Back to home

Data Processing Agreement

Draft version — subject to final legal review

Between the customer organisation using SpecOne ("Controller") and SpecOne ("Processor"). This agreement forms part of the SpecOne contract and is concluded electronically at organisation signup. It is drafted to satisfy Art. 28 of both the EU GDPR and the UK GDPR and constitutes a service-provider agreement for CCPA/CPRA purposes. For EU/UK Controllers, transfers to the US-based Processor are protected by [the Data Privacy Framework and/or] the EU Standard Contractual Clauses (Module 2) with the UK Addendum, incorporated by reference where required.

1. Subject matter

Processing of data uploaded to or generated in the Platform (specifications, artwork, scan and translation results, account and usage data) to provide the contracted services, for the term of the contract.

2. Data

Business contact and account data; content data which may incidentally contain personal data; data subjects are the Controller's employees and contractors and persons appearing in uploaded content.

3. Processor obligations

Processing only on documented instructions (use of the Platform's functions constitutes instructions); no sale or sharing of personal information; confidentiality commitments; the technical and organisational measures below; support with data-subject requests and Art. 32–36 obligations; breach notification without undue delay with Art. 33(3) information; deletion or return of personal data at contract end subject to statutory retention; audit support with reasonable notice.

4. Subprocessors

General authorisation for the listed subprocessors (hosting/database, file storage, deployment platform, payment, e-mail, AI model providers: Supabase, Cloudflare, Lovable, Stripe, Resend, Anthropic, OpenAI, Google); advance notice of changes with a 14-day objection right; transfers safeguarded by SCCs / UK Addendum and adequacy decisions or the Data Privacy Framework.

Technical and organisational measures (summary)

Personal accounts and role-based permissions with mandatory MFA for administrative roles; invitation-only registration; database row-level security isolating each organisation's projects, files and billing data with an automated cross-tenant test suite on every release; TLS and encryption at rest; project files via short-lived signed URLs after access checks; audit logging, security alerting and health monitoring; backups via the hosting provider; secrets stored server-side only.