Dokven

Loading Dokven.

Legal

Data Processing Addendum

The DPA for business and enterprise customers, setting out roles, processing scope, security, sub-processors, international transfers, and assistance with data-subject requests, aligned to GDPR Article 28 and equivalents. A counter-signed copy is available on request.

Effective: June 16, 2026Last updated: July 16, 2026Version: 1.1.0

1. Scope and roles

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between you (the "Customer") and Fuzail Khan, a sole proprietor based in Toronto, Ontario, Canada and operator of the Dokven service ("the Operator"), and applies where the Operator processes personal data contained in Customer Content on the Customer's behalf.

For that personal data, the Customer is the controller (or processor acting for its own customers) and the Operator is the processor (or sub-processor). For data the Operator processes for its own purposes (such as account administration, billing, and securing the Service), the Operator is the controller and the Privacy Policy applies. This DPA is drafted to satisfy GDPR Article 28 and equivalent requirements under the UK GDPR, PIPEDA, and Quebec Law 25.

2. Details of processing

  • Subject matter: provision of the Dokven Service to the Customer.
  • Duration:the term of the Customer's agreement, plus any retention period in the Privacy Policy.
  • Nature and purpose: hosting, executing automated and AI-assisted tests, generating reports and artifacts, and related operation, security, and support of the Service.
  • Types of data: data contained in Customer Content and account/usage data, which may include identifiers and any personal data the Customer chooses to submit.
  • Data subjects:the Customer's personnel and any individuals whose data appears in Customer Content.

3. Processor obligations

the Operator will:

  • process personal data only on the Customer's documented instructions, including this DPA and use of the Service, unless required by law (in which case it will inform the Customer where permitted);
  • ensure persons authorized to process the data are bound by confidentiality;
  • implement appropriate technical and organizational security measures (see the Security page);
  • assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations;
  • notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Content; and
  • at the Customer's choice, delete or return personal data at the end of the services, subject to legal retention.

4. Sub-processors

The Customer provides general authorization for the Operator to engage the sub-processors listed at Sub-processors. the Operator imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance.

Change notice

the Operatorwill provide at least 30 days' notice before adding or replacing a sub-processor that processes Customer personal data, so the Customer can object on reasonable data-protection grounds. Customers can subscribe to updates by contacting support@dokven.com.

5. International transfers

Where processing involves transferring personal data across borders, the parties incorporate by reference the European Commission's 2021 Standard Contractual Clauses (and the UK International Data Transfer Addendum) with the Operator acting in the relevant module, together with a transfer impact assessment, as the transfer mechanism, and rely on equivalent safeguards under PIPEDA and Quebec Law 25. Details are in the Privacy Policy.

6. Audit and assistance

On reasonable written request and no more than once per year (unless required by a supervisory authority), the Operator will make available information necessary to demonstrate compliance with this DPA and contribute to audits, which may be satisfied by providing existing reports, certifications, or a questionnaire, subject to confidentiality and reasonable scheduling.

7. Liability and signed DPA

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If there is a conflict between this DPA and the Terms on the processing of personal data, this DPA controls.

Need a signed copy?

Enterprise and business customers who require a counter-signed DPA can request one at support@dokven.com or support@dokven.com.

Questions about this document? Contact support@dokven.com (legal) or support@dokven.com (privacy). We review and update these policies as the product and the law change; the version and dates above always reflect the current text.