Data Processing Agreement
This Data Processing Agreement (DPA) is part of the Terms of Service between Repro It (Processor) and the customer that accepts the Terms (Controller). It applies when Repro It processes personal data for that customer. To request a countersigned copy, email agho@reproit.com.
1. Roles and instructions
The customer is the controller of personal data in captured failures and Repros. Repro It is the processor of that data. Repro It processes the data only to provide, secure, and support the service under the Terms, this DPA, the customer's configuration, and other documented instructions. Repro It acts as an independent controller for account, security, and business administration data where applicable law requires that role.
2. Processing details
- Subject and purpose: capture, validation, encryption, managed verification, authorized replay, storage, and workflow management for production backend failures.
- Data categories: operation inputs and outputs, dependency results, required state, environment facts, failure details, exact subject bytes, optional customer identifiers, and service workflow metadata. These categories can contain personal data chosen or produced by the customer's application.
- Data subjects: the customer's users, workers, contractors, contacts, and other people represented in customer systems.
- Operations: collect, receive, validate, encrypt, store, decrypt for an authorized bounded operation, execute in isolation, compare, display, export, and delete.
- Duration: for the service term and the applicable retention period, subject to legal and security retention duties.
3. Repro It obligations
- Process personal data only on documented instructions, unless the law requires other processing. We will inform the customer of that requirement when the law permits.
- Require confidentiality from people who can process personal data.
- Maintain appropriate technical and organizational measures. These include encryption in transit, encrypted Repro storage, scoped credentials, tenant-scoped access, isolated managed replay hosts, bounded operation grants, security logging, and cleanup after managed execution.
- Notify the customer without undue delay after we confirm a personal data breach that affects customer data.
- Provide reasonable assistance with data-subject requests, security duties, impact assessments, and regulator consultations.
- Delete or return customer personal data at the end of the service, unless the law requires retention.
- Provide information reasonably needed to demonstrate compliance. Audits will normally use current documentation, security summaries, and independent reports when available.
4. Customer obligations
The customer must have a lawful basis to process and send personal data. The customer must configure capture, access, retention, and removal for its legal duties. The customer must not send data that the service contract prohibits.
5. Sub-processors
The customer authorizes the providers on the sub-processor list. Repro It will give account holders at least 30 days of notice before it adds or replaces a sub-processor. A customer can object on reasonable data-protection grounds. If the parties cannot resolve the objection, the customer can stop the affected service and receive a proportional refund of prepaid fees for the unused affected service. Repro It remains responsible for each sub-processor's performance under this DPA.
6. International transfers
When required, the parties incorporate the current EU Standard Contractual Clauses for controller-to-processor transfers. For a transfer subject to UK law, the parties also incorporate the UK International Data Transfer Addendum. This DPA and the sub-processor list supply the relevant processing details.
7. Precedence and liability
This DPA controls if it conflicts with the Terms on a data-protection matter. The liability limits and governing terms in the Terms apply to this DPA.