Data Processing Agreement
The Article 28 terms on which we process personal data on a customer's behalf: what we may do with it, what we must do for you, and what happens to it at the end.
Last updated 2026-07-28
Awaiting counsel review.
This document is not legal advice and has not yet been reviewed by a qualified lawyer. Anything shown as "to be supplied" is a value the operating company has yet to provide, and is left visible rather than guessed. Statements about how the product behaves are drawn from the implementation and are accurate.
Parties and precedence
This agreement is between the customer (the "Controller") and Sodasoft LLC, a limited liability company registered in the State of Wyoming, at 30 N Gould St, Sheridan, WY 82801, the United States (the "Processor", "we").
It forms part of the Terms of Service and prevails over them on any point about personal data. It is governed by the same law and courts as the Terms.
This document is a draft prepared for review by a qualified lawyer. It is not legal advice and is not executed until both parties sign it.
Anything shown as "to be supplied" is a value the operating company must complete before this document is relied on.
Article 28(3)(a) - processing only on documented instructions
We process personal data only on the Controller's documented instructions, including on transfers to a third country. The Controller's instructions are: the Terms of Service, this agreement, the configuration the Controller sets in the product, and any further written instruction the parties agree.
We do not process customer register content for our own purposes. We do not use it to train any model, to build a product feature, or for analytics of any kind.
If we believe an instruction infringes the GDPR or another Union or member state data protection provision, we will tell the Controller and may suspend that processing until it is resolved.
Article 28(3)(b) - confidentiality
Every person we authorise to process personal data is bound by a written confidentiality obligation that survives the end of their engagement. Access is granted on a need-to-know basis and is removed when the need ends.
Article 28(3)(c) - security of processing (Article 32)
The measures below are the ones actually implemented, not an aspiration. A reviewer can test each of them.
- Tenant isolation in four layers: every query runs through a scoped accessor that binds the tenant, PostgreSQL row-level security is ENABLEd and FORCEd on every tenant-bearing table, a tenant registry gates the accessor, and the cross-tenant administrative surface is a separate application.
- The application connects to the database as a role without permission to bypass row-level security, so a defect in application code cannot read across tenants.
- Authentication is a single-use email link plus TOTP two-factor authentication. The second factor is enforced where an actor is resolved, so it applies to every page, every server action and every API route.
- Role-based authorisation is enforced at the data layer, not in the interface, because every server action is addressable over HTTP.
- Uploaded evidence is stored privately, served only through short-lived non-guessable links, and its SHA-256 hash is recorded on upload and recomputed on a weekly sweep so tampering is detectable rather than assumed.
- The audit log is append-only: the application role holds INSERT and no UPDATE or DELETE grant, enforced in the database rather than in code.
- Data in transit is protected by TLS with HSTS. Database storage and the evidence store are encrypted at rest by the respective providers.
- Error monitoring receives no register content and no document: request bodies, cookies, authorisation headers and query strings are removed, and record identifiers in URLs are replaced before an event is sent.
Article 28(3)(d) - sub-processors
The Controller gives general written authorisation for us to engage the sub-processors listed at /legal/subprocessors. That list states, for each one, what it does, what data it handles, where it is, and the transfer mechanism where it sits outside the EEA.
We will publish any addition to that list before it takes effect and give the Controller at least thirty days to object on reasonable data protection grounds. If an objection cannot be resolved, the Controller may terminate the affected part of the service without penalty and receive a refund of fees paid for the unused period.
Each sub-processor is bound by written terms imposing obligations no less protective than these, and we remain fully liable to the Controller for its performance.
Article 28(3)(e) - assisting with data subject rights
The product is built so the Controller can answer most requests without us: register content, evidence and the audit trail are all readable and exportable from the interface and the API.
Where a request reaches us instead, we will not respond to it ourselves. We will forward it to the Controller without undue delay and assist by appropriate technical and organisational measures, taking account of the nature of the processing.
Article 28(3)(f) - assisting with Articles 32 to 36
We will notify the Controller of a personal data breach affecting their data without undue delay and in any event within twenty-four hours of becoming aware of it, with the information we hold at that point, and will supplement it as the picture develops. We will not delay a notification to make it complete.
We will assist the Controller with data protection impact assessments and prior consultation by providing the information about our processing that is reasonably required and that the Controller cannot obtain for itself.
We will make available the information necessary to demonstrate compliance with Article 28 and allow and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. The corresponding rights of access, inspection and audit are set out in the Terms of Service.
Article 28(3)(g) - deletion or return at the end
On termination, or on the Controller's documented erasure instruction, erasure is scheduled 30 days out. The workspace stays fully usable and exportable throughout that period and the request can be withdrawn, so an instruction given in error is recoverable. On that date the register rows and the stored evidence bytes are deleted irreversibly. Deleted means removed, not flagged.
The single exception is the audit log, which is retained for 5 years after the agreement ends. Its purpose is to answer a supervisory question about a filing made during the relationship, which is a legal obligation under Article 17(3)(b), and the period is bounded rather than indefinite so that it stays lawful under Article 5(1)(e). Entries are reduced to what identifies the actor and the action; they do not retain a copy of the record that was changed.
Users, entities and the workspace record itself are pseudonymised rather than deleted: names, email addresses and identifiers such as an LEI are replaced and accounts deactivated, while the internal identifier survives so the audit trail can still say that the same person did these things. The database enforces this - it refuses to delete a user that an audit entry names - and it is what makes retaining the trail lawful without retaining the people in it.
The Controller may ask us to certify in writing that deletion has been carried out, and we will.
Article 28(3)(h) - information and audits
On reasonable notice, and no more than once in any twelve months unless a supervisory authority or a personal data breach requires otherwise, the Controller may audit our compliance with this agreement. We will cooperate, provide the information we hold, and answer a security questionnaire.
Nothing in this section limits a supervisory authority's own powers, or the audit and access rights the Controller holds under DORA Article 30, which are set out in the Terms of Service and are not restricted by frequency.
Subject matter, duration, nature, purpose, categories
| Item | Detail |
|---|---|
| Subject matter | Provision of the Treica ICT third-party governance platform. |
| Duration | The term of the Terms of Service, plus the deletion and retention periods above. |
| Nature and purpose | Storing, organising, validating and exporting a register of ICT third-party arrangements so the Controller can meet its obligations under Regulation (EU) 2022/2554. |
| Types of personal data | Names, business email addresses, job roles and sign-in events of the Controller's own personnel and of its external auditors and consultants; names and business contact details of individuals at the Controller's ICT third-party providers; any personal data the Controller chooses to place in free-text fields or uploaded evidence. |
| Categories of data subject | The Controller's employees and contractors, its appointed external auditors, and contact persons at its ICT third-party providers. |
| Special categories | None are required by the service and none should be uploaded. The product does not ask for any. |
International transfers
We are established in the United States, outside the EEA. Customer register content and evidence are stored in the European Union and are not relocated, but administering the service from the United States means personal data may be accessed from outside the EEA. Those transfers are made under the European Commission's standard contractual clauses (Module Two, controller to processor), which are incorporated into this agreement by reference and prevail over it on any conflict, together with a transfer impact assessment available on request.
Our representative in the Union under Article 27 GDPR is to be supplied.
Liability
The limitation of liability in the Terms of Service applies to this agreement, save that nothing in it limits either party's liability to a data subject under Article 82 GDPR or a fine imposed by a supervisory authority, neither of which can be capped by agreement between the parties.