Data Processing Agreement framework.
SupraOS maintains a customer-ready DPA framework covering data flows, security, subprocessors, transfers, retention and deletion. The schedules are completed for each deployment.
Effective and last reviewed: 16 July 2026
Before signature, SupraOS completes the parties, data flow, connected systems, data categories, action classes, retention, security schedule, subprocessors, transfer mechanism and customer schedules.
What the framework covers
Roles and instructions
Controller/processor roles, documented instructions, confidentiality and personnel obligations.
Security and governed AI
Technical and organisational measures, AI/model processing, customer controls, action gates and Action Receipt boundaries.
Rights and incidents
Data-subject assistance, DPIAs, security incidents, government requests and cooperation.
Subprocessors
Deployment-specific providers, purposes, locations, transfer safeguards, change procedures and deletion behavior.
Transfers
EU SCCs, the UK Addendum or UK IDTA, and other applicable transfer terms selected for the actual data path.
Return and deletion
Active-system deletion, exports, temporary files, subprocessors, backups, legal holds and written confirmation.
What must be completed for each customer
| Schedule item | Deployment-specific completion |
|---|---|
| Parties and roles | Customer legal entity, controller/processor role, SupraOS contracting details and authorized signatories. |
| Data map | Data subjects, personal-data categories, systems, fields, purposes, frequency, regions and remote-access locations. |
| Action scope | Read-only and write-enabled connectors, permitted actions, approvers, risk thresholds and prohibited actions. |
| Retention and deletion | Active data, evidence/cache, prompts/outputs, Action Receipts, logs, support records, exports and backup expiry. |
| Subprocessors and transfers | Exact legal entity, service, location, provider configuration, retention and applicable transfer mechanism. |
| Security schedule | Verified technical and organisational measures for the actual deployment. |
Request the current diligence materials
Security and legal teams can request the DPA framework, MSA and Security Schedule / TOMs. The signature copy is completed for the proposed deployment.