← Back to home

Data Processing Agreement

Last updated: May 31, 2026

Data Processing Agreement (GDPR Article 28)

This DPA is incorporated into the Terms of Service and applies to all EU/UK/Swiss customers.

Processor Responsibilities

SafePrompt acts as a Data Processor and agrees to:

  • Process data only on instruction from the Customer (Data Controller)
  • Implement technical and organizational security measures
  • Ensure staff confidentiality agreements
  • Assist with data subject requests within 30 days
  • Report breaches within 72 hours
  • Undergo annual security audits

Sub-Processors

SafePrompt uses the following sub-processors (view full list at /legal/subprocessors):

  • Google Cloud (US, primary region: Virginia)
  • Firebase (authentication & database)
  • Stripe (payments)
  • MongoDB (data storage)

Data Subject Rights

SafePrompt assists you in responding to data subject requests including:

  • Right of Access
  • Right to Rectification
  • Right to Erasure ("Right to be Forgotten")
  • Right to Restrict Processing
  • Right to Data Portability
  • Right to Object

Security Measures

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Multi-factor authentication (MFA)
  • Rate limiting (100 req/min per IP)
  • DDoS protection
  • Daily encrypted backups
  • 24/7 security monitoring

For legal inquiries: Email sales@safeprompt.pro (5-day response SLA)

© 2026 SafePrompt | A product of SG2 Technologies

TermsPrivacyCookiesDPAContactMetaSight