Legal
Data Processing Agreement
Last updated: June 1, 2026
Template DPA — to be reviewed by counsel and countersigned.
1. Parties
Customer (the data controller) and AzureProof (the data processor).
2. Subject matter & duration
Processing of Customer personal data to deliver the AzureProof service for the term of the subscription.
3. Nature & purpose
Running SOC2 evidence checks against the Customer's Azure tenant; storing run metadata and reports.
4. Categories of data subjects
- Customer employees and authorized users of the platform.
5. Categories of personal data
- Names, work email, IP addresses, user agent.
- Azure account identifiers (tenant ID, principal IDs, group IDs).
6. Processor obligations
- Process only on Customer's documented instructions.
- Ensure confidentiality of authorized personnel.
- Implement appropriate technical & organizational security measures.
- Assist with data subject rights requests.
- Notify Customer of personal-data breaches without undue delay.
7. Sub-processors
Current list at /trust. We give 30 days' notice before adding new sub-processors.
8. International transfers
Where applicable, transfers rely on the EU Standard Contractual Clauses (2021/914).
9. Return / deletion
On termination, Customer data is deleted within 30 days unless retention is legally required.
10. Audits
Customer may request our latest SOC2 report once per year under NDA.
Sign
To countersign this DPA, email legal@azureproof.com.