Data Processing Agreement v1.0
This Data Processing Agreement ("DPA") governs the processing of personal data by ABC Dynamic Environment (ABC-IO) on behalf of its customers.
1. Definitions
- "Controller" — The customer who determines the purposes and means of processing personal data.
- "Processor" — ABC-IO, who processes personal data on behalf of the Controller.
- "Personal Data" — Any information relating to an identified or identifiable natural person.
- "Processing" — Any operation performed on personal data (collection, storage, retrieval, deletion, etc.).
2. Scope of Processing
ABC-IO processes the following categories of personal data on behalf of Controller:
- Account Data: Name, email, company name, phone number (for account creation and authentication)
- Usage Data: API call logs, request timestamps, IP addresses (for service delivery and security)
- Transaction Data: Purchase history, wallet balances, invoice records (for billing and fulfillment)
- Support Data: Ticket content, email correspondence (for customer support)
3. ABC-IO Obligations
ABC-IO agrees to:
- Process personal data only on documented instructions from the Controller
- Ensure all staff with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (encryption at rest and in transit, access controls, audit logging)
- Notify Controller within 72 hours of becoming aware of a personal data breach
- Assist Controller in responding to data subject requests (access, rectification, erasure, portability)
- Delete or return all personal data upon termination of service
- Make available to Controller all information necessary to demonstrate compliance with GDPR Article 28
4. Subprocessors
Controller authorizes ABC-IO to engage the following subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | US |
| Google LLC (GA) | Analytics | US |
| Let's Encrypt | SSL certificates | US |
ABC-IO will notify Controller of any changes to subprocessors via email 30 days in advance.
5. Data Retention
- Account Data: Retained for the duration of the account plus 30 days after deletion request
- Usage Logs: 90 days rolling, then automatically purged
- Transaction Records: 7 years (for tax and accounting compliance)
- Support Tickets: 3 years from last activity, then anonymized
6. Security Measures
- TLS 1.2/1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Role-based access control (RBAC) with least privilege
- Immutable audit logs for all data access
- Regular vulnerability scanning and penetration testing
- Geographic redundancy with encrypted backups
7. Data Subject Rights
ABC-IO will assist Controller in responding to requests from data subjects to:
- Access their personal data (Article 15 GDPR)
- Rectify inaccurate data (Article 16 GDPR)
- Erasure / "right to be forgotten" (Article 17 GDPR)
- Data portability (Article 20 GDPR)
- Restrict processing (Article 18 GDPR)
- Object to processing (Article 21 GDPR)
8. Contact
For data protection inquiries:
- Email: privacy@abc-io.net
- DPO: Christopher Porreca (owner)
- Response time: Within 72 hours
Last updated: 2026-09-11
Version: DPA/1.0