Back to SenseCore 360

Data Processing Agreement — unsigned review template

Parties and instructions

The deployment contract must identify the controller, processor, authorised instructions, duration, nature of processing, subject categories and data categories. This page is not an executed agreement.

Required processor obligations

The signed agreement should address confidentiality, least-privilege access, security controls, incident assistance, data-subject requests, subprocessors, audit evidence, lawful transfers and deletion or return at termination.

Processing schedule

Complete a schedule for account data, human or animal records, sensor readings, location, alerts, notes, attachments, AI prompts, generated outputs and audit records. Identify purposes, retention, recipients and countries for each flow.

Subprocessors and residency

Record Supabase hosting, external AI/speech providers, notification services, map providers and backup operators where enabled. Obtain required approvals and transfer safeguards before use. Local frontend hosting alone does not make processing on-premise.

Security and exit

Agree recovery objectives, encryption/key ownership, access-review frequency, incident reporting route and contractual timeframes. Validate export, restoration and deletion including backups. Assign responsibility for testing, logs and breach assessments.

Official references: SDAIA regulations · ISO/IEC 27001 · HHS applicability guidance

هذه وثيقة مراجعة أولية. يجب تأكيد الجهة القانونية وموقع معالجة البيانات وسياسات الاحتفاظ والالتزامات التعاقدية قبل اعتماد النشر. لا تمثل شهادة امتثال أو ضماناً لإقامة البيانات.