruction Conflicts

If Acme Cloud believes an instruction violates Applicable Data Protection Law:

Step 1: Notification 1.1. Acme Cloud promptly notifies Customer of the concern 1.2. Notification includes specific legal basis for concern 1.3. Acme Cloud may suspend execution pending resolution

Step 2: Resolution 2.1. Parties discuss and attempt to resolve concern 2.2. Customer may modify instruction 2.3. If unresolved, parties may escalate to counsel

Step 3: Documentation 3.1. Resolution documented in writing 3.2. Modified instructions incorporated 3.3. Acme Cloud resumes processing per resolution

3.3 Personnel Confidentiality

Acme Cloud ensures that personnel authorized to Process Customer Personal Data:

RequirementImplementationVerification
Confidentiality commitmentEmployment agreements with confidentialityHR records
Security trainingAnnual security awareness trainingTraining records
Need-to-know accessRole-based access controlsAccess reviews
Background checksPre-employment screening (where permitted)HR records
Ongoing obligationsConfidentiality survives terminationEmployment terms

3.4 Processing Restrictions

Acme Cloud shall not:

ProhibitionException
Sell Customer Personal DataNone
Share for cross-context behavioral advertisingNone
Use for Acme Cloud's own commercial purposesAggregated/anonymized analytics
Retain longer than necessaryLegal obligation, dispute resolution
Process Sensitive Personal Data without authorizationBAA for PHI, explicit customer instruction
Transfer to third countries without safeguardsApproved transfer mechanisms

Security Measures

4.1 Technical and Organizational Measures

Acme Cloud implements Security Measures appropriate to the risk, including:

Security DomainMeasuresVerification
Access controlRole-based access, MFA, JIT provisioningAccess reviews, audit logs
EncryptionAES-256 at rest, TLS 1.2+ in transitTechnical configuration
Network securityVPC isolation, WAF, DDoS protectionArchitecture review
MonitoringSIEM, 24/7 SOC, anomaly detectionSOC 2 report
Incident responseDocumented IR plan, tabletop exercisesIR records
Business continuityBackup, replication, DR proceduresDR test results
Vulnerability managementScanning, patching, penetration testingScan reports
Physical securityAWS data center controlsAWS SOC 2

4.2 Security Measures by Data Sensitivity

Data ClassificationSecurity Measures Applied
Standard Personal DataBase security measures (Section 4.1)
Sensitive Personal DataEnhanced access controls, field-level encryption
Protected Health InformationBAA controls, HIPAA safeguards, audit logging
Payment Card DataPCI DSS controls, tokenization
Children's DataParental consent verification, enhanced deletion

4.3 Security Documentation

Acme Cloud maintains documentation of Security Measures:

DocumentAvailabilityUpdate Frequency
Security OverviewPublic (Trust Center)Quarterly
Encryption StandardsPublic (Trust Center)Annual
SOC 2 Type II ReportUnder NDAAnnual
Penetration Test SummaryUnder NDAAnnual
Technical Security WhitepaperUpon requestAnnual

4.4 Security Certifications

CertificationScopeStatusRenewal
SOC 2 Type IISecurity, Availability, ConfidentialityActiveAnnual
ISO 27001ISMSIn progressAnnual surveillance
CSA STARCloud securityPlannedAnnual

Subprocessors

5.1 General Authorization

Customer provides general authorization for Acme Cloud to engage Subprocessors, subject to the conditions in this Section 5. The current list of Subprocessors is available at /subprocessor-list.

5.2 Subprocessor Requirements

Acme Cloud ensures each Subprocessor:

RequirementVerificationOngoing
Contractual obligations equivalent to this DPAContract reviewContract monitoring
Appropriate Security MeasuresSecurity assessmentAnnual reassessment
Compliance with Applicable Data Protection LawDue diligenceCompliance monitoring
Personnel confidentialityContract termsContract monitoring
Audit rightsContract termsAs needed

5.3 Subprocessor Notification Process

Step 1: Advance Notice 1.1. Acme Cloud provides thirty (30) days' advance notice of new Subprocessors 1.2. Notice includes Subprocessor name, location, and processing description 1.3. Notice sent via email to designated privacy contact

Step 2: Customer Review 2.1. Customer reviews proposed Subprocessor 2.2. Customer may request additional information 2.3. Acme Cloud provides reasonable information for assessment

Step 3: Objection Process 3.1. Customer may object in writing within notice period 3.2. Objection must state reasonable grounds related to data protection 3.3. Parties negotiate in good faith to resolve objection

Step 4: Resolution 4.1. Acme Cloud may: address concerns, offer alternative, or proceed 4.2. If unresolved, Customer may terminate affected services without penalty 4.3. Termination right is Customer's exclusive remedy

5.4 Subprocessor Categories

CategoryExamplesProcessing ActivityLocation
InfrastructureAWS, CloudflareHosting, CDN, securityUS, EU
Support toolsIntercom, ZendeskCustomer supportUS
AnalyticsPostHog, MixpanelProduct analyticsUS, EU
CommunicationSendGrid, TwilioTransactional messagingUS
SecurityCrowdStrike, DatadogSecurity monitoringUS

5.5 Subprocessor Liability

Acme Cloud remains liable to Customer for Subprocessor performance. If a Subprocessor fails to fulfill data protection obligations, Acme Cloud shall be liable as if Acme Cloud had failed to fulfill such obligations directly.


