Data Processing Agreement.
The DPA governs how we process personal data on your behalf. This page summarises it in plain terms; the signed document is the authority.
What it covers
●Roles: you are the controller, Specicon is the processor. We never process your customers’ data for our own purposes.●Purpose limitation: data is used to return the decision you asked for, and to keep that decision auditable.●Instructions: documented processing instructions are the contract plus your configuration in the console.●Duration: the term of your subscription, plus the retention window you set (24 months by default).
Transfers
Primary regionap-south-1 (Mumbai)Alternate regionseu-central-1, us-east-1MechanismSCCs, modules 2 and 3Onward transferssub-processors only, listed
Security and breach
●Encryption in transit (TLS 1.3) and at rest (AES-256).●Pseudonymous customer identifiers — the User Barcode carries dimensions, not identities.●Breach notification without undue delay and within 48 hours of confirmation.●Annual penetration test with a summary letter available under NDA.
Your rights as controller
●Audit: one audit or questionnaire per contract year, plus the security whitepaper on request.●Deletion and export: initiated from Settings in the console; invoiced decisions keep their audit record.●Sub-processor objection: 30 days’ notice before a new sub-processor starts processing.
Get a countersigned copy
Send your entity details and signatory to contact@specicon.com, or ask your account manager. We countersign the standard DPA within two business days; redlines take longer and go through counsel.