Data Processing Addendum
This DPA governs how Aegis Firma processes personal data on behalf of customers. It supplements the Terms of Service and reflects the GDPR Article 28 processor requirements.
Data processing model: Customer-as-controller, Aegis Firma-as-processor
You (the customer) determine the purposes and means of processing personal data in Aegis Firma. We process that data only according to your instructions. You remain responsible for ensuring your use of Aegis Firma complies with applicable data protection law.
1. Parties and Definitions
Controller: The customer entity that has entered into the Aegis Firma Terms of Service. The Controller determines the purposes and means of processing Personal Data.
Processor: Aegis Firma (operated by Aegis Digital Systems). The Processor processes Personal Data on behalf of the Controller according to the Controller's instructions.
Personal Data: Any information relating to an identified or identifiable natural person that the Controller submits to the Service.
Processing: Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, erasure, or destruction.
Sub-processor: Any third party engaged by the Processor to process Personal Data on the Controller's behalf.
2. Processor Obligations
Aegis Firma, as Processor, undertakes to:
- Process Personal Data only on documented instructions from the Controller (i.e., to provide the Service as described in the Terms of Service)
- Ensure persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see our Security Posture)
- Respect the conditions for engaging sub-processors as set out in Section 5
- Assist the Controller in responding to data subject rights requests, taking into account the nature of the processing
- Assist the Controller with security, breach notification, DPIAs, and prior consultation obligations
- Delete or return all Personal Data at the end of the service relationship, at the Controller's choice
- Provide all information necessary to demonstrate compliance with Article 28 GDPR, and allow for audits and inspections
3. Controller Obligations and Compliance Responsibility
Important: You remain the Controller. You own compliance decisions.
Aegis Firma generates documentation tools and workflows. We are your data processor β not your compliance officer, legal counsel, or regulator. You are solely responsible for determining whether your use of the Service (and the outputs generated) satisfies your applicable legal obligations.
The Controller represents and warrants that:
- It has a lawful basis for transferring Personal Data to Aegis Firma for processing
- It has provided all required notices to data subjects about the processing
- It has the authority to enter into this DPA on behalf of the Controller entity
- It will not submit Personal Data to the Service that requires a higher level of protection than our standard security measures provide (e.g., special categories of data) without first obtaining our written agreement
4. Subject Matter, Nature, and Purpose of Processing
5. Sub-processors
By entering into this DPA, the Controller provides general written authorization for Aegis Firma to engage sub-processors. Current authorized sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (West Europe) |
| LemonSqueezy | Payment processing (Merchant of Record) | USA |
| Resend | Transactional email | USA |
| Cloudflare | CDN, DDoS protection, DNS | Global edge |
We will notify you of new sub-processors by updating this page. You may object to a new sub-processor within 30 days of notification. If we cannot accommodate your objection, you may terminate the Service.
6. International Data Transfers
Where Personal Data is transferred from the European Economic Area (EEA) or UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism. Our primary data store (Supabase) is located in the EU. Transfers to US-based sub-processors (Resend, LemonSqueezy, Cloudflare) are made under appropriate safeguards including SCCs or their US equivalents.
7. Security Measures
We implement technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security on all database tables (no customer can access another customer's data)
- Multi-factor authentication available for all accounts
- Regular dependency vulnerability scanning
- Content Security Policy blocking unauthorized data exfiltration
- Tamper-evident audit log for all data access events
Full security posture: aegisfirma.com/security/posture
8. Data Subject Rights Assistance
Where a data subject exercises their rights (access, erasure, restriction, portability, objection) and those rights apply to data processed by Aegis Firma on your behalf, we will assist you in responding. You can export all data for a user via the Settings page. Account deletion permanently removes all associated Personal Data, subject to legal retention requirements.
9. Breach Notification
In the event of a Personal Data breach, we will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach, where feasible. We will provide sufficient information to allow the Controller to meet its own breach notification obligations under applicable law.
10. Audit Rights
The Controller may conduct audits of our data processing activities or commission third-party auditors to do so, subject to 30 days' written notice and agreement on audit scope and cost allocation. We may satisfy audit requests by providing documentation of our security controls and certifications in lieu of on-site visits.
11. Return and Deletion of Data
On termination of the Service agreement, or on the Controller's request, we will delete or return all Personal Data. You may export all your data at any time from the Settings page. Account deletion is permanent and immediate. We retain only what is legally required (e.g., billing records for 7 years per applicable tax law).
12. Contact
Questions about this DPA? Contact us via in-app feedback (sign in required). We aim to respond within 48 hours on business days.