LEGAL

Data Processing Agreement framework.

SupraOS maintains a customer-ready DPA framework covering data flows, security, subprocessors, transfers, retention and deletion. The schedules are completed for each deployment.

Effective and last reviewed: 16 July 2026

The signed DPA defines the customer deployment.

Before signature, SupraOS completes the parties, data flow, connected systems, data categories, action classes, retention, security schedule, subprocessors, transfer mechanism and customer schedules.

What the framework covers

Roles and instructions

Controller/processor roles, documented instructions, confidentiality and personnel obligations.

Security and governed AI

Technical and organisational measures, AI/model processing, customer controls, action gates and Action Receipt boundaries.

Rights and incidents

Data-subject assistance, DPIAs, security incidents, government requests and cooperation.

Subprocessors

Deployment-specific providers, purposes, locations, transfer safeguards, change procedures and deletion behavior.

Transfers

EU SCCs, the UK Addendum or UK IDTA, and other applicable transfer terms selected for the actual data path.

Return and deletion

Active-system deletion, exports, temporary files, subprocessors, backups, legal holds and written confirmation.

What must be completed for each customer

Schedule itemDeployment-specific completion
Parties and rolesCustomer legal entity, controller/processor role, SupraOS contracting details and authorized signatories.
Data mapData subjects, personal-data categories, systems, fields, purposes, frequency, regions and remote-access locations.
Action scopeRead-only and write-enabled connectors, permitted actions, approvers, risk thresholds and prohibited actions.
Retention and deletionActive data, evidence/cache, prompts/outputs, Action Receipts, logs, support records, exports and backup expiry.
Subprocessors and transfersExact legal entity, service, location, provider configuration, retention and applicable transfer mechanism.
Security scheduleVerified technical and organisational measures for the actual deployment.

Request the current diligence materials

Security and legal teams can request the DPA framework, MSA and Security Schedule / TOMs. The signature copy is completed for the proposed deployment.