Data Subject Rights

6.1 Rights Assistance

Acme Cloud assists Customer in responding to Data Subject requests:

RightGDPR ArticleAcme Cloud AssistanceResponse Timeline
AccessArt. 15Provide data export, search capability5 business days
RectificationArt. 16Self-service correction, API access5 business days
ErasureArt. 17Deletion tools, confirmation10 business days
RestrictionArt. 18Processing restriction flags5 business days
PortabilityArt. 20Machine-readable export5 business days
ObjectionArt. 21Processing cessation tools5 business days
Automated decisionsArt. 22Human review capability5 business days

6.2 Request Handling Process

Step 1: Request Receipt 1.1. Customer receives Data Subject request 1.2. Customer verifies Data Subject identity 1.3. Customer determines request validity and scope

Step 2: Acme Cloud Notification 2.1. If request relates to Customer Personal Data in Acme Cloud platform, Customer notifies Acme Cloud 2.2. Notification includes verified request details 2.3. Acme Cloud acknowledges within one (1) business day

Step 3: Acme Cloud Assistance 3.1. Acme Cloud provides requested assistance per Section 6.1 3.2. Customer compiles and provides response to Data Subject 3.3. Acme Cloud documents assistance provided

6.3 Direct Requests to Acme Cloud

If Acme Cloud receives a Data Subject request directly:

ActionTimelineDocumentation
Redirect to Customer (if identifiable)3 business daysRequest log
Inform Data Subject of redirect3 business daysResponse record
Notify Customer (if identifiable)3 business daysNotification record
Respond if Customer unidentifiablePer GDPR timelinesResponse record

6.4 DPIA and Consultation Assistance

Where Customer is required to conduct a DPIA or consult with a Supervisory Authority, Acme Cloud provides:

Assistance TypeScopeTimeline
Processing descriptionNature, scope, context, purposes10 business days
Security documentationTechnical and organizational measures5 business days
Risk assessment inputAcme Cloud's risk analysis10 business days
Supervisory consultationParticipation as reasonably requestedReasonable cooperation

Personal Data Breach Notification

7.1 Breach Detection and Response

Acme Cloud maintains breach detection and response capabilities:

CapabilityImplementationCoverage
Real-time monitoringSIEM, anomaly detection24/7
Incident response teamTrained IR personnel24/7 on-call
Forensic capabilityInternal + external forensicsAs needed
Communication proceduresDocumented notification proceduresTested annually

7.2 Customer Notification

Upon becoming aware of a Personal Data Breach affecting Customer Personal Data, Acme Cloud shall:

Step 1: Initial Notification (within 48 hours) 1.1. Notify Customer of the breach 1.2. Provide initial information available at time of notification 1.3. Designate communication contact

Step 2: Detailed Information (as available) 2.1. Nature of the breach 2.2. Categories and approximate number of Data Subjects affected 2.3. Categories and approximate number of records affected 2.4. Likely consequences of the breach 2.5. Measures taken or proposed to address the breach

Step 3: Ongoing Updates 3.1. Provide updates as investigation proceeds 3.2. Respond to reasonable Customer inquiries 3.3. Coordinate on regulatory communications

7.3 Breach Notification Content

Information ElementInitial NotificationSubsequent Updates
Date/time of breach discoveryRequiredIf refined
Nature of breachHigh-level descriptionDetailed description
Data categories affectedIf knownConfirmed list
Data subjects affectedApproximate numberRefined number
Containment actionsImmediate stepsComprehensive steps
Root causePreliminaryConfirmed
Remediation planInitial planUpdated plan
Acme Cloud contactName and contact infoUpdates if changed

7.4 Customer Obligations

Customer remains responsible for:

ObligationAcme Cloud Support
Supervisory Authority notificationInformation for notification
Data Subject notificationInformation for notification
Regulatory responseCooperation, documentation
Determining notification necessityLegal assessment input

Data Retention and Deletion

8.1 Retention During Agreement

During the Agreement term, Acme Cloud retains Customer Personal Data:

