# Data Processing Agreement — Executable Template

> Mirror of the live summary at `/dpa` in a redline-friendly format.
> Fields marked `[OPERATOR: …]` / `[CUSTOMER: …]` are completed at
> contracting. To execute, email **legal@ovriven.com**.

This Data Processing Agreement ("**DPA**") supplements the Terms of
Service (or executed Master Service Agreement) between
`[OPERATOR: Ovriven legal entity]` ("**Processor**") and
`[CUSTOMER: legal entity]` ("**Controller**") for personal data
processed through Ovriven on Team or Enterprise plans.

## 1 · Subject matter

Processor processes personal data on behalf of Controller solely to
provide the simulation service contracted under the Terms of Service
or MSA. Personal data may include Controller's end-users, workspace
members, and the contents of materials Controller submits.

## 2 · Duration; return & deletion

Processing continues for the subscription term plus any post-term
retention period required by law or agreed in writing. On
termination, Processor returns or deletes all Controller data within
**90 days** (self-service exports remain available during the
return window).

## 3 · Subprocessors

Controller authorizes the subprocessors listed at `/sub-processors`
(the authoritative register). Processor notifies Controller before
adding new subprocessors and provides a **30-day objection window**.

## 4 · Security measures

Processor maintains at minimum: TLS in transit and AES-256 at rest;
per-tenant logical isolation via the Workspace boundary; audit
logging of sensitive actions (tamper-evident hash chain); MFA
available to all users and required for Processor administrative
access; tested backups with point-in-time recovery. The fuller
description at `/security` is incorporated by reference.

## 5 · Data subject requests

Processor assists Controller with access, erasure, rectification,
and portability requests within **30 days**; end-users can also
self-serve (export + deletion) via Account → Privacy.

## 6 · Personal data breach

Processor notifies Controller of any confirmed personal data breach
without undue delay, and within **72 hours** where feasible, with
the information reasonably required for Controller's own Art. 33/34
obligations. Processor maintains a documented breach-response
process including affected-user enumeration.

## 7 · Cross-border transfers

For transfers outside the EEA/UK, the parties rely on the European
Commission's Standard Contractual Clauses (incorporated by
reference, module 2: controller→processor); for US transfers the
EU-US Data Privacy Framework applies where applicable.

## 8 · Audit

Processor makes available the information reasonably necessary to
demonstrate compliance (security overview, questionnaire answers,
control inventory under NDA) and permits audits as required by GDPR
Art. 28(3)(h), no more than annually absent a breach.

---

**Processor**: signature `____________` · name/title `[OPERATOR: …]`
· date `______`

**Controller**: signature `____________` · name/title
`[CUSTOMER: …]` · date `______`
