Data Processing Agreement

Last updated: 12/05/2025

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Userscanner ("Processor") and the User ("Controller") and reflects the parties' agreement with regard to the processing of personal data.

2. Definitions

For the purposes of this DPA:

  • "GDPR" means the General Data Protection Regulation (EU) 2016/679.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation or set of operations which is performed on Personal Data.

3. Processing of Personal Data

The Processor shall process Personal Data only on behalf of the Controller and in accordance with the Controller's documented instructions. The subject matter, duration, nature, and purpose of the processing are described in the Terms of Service.

4. Security Measures

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

  • The pseudonymisation and encryption of personal data.
  • The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
  • The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.

5. Sub-processors

The Controller authorizes the Processor to engage sub-processors to process Personal Data. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of other sub-processors.

6. Data Subject Rights

The Processor shall, to the extent legally permitted, promptly notify the Controller if it receives a request from a Data Subject to exercise their rights under the GDPR. The Processor shall assist the Controller in fulfilling its obligation to respond to such requests.

7. Deletion or Return of Data

Upon termination of the Services, the Processor shall, at the choice of the Controller, delete or return all the Personal Data to the Controller and delete existing copies unless applicable law requires storage of the Personal Data.