Data TypeRetention PeriodDeletion Trigger
Active account dataAccount lifetimeAccount termination
Deleted data (soft delete)30 daysAutomatic permanent deletion
Backup data90 days rollingAutomatic rotation
Audit logs7 yearsAutomatic deletion
Support tickets with PII3 yearsAutomatic deletion

8.2 Post-Termination Handling

Upon Agreement termination or expiration:

Step 1: Data Export Period (30 days) 1.1. Customer may export Customer Personal Data via platform tools 1.2. Acme Cloud provides reasonable export assistance 1.3. Data remains accessible in read-only mode

Step 2: Deletion (after export period) 2.1. Acme Cloud deletes Customer Personal Data from production systems 2.2. Deletion completed within 30 days of export period end 2.3. Customer notified of deletion completion

Step 3: Backup Purge (90 days after deletion) 3.1. Customer Personal Data purged from backups 3.2. Purge occurs through normal backup rotation 3.3. Accelerated purge available upon request (additional fee may apply)

8.3 Deletion Exceptions

Acme Cloud may retain Customer Personal Data beyond standard periods:

ExceptionDurationCustomer Notification
Legal holdDuration of holdWhere legally permitted
Dispute resolutionDuration of disputeUpon dispute initiation
Regulatory requirementPer regulationWhere legally permitted
Anonymized for analyticsIndefiniteN/A (no longer Personal Data)

8.4 Deletion Certification

Upon Customer request, Acme Cloud provides written certification of deletion:

Certificate ElementContent
Deletion scopeCustomer Personal Data deleted
Deletion dateDate of final deletion
Deletion methodCryptographic erasure, physical destruction
ExceptionsAny data retained per Section 8.3
Authorized signatureAcme Cloud privacy officer

Audit Rights

9.1 Audit Methods

Customer may verify Acme Cloud's compliance through:

MethodAvailabilityCost
SOC 2 Type II reportUpon request (under NDA)No charge
Security questionnaire completionAnnualNo charge
Penetration test executive summaryUpon request (under NDA)No charge
Additional certificationsUpon availabilityNo charge
Customer-conducted auditPer Section 9.2Customer's cost

9.2 On-Site Audit Procedures

If Customer requires an on-site audit:

Step 1: Audit Request 1.1. Customer provides thirty (30) days' written notice 1.2. Notice includes proposed scope, timing, and auditors 1.3. Acme Cloud confirms or proposes alternatives within ten (10) days

Step 2: Audit Planning 2.1. Parties agree on audit plan 2.2. Auditors execute confidentiality agreements 2.3. Acme Cloud prepares relevant documentation

Step 3: Audit Execution 3.1. Audit conducted during normal business hours 3.2. Acme Cloud personnel available for interviews 3.3. Access to relevant systems and documentation provided

Step 4: Audit Completion 4.1. Auditor provides draft findings to Acme Cloud 4.2. Acme Cloud may provide factual corrections 4.3. Final report shared with Customer and Acme Cloud

9.3 Audit Limitations

LimitationRationale
One audit per year (absent breach)Operational efficiency
30 days' advance noticePreparation time
Business hours onlyMinimize disruption
No access to other customer dataConfidentiality
Acme Cloud confidential information protectedTrade secrets
Auditor confidentiality requiredInformation protection

International Data Transfers

10.1 Transfer Mechanisms

For transfers of Customer Personal Data outside the EEA, UK, or Switzerland:

Transfer RoutePrimary MechanismSupplementary Measures
EEA to USEU-US Data Privacy FrameworkTIA completed
EEA to other third countriesSCCs (2021)TIA, encryption
UK to USUK Extension to DPFTIA completed
UK to other third countriesUK IDTATIA, encryption
Switzerland to USSwiss-US DPFTIA completed

10.2 Standard Contractual Clauses

The EU SCCs (Commission Decision 2021/914) are incorporated by reference:

SCC ModuleApplicationParties
Module 2 (Controller to Processor)Customer Personal DataCustomer (exporter), Acme Cloud (importer)
Module 3 (Processor to Processor)Subprocessor transfersAcme Cloud (exporter), Subprocessor (importer)

SCC configuration:

ClauseSelection
Clause 7 (Docking)Included
Clause 9 (Subprocessors)Option 2 (general authorization)
Clause 11 (Redress)Option (independent dispute resolution) not selected
Clause 17 (Governing Law)Ireland
Clause 18 (Forum)Ireland

10.3 Transfer Impact Assessment

Acme Cloud maintains Transfer Impact Assessments for US transfers:

Assessment ElementAcme Cloud Position
US legal frameworkEO 14086, FISA 702, law enforcement access
Acme Cloud's experienceNo national security orders to date
Technical measuresEncryption at rest and in transit, access controls
Contractual measuresSCCs, DPA commitments
Organizational measuresData minimization, access limitation
Overall assessmentEffective level of protection maintained

10.4 Customer Cooperation on Transfers

Where Customer requires additional transfer documentation:

Document TypeAcme Cloud ProvisionTimeline
SCC annexes completionPre-populated, Customer review5 business days
TIA supporting documentationAvailable upon request10 business days
Subprocessor transfer detailsSubprocessor list with locationsCurrent list
UK IDTA tablesPre-populated for UK customers5 business days

CCPA/CPRA Addendum

11.1 Applicability

This section applies where Customer is a "Business" and Acme Cloud is a "Service Provider" under the California Consumer Privacy Act, as amended by the CPRA.

