SumveroBY OPTIMUS TECH
Privacy Cookies Terms Subscriptions DPA Subprocessors Accessibility Data rights
Production legal setup is incomplete. The operator's full legal identity and address, and the operator-specific processing, retention, security and subprocessor schedules, must be completed and reviewed before these documents are relied on for live customer sales.
ARTICLE 28 UK GDPR TEMPLATE

Data Processing Agreement

This document is a versioned implementation template, not a production-ready agreement. It must be completed with the customer, processor, processing details, security measures, locations, deletion process and subprocessors, then approved by the parties before regulated customer data is processed.

Template version 2026-07-30-template-1

Not complete for production. Blank schedules are intentional: the application cannot determine the operator's legal identity, hosting arrangements, countries, suppliers, support model or retention instructions. Registration acknowledgement of this template does not turn incomplete schedules into an operative DPA.

1. Parties and status

The customer identified in the completed order or registration record is the controller, and the legal entity identified as the production operator is the processor, except where either party acts in another role for a specific activity. This DPA applies only when the processor handles personal data on the controller’s behalf in connection with Optimus Invoicing.

2. Processing details

The subject matter, duration, nature and purpose of processing, categories of personal data, categories of data subjects, and the controller’s obligations and rights must be completed in Schedule 1 below. Processing is limited to what is necessary to provide, secure, support and terminate the contracted service and to the controller’s documented instructions, including the completed agreement and authorised use of product features. If UK law requires other processing, the processor must inform the controller before that processing unless the law prohibits the information on important grounds of public interest.

If the processor believes an instruction infringes applicable data-protection law, it will inform the controller unless the law prohibits that notice and may suspend the affected processing while the parties resolve it.

3. Confidentiality

The processor must ensure that people authorised to process personal data are bound by an appropriate duty of confidentiality and receive access only where needed for their responsibilities.

4. Security

The processor must implement measures appropriate to the risk as required by Article 32 UK GDPR. Schedule 2 must describe the measures actually operated in production, including identity and access management, encryption in transit, secret and key management, tenant isolation, secure development and patching, logging and monitoring, vulnerability handling, backups and restore tests, incident response, supplier assurance, continuity and deletion controls.

Application features alone are not a complete security programme. Schedule 2 must be verified against the deployed infrastructure before this DPA is adopted.

5. Subprocessors

The controller authorises only the subprocessors in the completed Subprocessor Schedule, under the authorisation model stated there. The processor must impose materially equivalent data-protection obligations on each subprocessor and remain responsible for its obligations under this DPA. The schedule must state how the controller will be informed of intended additions or replacements and how a reasonable objection can be raised.

6. Assistance to the controller

Taking account of the nature of processing and information available, the processor must provide reasonable assistance with data-subject requests and the controller’s obligations concerning security, personal-data breaches, data-protection impact assessments and prior consultation. The completed support schedule must identify the channels, responsibilities and any agreed charges; this template does not invent response-time commitments.

7. Personal-data breaches

The processor must notify the controller without undue delay after becoming aware of a personal-data breach affecting controller data and provide available information needed for the controller’s assessment and notifications. The production incident process and notification contacts must be completed before launch.

8. International transfers

Personal data must not be transferred outside the UK except on documented instructions or as needed to provide the agreed service and with a lawful transfer mechanism. The completed schedules must identify relevant locations, adequacy status, contractual safeguards and transfer-risk assessments. No transfer representation is made by this uncompleted template.

9. Return and deletion

At the controller’s choice following termination, the processor must return or delete personal data and delete existing copies unless applicable law requires retention. Schedule 1 must define the request/export route, active-system deletion process, backup treatment, verification and any legal exception. No fixed deletion period is promised until that schedule is completed.

10. Demonstrating compliance and audits

The processor must make available information reasonably necessary to demonstrate compliance with Article 28 and allow audits or inspections on proportionate notice, subject to appropriate confidentiality, security and disruption safeguards. The parties must complete the evidence and audit procedure before adoption.

11. Priority and liability

The final DPA should identify the order of precedence between it, the order form and the Business Terms. Liability and cost allocation must be agreed in the final contract; this template intentionally does not create a cap or indemnity.

Schedule 1 — processing instructions (completion required)

Required fieldProduction entry
Controller legal name, address and contactNot completed
Processor legal name, address and privacy contactNot completed
Subject matter, nature and purposeNot completed
Duration and termination eventNot completed
Categories of data subjectsNot completed
Categories of personal dataNot completed
Whether special-category or criminal-offence data is permittedNot completed; it must not be assumed to be approved
Controller instructions and authorised featuresNot completed
Controller obligations and rightsNot completed
Return, export, deletion and backup treatmentNot completed
Processing countries and transfer safeguardsNot completed

Schedule 2 — technical and organisational measures (completion required)

The production operator must attach an accurate, deployment-specific control schedule and evidence owner. It must distinguish application controls from infrastructure and operational controls, identify material residual risks, and be reviewed whenever architecture or suppliers change.

Schedule 3 — contacts and signatures (completion required)

Complete the authorised representatives, privacy/security contacts, notice addresses, effective date and acceptance mechanism for both parties. Questions about completing this template can be sent to info@optimustech.co.uk.

© 2026 Sumvero by Optimus Tech
Privacy Cookies Terms DPA Subprocessors Accessibility Data rights
Necessary cookies only

Sumvero uses necessary cookies for security, sign-in and your privacy choice. No optional analytics cookies, advertising technology or cross-site tracking is loaded.

Read the cookie policy