Legal

Data Processing Agreement

Last updated: June 1, 2026

Template DPA — to be reviewed by counsel and countersigned.

1. Parties

Customer (the data controller) and AzureProof (the data processor).

2. Subject matter & duration

Processing of Customer personal data to deliver the AzureProof service for the term of the subscription.

3. Nature & purpose

Running SOC2 evidence checks against the Customer's Azure tenant; storing run metadata and reports.

4. Categories of data subjects

  • Customer employees and authorized users of the platform.

5. Categories of personal data

  • Names, work email, IP addresses, user agent.
  • Azure account identifiers (tenant ID, principal IDs, group IDs).

6. Processor obligations

  • Process only on Customer's documented instructions.
  • Ensure confidentiality of authorized personnel.
  • Implement appropriate technical & organizational security measures.
  • Assist with data subject rights requests.
  • Notify Customer of personal-data breaches without undue delay.

7. Sub-processors

Current list at /trust. We give 30 days' notice before adding new sub-processors.

8. International transfers

Where applicable, transfers rely on the EU Standard Contractual Clauses (2021/914).

9. Return / deletion

On termination, Customer data is deleted within 30 days unless retention is legally required.

10. Audits

Customer may request our latest SOC2 report once per year under NDA.

Sign

To countersign this DPA, email legal@azureproof.com.