11.2 Service Provider Certification

Acme Cloud certifies that it:

RequirementAcme Cloud Compliance
Processes Personal Information only for documented business purposesYes - per Agreement
Does not sell or share Personal InformationCertified
Does not retain, use, or disclose for purposes other than AgreementCertified
Does not combine with data from other sources (except as permitted)Certified
Will notify if unable to complyCommitted

11.3 CPRA-Specific Obligations

CPRA RequirementAcme Cloud Implementation
Right to Delete assistanceDeletion tools, assistance per Section 6
Right to Correct assistanceCorrection tools, assistance per Section 6
Right to Know assistanceExport tools, assistance per Section 6
Opt-out of sale/sharingN/A (not selling/sharing)
Limit sensitive PI useProcess only per instructions
Security measuresSection 4 measures
Subcontractor obligationsFlow-down requirements to subcontractors

Framework Mapping Appendix

GDPR Article 28 Compliance Matrix

Art. 28 RequirementDPA SectionImplementation
28(1) - Sufficient guaranteesSection 4Security measures, certifications
28(2) - Subprocessor engagementSection 5Prior authorization, equivalent terms
28(3)(a) - Documented instructionsSection 3.1Instruction framework
28(3)(b) - ConfidentialitySection 3.3Personnel obligations
28(3)(c) - Security measuresSection 4Technical and organizational measures
28(3)(d) - Subprocessor conditionsSection 5Contract requirements
28(3)(e) - Data subject rightsSection 6Assistance procedures
28(3)(f) - Breach assistanceSection 7Notification and cooperation
28(3)(g) - DPIA assistanceSection 6.4Information provision
28(3)(h) - Deletion/returnSection 8Post-termination procedures
28(3)(h) - Audit cooperationSection 9Audit rights

ISO 27701 Control Mapping

ISO 27701 ControlDPA SectionImplementation
7.2.1 - Purpose identificationSection 1.4Processing details
7.2.2 - Lawful basisAgreementCustomer's responsibility
7.4.1 - Collection limitationSection 3.4Processing restrictions
7.4.5 - RetentionSection 8Retention and deletion
7.5 - SharingSection 5Subprocessor management
8.2 - Controller conditionsSection 2Role determination
8.3 - Joint determinationSection 2.2Joint controller scenarios
8.4 - Subprocessor conditionsSection 5Subprocessor requirements
8.5 - International transfersSection 10Transfer mechanisms

Annexes

Annex I: Processing Description

ElementDescription
Subject matterProvision of Acme Cloud SaaS platform services
DurationTerm of Agreement plus data retention period
Nature of ProcessingStorage, organization, retrieval, transmission, deletion
PurposeDelivering compliance management services
Categories of Data SubjectsCustomer employees, customer customers, partners (as determined by Customer)
Types of Personal DataName, email, employment information, compliance data (as determined by Customer)
Sensitive DataAs uploaded by Customer (BAA required for PHI)

Annex II: Technical and Organizational Measures

Detailed security measures are documented in /security-overview and /encryption-standards.

Annex III: Subprocessor List

Current subprocessor list is maintained at /subprocessor-list.


Related Trust Center documents

privacy policy, subprocessor list, security overview, encryption standards, data retention, terms of service

Document revision history

VersionDateAuthorSummary of changes
1.02024-06-01Legal & ComplianceInitial Trust Center publication
2.02025-03-15GRC ProgramSOC 2 Type II alignment refresh; expanded subprocessors
2.52025-09-01Security EngineeringEncryption standards update; ISO 27001 mapping
3.02026-01-15Trust Center ProgramFull procurement-grade expansion; 34-document set

Contact

Acme Cloud, Inc. 1200 Market Street, Suite 400 San Francisco, CA 94103, USA

ChannelEmailUse case
Trust & procurementtrust@acmecloud.comSecurity questionnaires, trust reviews
Securitysecurity@acmecloud.comIncidents, vulnerabilities, control questions
Privacyprivacy@acmecloud.comDSRs, privacy assessments
Legallegal@acmecloud.comContractual, DPA, legal notices
Last updated: January 15, 2026
EthicPages logoEthicPages