Data Processing Agreement (GDPR Article 28)
This DPA is incorporated into the Terms of Service and applies to all EU/UK/Swiss customers.
Processor Responsibilities
SafePrompt acts as a Data Processor and agrees to:
- Process data only on instruction from the Customer (Data Controller)
- Implement technical and organizational security measures
- Ensure staff confidentiality agreements
- Assist with data subject requests within 30 days
- Report breaches within 72 hours
- Undergo annual security audits
Sub-Processors
SafePrompt uses the following sub-processors (view full list at /legal/subprocessors):
- Google Cloud (US, primary region: Virginia)
- Firebase (authentication & database)
- Stripe (payments)
- MongoDB (data storage)
Data Subject Rights
SafePrompt assists you in responding to data subject requests including:
- Right of Access
- Right to Rectification
- Right to Erasure ("Right to be Forgotten")
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
Security Measures
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Multi-factor authentication (MFA)
- Rate limiting (100 req/min per IP)
- DDoS protection
- Daily encrypted backups
- 24/7 security monitoring
For legal inquiries: Email sales@safeprompt.pro (5-day response SLA)