Skip to content
RohaLabs
Legal / 04

Data Processing Agreement

The terms that apply when we process personal data on a client's behalf — as we do when we build or operate a platform for them.

1. Scope and roles

This agreement applies where Roha Labs processes personal data on behalf of a client in the course of delivering or operating a platform. The client is the controller and decides why and how the data is processed. Roha Labs is the processor and acts on the client's documented instructions.

It supplements the main services agreement. Where the two conflict on data protection, this agreement prevails.

2. Subject matter, nature and duration

The subject matter is the processing needed to provide the agreed services. The categories of data subject and personal data depend on the platform concerned — for a telecom service that may be subscriber identifiers and transaction records; for a clinical system, patient and appointment records. These are set out per engagement.

Processing lasts for the term of the services agreement, plus any period needed to return or delete the data.

3. Our obligations as processor

  • Process personal data only on the client's documented instructions, including on international transfers
  • Ensure everyone authorised to process the data is bound by confidentiality
  • Implement appropriate technical and organisational security measures
  • Assist the client in responding to data subject requests, so far as we are able
  • Assist with security, breach notification and impact assessment obligations
  • Delete or return the data at the end of the engagement, at the client's choice
  • Make available the information needed to demonstrate compliance, and allow audits

4. Sub-processors

The client gives general authorisation for us to engage sub-processors — typically hosting, infrastructure and communications providers. We impose data protection obligations on each of them no less protective than these, and we remain responsible for their performance.

We will give notice of any intended change of sub-processor, and the client may object on reasonable data protection grounds.

5. International transfers

Where processing involves transferring personal data out of the European Economic Area, the transfer is made under an approved safeguard — normally the European Commission's standard contractual clauses, together with any supplementary measures the circumstances require.

6. Security

We apply measures appropriate to the risk, including encryption in transit, role-based access control with least privilege, separation of environments, audit logging of administrative actions, and restricted production access.

Specific measures for a given platform are recorded in the engagement documentation.

7. Personal data breach

We will notify the client without undue delay after becoming aware of a personal data breach affecting their data, with the information available to us, and will cooperate in investigating and remedying it.

8. Term and termination

This agreement runs for as long as we process personal data on the client's behalf. On termination we will, at the client's choice, return or delete the data, unless we are required by law to retain it.