Data Processing Agreement
Last updated: February 7, 2026
1. Scope and nature of processing
CaviusConnect acts as a data processor for customer data processed through our platform. We process personal data solely on your instructions and in accordance with applicable data protection laws including GDPR and CCPA.
Data types: contact information, message content, metadata, usage analytics, and authentication credentials.
Data subjects: your customers, employees, and end-users who interact with your organization through our platform.
2. Data processor obligations
We commit to:
- Process data only on your documented instructions
- Ensure personnel authorized to process data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist with data subject rights requests (access, deletion, portability)
- Notify you of data breaches within 48 hours of discovery
- Delete or return data upon termination of services
3. Sub-processors
We engage the following categories of sub-processors:
- Cloud infrastructure: Google Cloud Platform (GCP) for data hosting and compute
- Database: MongoDB Atlas for data storage
- Messaging providers: Twilio (SMS), SendGrid (Email), Meta (WhatsApp Business API)
- AI services: Google Vertex AI for natural language processing
- Monitoring: cloud logging and analytics services
We will notify you of any changes to sub-processors with 30 days' notice. You may object to new sub-processors within this period.
4. Security measures
Encryption: TLS 1.3 in transit, AES-256 at rest.
Access control: role-based access, multi-factor authentication, least-privilege principle.
Infrastructure: multi-tenant isolation, regular security patching, intrusion detection.
Testing: annual penetration testing, vulnerability scanning, security audits.
5. Data breach notification
We will notify you within 48 hours of becoming aware of a personal data breach. Our notification will include the nature of the breach, affected data categories, likely consequences, and mitigation measures taken.
6. International transfers
Data may be processed in the United States and other jurisdictions where our sub-processors operate. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers outside the EEA.
7. Audit rights
You have the right to audit our compliance with this DPA once per year with 30 days' notice. We will provide necessary documentation and access to demonstrate compliance.
8. Term and termination
This DPA remains in effect as long as we process personal data on your behalf. Upon termination, we will delete or return all personal data within 30 days, unless legally required to retain it.
9. Contact for DPA matters
For DPA-related questions or to exercise your rights under this agreement, contact our Data Protection Officer at dpo@caviusconnect.com.
