Data Processing Addendum
The DPA for business and enterprise customers, setting out roles, processing scope, security, sub-processors, international transfers, and assistance with data-subject requests, aligned to GDPR Article 28 and equivalents. A counter-signed copy is available on request.
On this page
1. Scope and roles
This Data Processing Addendum (the "DPA") forms part of the Terms of Service between you (the "Customer") and Fuzail Khan, a sole proprietor based in Toronto, Ontario, Canada and operator of the Dokven service ("the Operator"), and applies where the Operator processes personal data contained in Customer Content on the Customer's behalf.
For that personal data, the Customer is the controller (or processor acting for its own customers) and the Operator is the processor (or sub-processor). For data the Operator processes for its own purposes (such as account administration, billing, and securing the Service), the Operator is the controller and the Privacy Policy applies. This DPA is drafted to satisfy GDPR Article 28 and equivalent requirements under the UK GDPR, PIPEDA, and Quebec Law 25.
2. Details of processing
- Subject matter: provision of the Dokven Service to the Customer.
- Duration:the term of the Customer's agreement, plus any retention period in the Privacy Policy.
- Nature and purpose: hosting, executing automated and AI-assisted tests, generating reports and artifacts, and related operation, security, and support of the Service.
- Types of data: data contained in Customer Content and account/usage data, which may include identifiers and any personal data the Customer chooses to submit.
- Data subjects:the Customer's personnel and any individuals whose data appears in Customer Content.
3. Processor obligations
the Operator will:
- process personal data only on the Customer's documented instructions, including this DPA and use of the Service, unless required by law (in which case it will inform the Customer where permitted);
- ensure persons authorized to process the data are bound by confidentiality;
- implement appropriate technical and organizational security measures (see the Security page);
- assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations;
- notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Content; and
- at the Customer's choice, delete or return personal data at the end of the services, subject to legal retention.
4. Sub-processors
The Customer provides general authorization for the Operator to engage the sub-processors listed at Sub-processors. the Operator imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance.
Change notice
5. International transfers
Where processing involves transferring personal data across borders, the parties incorporate by reference the European Commission's 2021 Standard Contractual Clauses (and the UK International Data Transfer Addendum) with the Operator acting in the relevant module, together with a transfer impact assessment, as the transfer mechanism, and rely on equivalent safeguards under PIPEDA and Quebec Law 25. Details are in the Privacy Policy.
6. Audit and assistance
On reasonable written request and no more than once per year (unless required by a supervisory authority), the Operator will make available information necessary to demonstrate compliance with this DPA and contribute to audits, which may be satisfied by providing existing reports, certifications, or a questionnaire, subject to confidentiality and reasonable scheduling.
7. Liability and signed DPA
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If there is a conflict between this DPA and the Terms on the processing of personal data, this DPA controls.
Need a signed copy?
Questions about this document? Contact support@dokven.com (legal) or support@dokven.com (privacy). We review and update these policies as the product and the law change; the version and dates above always reflect the current text.