DPA

Data processing addendum

A transparent place to publish the data-processing commitments required by business customers.

PUBLIC DRAFT

Clear boundaries before production use.

These public pages describe the product direction in this repository. They require review by StartOCR’s legal and security owners before being relied on as a customer agreement.

Roles and instructions
The executed DPA should identify controller and processor roles and the documented processing instructions.
Security measures
The executed DPA should link to the approved technical and organizational measures, not marketing claims.
Subprocessors
The executed DPA should name the current subprocessors, purpose, location, and change-notification process.
International transfers
The executed DPA should state the approved transfer mechanism when personal data crosses borders.