Data Processing Agreement (DPA)
Template Version: 1.0 Effective Date: [DATE]
This Data Processing Agreement ("DPA") is entered into between:
Data Controller: [CUSTOMER_LEGAL_NAME], a company registered at [CUSTOMER_ADDRESS] ("Customer")
Data Processor: Pavri, Inc., a company incorporated in [STATE], USA ("Pavri")
Together referred to as the "Parties."
This DPA supplements and forms part of the Master Service Agreement or Terms of Service between the Parties ("Agreement").
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person processed under this DPA
- Processing: Any operation performed on Personal Data
- Sub-processor: Any third party engaged by Pavri to process Personal Data on behalf of Customer
- Data Breach: A confirmed breach of security leading to accidental or unlawful access to Personal Data
2. Scope of Processing
2.1 Subject Matter
Pavri processes Personal Data as necessary to provide the AI agent security monitoring services described in the Agreement.
2.2 Nature and Purpose
| Processing Activity | Purpose |
|---|---|
| Agent telemetry ingestion | Monitoring AI agent behavior for security threats |
| Policy enforcement decisions | Applying governance rules to agent actions |
| Audit log storage | Compliance evidence and incident investigation |
| Session analysis | Threat detection and operator visibility |
2.3 Categories of Data Subjects
Customer's employees, contractors, and end users whose interactions generate agent telemetry.
2.4 Categories of Personal Data
- Operational data: IP addresses in audit logs, user identifiers in session metadata
- Agent-generated data: Tool call metadata, model invocation summaries
- Account data: Names, email addresses of dashboard users
Note: Pavri does not receive or store raw AI model prompts or outputs by default. Log forwarding of prompt content is opt-in and subject to additional controls.
3. Pavri's Obligations
3.1 Processing on Instructions Only
Pavri processes Personal Data only on Customer's documented instructions, except where required by applicable law.
3.2 Confidentiality
Pavri ensures persons authorized to process Personal Data are bound by appropriate confidentiality obligations.
3.3 Security
Pavri implements appropriate technical and organizational measures including:
- TLS 1.2+ for data in transit
- AES-256 for data at rest
- Role-based access controls
- Annual security training for personnel with data access
- Incident response procedures (see Incident Response Plan)
3.4 Sub-processors
Customer authorizes Pavri to use Sub-processors. Pavri maintains a current list of Sub-processors at [SUBPROCESSOR_LIST_URL]. Pavri will:
- Give 30 days' prior notice of new Sub-processors
- Impose equivalent data protection obligations on Sub-processors
- Remain liable for Sub-processor performance
3.5 Data Subject Rights
Pavri will assist Customer in responding to Data Subject rights requests within the agreed timeframes. Requests may be submitted to privacy@pavri.ai.
3.6 Data Breach Notification
Pavri will notify Customer of a confirmed Data Breach within 72 hours of becoming aware, providing:
- Nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences
- Measures taken or proposed to address the breach
3.7 Data Deletion
Upon termination of the Agreement or written request, Pavri will delete all Customer Personal Data within 30 days, except where retention is required by law. Encrypted backup copies will be purged after the 30-day backup retention period.
3.8 Audits
Customer may audit Pavri's compliance with this DPA once per year with 30 days' notice, or following a Security Incident. Audits may be conducted through questionnaire, documentation review, or on-site inspection (at Customer's cost).
4. Customer's Obligations
Customer warrants that:
- It has a valid legal basis for the Personal Data it submits for processing
- It has provided appropriate notices to Data Subjects
- It will not submit Special Category Data (health, financial, etc.) without explicit written agreement
5. International Data Transfers
Where Personal Data is transferred from the EU/EEA to Pavri in the US, the Parties agree that the EU Standard Contractual Clauses (Controller to Processor, 2021/914/EU) are hereby incorporated by reference and form part of this DPA.
6. Liability
Each Party's liability under this DPA is subject to the limitations set out in the Agreement.
7. Term
This DPA is effective upon execution and remains in force for the duration of the Agreement.
8. Signatures
Data Controller:
Signature: ___________________________ Name: [CUSTOMER_SIGNATORY_NAME] Title: [CUSTOMER_SIGNATORY_TITLE] Date: [DATE]
Data Processor (Pavri, Inc.):
Signature: ___________________________ Name: [PAVRI_SIGNATORY_NAME] Title: [PAVRI_SIGNATORY_TITLE] Date: [DATE]
Appendix A — Sub-processor List: [SUBPROCESSOR_LIST_URL] Appendix B — Standard Contractual Clauses: Incorporated by reference (2021/914/EU)