Tovanix
Tovanix Data Processing Agreement (DPA)
The Tovanix Data Processing Agreement (DPA) is a formal compliance contract between Tovanix as Data Processor and enterprise customers as Data Controllers, designed for organizations that require GDPR / CCPA processor terms. Core clauses include:
- Purpose and scope: personal data is processed only on documented customer instructions, strictly limited to delivering the contracted services (payments, email, SMS, cloud)
- Sub-processor management: a published sub-processor list (cloud infrastructure, email delivery, SMS channels) with advance change notifications and the right to object
- Technical and organizational measures (TOMs): AES-GCM encryption at rest for sensitive data, role-based access control, audit logging, TLS in transit
- Cross-border transfers: safeguarded via Standard Contractual Clauses (SCCs) and equivalent lawful transfer mechanisms
- Data subject rights assistance: support for access, rectification, erasure and portability requests
- Breach notification: prompt notification of personal data breaches with incident details and remediation steps
- Deletion and return: on termination, all personal data is deleted or returned per customer instruction with written confirmation
To execute a signed DPA or obtain the current sub-processor list, contact us via support ticket or the official email channels.
불러오는 중…