Data Processing Agreement
Last updated September 28, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between ProjectOnUs (“Processor”) and the Customer (“Controller”) for the ProjectOnUs service, and applies when we process personal data on the Customer’s behalf. It is designed to meet Article 28 of the GDPR and UK GDPR and the CCPA. To sign a copy for your records, email privacy@projectonus-delivered.com.
1. Scope
| Subject matter | Hosting and processing Customer Content to provide the ProjectOnUs service |
|---|---|
| Duration | The term of the agreement, plus the deletion periods in section 9 |
| Nature and purpose | Storage, text extraction (including OCR), search, AI summarization and extraction, automations, notifications, sharing through links the Customer creates |
| Data subjects | Customer’s users; people named in or sending Customer Content (e.g. employees, subcontractors, clients, students) |
| Personal data | Names, email addresses, and any personal data contained in documents and messages the Customer uploads |
| Special categories | Only if the Customer uploads them; the Customer is responsible for having a lawful basis |
2. Processor obligations
- Process personal data only on the Customer’s documented instructions (the agreement, this DPA, and the Customer’s use and settings of the service), and tell the Customer if we believe an instruction breaks data protection law.
- Ensure everyone with access is bound by confidentiality.
- Implement the security measures in Annex 1.
- Help the Customer respond to data subject requests (access, correction, deletion, export) and with security, breach notification and data protection impact assessments, taking into account the nature of the processing.
- Not sell or share personal data, not use it for our own purposes, and not use Customer Content to train AI models.
3. Sub-processors
The Customer authorizes the sub-processors listed on our sub-processors page. We will give at least 30 days’ notice of a new sub-processor by updating that page and emailing Customer admins; the Customer may object on reasonable grounds, and if we cannot address the objection the Customer may terminate the affected service. We remain responsible for our sub-processors and bind them to data protection terms at least as protective as this DPA.
4. International transfers
Personal data is stored in the United States (AWS us-west-2). For transfers from the EEA, UK or Switzerland, the parties agree to the EU Standard Contractual Clauses (Module 2, controller to processor) and the UK International Data Transfer Addendum, which are incorporated by reference.
5. Personal data breaches
We will notify the Customer without undue delay, and within 72 hours of becoming aware of a personal data breach affecting its data, with the information then available: what happened, the data and people affected, likely consequences, and the measures taken or proposed. We will update the Customer as we learn more.
6. Audits
We will make available the information needed to demonstrate compliance with this DPA, and answer reasonable security questionnaires once a year. Where that is insufficient, the Customer may carry out an audit on 30 days’ notice, at its own cost, during business hours and subject to confidentiality.
7. California (CCPA/CPRA)
We act as a “service provider” / “processor”: we will not sell or share personal information, retain, use or disclose it outside the direct business relationship, or combine it with other data except as permitted by law.
8. Customer obligations
The Customer is responsible for the lawfulness of the personal data it uploads, for the notices and consents required to collect it, and for its own settings (who is invited, which AI features and outside links are on).
9. Return and deletion
Admins can export Customer Content at any time. When the agreement ends, we delete Customer Content within 30 days, and it leaves backups within a further 35 days, unless the law requires us to keep it.
Annex 1 — Security measures
- Encryption in transit (TLS 1.2+) and at rest (AWS-managed encryption for databases and file storage).
- Logical separation of every organization’s data; each request is restricted to one organization.
- Sign-in only through Google or Microsoft; invitation-only access; roles; confidential documents; guest restrictions.
- Outside links: unguessable tokens, expiry, optional passwords with lockout, download limits, rate limits, blocked executable file types.
- Short-lived signed links for file access; files never publicly readable.
- Per-document audit trail and project activity history.
- Infrastructure defined as code; production changes deployed through an automated pipeline without stored cloud keys; production data protected against deletion, with point-in-time backups (35 days).
- Least-privilege access for our own staff; multi-factor authentication on administrative accounts.
- AI through Amazon Bedrock, which does not retain or train on Customer Content.