Data Processing Agreement
This agreement applies whenever DC ESCRYPT ("Processor") processes personal data on behalf of a customer ("Controller") through Raposa Aval. It is incorporated into the Terms of Service and takes effect when the customer starts using the service. A signed copy is available on request at contact@raposa.group.
1. Subject matter and duration
The Processor operates a human approval service: the Controller's agents submit approval requests, authorized humans decide them, and every decision is recorded in a tamper-evident audit log. Processing lasts for the term of the service agreement plus the retention periods in section 7.
2. Nature and purpose of processing
| Category of data subject | Data processed | Purpose |
|---|---|---|
| Controller's staff acting as approvers | operator identifier, decision, timestamp, comment | recording who authorized an action |
| Controller's end users, where the Controller places their data in a request | free-text context supplied by the Controller | giving the approver enough information to decide |
| Controller's technical contacts | email address, API key hash | account administration and support |
3. Instructions
The Processor processes personal data only on documented instructions from the Controller, which the API calls themselves constitute, unless required otherwise by Union or Member State law. If the Processor believes an instruction infringes the GDPR, it informs the Controller without undue delay.
4. Confidentiality
Everyone authorised to process the data is bound by confidentiality. Access to the production database is limited to named administrators of the Processor.
5. Security (Article 32)
- All traffic served over TLS; the application listens only on loopback behind a reverse proxy.
- API keys and panel passwords stored as SHA-256 hashes only — the plaintext is shown once at issuance and never persisted.
- The agent signing key is Ed25519, generated on the server, permissions 0600, and has never left it.
- Clients are isolated: a client can only read approvals created with its own key; an attempt to read another client's approval returns 404 without disclosing its existence.
- The audit log is an append-only SHA-256 hash chain — modification, insertion or deletion breaks verification and is therefore detectable.
- Outbound callbacks are HMAC-signed and refuse to resolve to internal addresses.
- Daily database backups with integrity verification, retained 14 days.
- Automated availability checks every five minutes.
6. Sub-processors
The Controller gives general authorisation for the sub-processors listed at dcescrypt.com/subprocessors. The Processor announces intended changes at that URL at least 30 days in advance; the Controller may object in writing before the change takes effect, and if the objection cannot be resolved either party may terminate the affected service.
7. Retention and deletion
- Approval records and audit entries: for the life of the account, then 12 months.
- Server logs: 30 days. Support correspondence: 24 months.
- On termination the Controller may request an export within 30 days; after that the data is deleted.
The audit chain is designed so that entries cannot be removed without breaking verification. An erasure request is therefore satisfied by deleting or pseudonymising the personal data inside the entry while the hash remains, which preserves the integrity guarantee the service exists to provide.
8. Data subject rights
Where a data subject contacts the Processor directly, the Processor refers them to the Controller and notifies the Controller without undue delay. The Processor assists the Controller in answering requests, taking into account the nature of processing and the information available.
9. Breach notification
The Processor notifies the Controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach, with the information needed for the Controller's own notification under Articles 33–34.
10. Location and transfers
Application servers and the database are located in Germany. Transactional email is delivered from the EU region (eu-west-1). DNS, edge proxying and inbound email routing are provided by Cloudflare, which may route requests through infrastructure outside the EEA; those transfers rely on the EU Standard Contractual Clauses concluded with that provider.
11. Audits
The Processor makes available the information necessary to demonstrate compliance with Article 28 and allows for audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice and no more than once per year unless a breach or a supervisory authority requires otherwise.
12. Liability and precedence
Liability is governed by the Terms of Service. Where this agreement conflicts with the Terms in matters of data protection, this agreement prevails.
DC ESCRYPT