Data Processing Agreement
Last updated: July 19, 2026
1. Parties
This agreement is entered into between the Client (data controller) and DevPrism SAS (data processor), in accordance with Art. 28 GDPR.
2. Scope of Processing
DevPrism processes data on behalf of the Client solely for the purpose of providing the Service (engineering metrics analysis, AI agent execution, alert generation). Data categories and data subjects are described in the Privacy Policy.
3. Processor Obligations
DevPrism undertakes to: (a) process data only according to the Client's documented instructions; (b) ensure confidentiality (personnel bound by secrecy obligation); (c) implement appropriate technical and organizational security measures (Art. 32 GDPR); (d) not sub-process without prior written authorization; (e) assist the Client in responding to data subject requests; (f) notify any data breach within 72 hours.
4. Sub-processors
The Client authorizes the use of sub-processors listed in the Privacy Policy (§7). DevPrism will inform the Client of any sub-processor change with 30 days notice. The Client may object; failing resolution, the Client may terminate.
5. International Transfers
Data is hosted in the EU. In case of transfer outside the EU (AI API calls), the European Commission's Standard Contractual Clauses (SCCs) apply. Transfers are limited to technical prompts — no identifiable personal data is transmitted to AI models. The payment provider (Stripe) may process certain billing data in the United States, under SCCs and the EU–U.S. Data Privacy Framework.
6. Data Breach
In case of a personal data breach, DevPrism will notify the Client within a maximum of 72 hours after becoming aware, including: (a) the nature of the breach; (b) categories of data concerned; (c) corrective measures taken or proposed.
7. Data Fate
Upon contract expiration or termination, DevPrism will delete all Client data within 30 days, unless legally required to retain it. A data export (JSON/CSV format) is available upon request before deletion.
8. Audit
The Client may request a compliance audit once per year, with reasonable 30-day prior notice. DevPrism will provide necessary information and facilitate audits (including inspections) conducted by the Client or a mandated auditor.