Draft for legal review

Data processing agreement

Last updated

1. Parties and scope

This Data processing agreement ("DPA") is between the customer that has accepted the CompleteVantage Terms of service ("Customer", the controller) and [Company legal name], registered at [Registered address] ("Processor"). It forms part of the Terms and applies whenever the Processor processes personal data on the Customer's behalf in providing CompleteVantage.

Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the EU General Data Protection Regulation 2016/679 ("GDPR") and, where applicable, the UK GDPR ("Data Protection Law").

If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data.

2. Subject matter and duration

  1. Subject matter: hosting and delivering digital signage content to the Customer's screens, and providing the admin, monitoring, reporting and related features of CompleteVantage.
  2. Duration: for the term of the Customer's subscription, and afterwards until the personal data is deleted or returned under section 10.

3. Nature and purpose of processing

The Processor stores, converts, transmits and displays data only to:

  • host Customer Content and deliver it to paired screens;
  • show screen status, screenshots and live view to authorized users;
  • record proof-of-play and produce reports and CSV exports;
  • send alerts to destinations the Customer configures (email, Microsoft Teams, Slack, webhooks);
  • fetch calendar feeds the Customer connects and show events on screens;
  • keep an activity log of changes in the Customer's organization;
  • provide support, keep the service secure and meet legal obligations.

4. Categories of data subjects and personal data

Data subjectsPersonal data
Customer's users of the adminName, email, role, hashed password, sign-in times, activity log entries
People appearing in Customer Content (for example staff, visitors, event speakers)Names, photos, video, job titles and other content the Customer chooses to show
People named in connected calendarsMeeting titles, organizers and times, as published in the calendar feed. Private events are shown as "Busy"
People near screens, incidentallyImages captured in screenshots of what a screen is showing (screens do not use cameras)
Alert recipientsEmail addresses and webhook destinations

Device data such as IP address, model, app version and time zone relates to screens. It may be personal data where a device can be linked to an individual.

The Customer should not use CompleteVantage to process special categories of personal data unless it has assessed that this is lawful and appropriate.

5. Customer instructions

The Processor processes personal data only on the Customer's documented instructions. The Terms, this DPA and the Customer's use and configuration of the service are those instructions. The Processor will inform the Customer if it believes an instruction breaks Data Protection Law, unless the law prevents it.

6. Processor obligations

The Processor will:

  1. process personal data only as described in section 5, unless required by law, in which case it will inform the Customer first where legally allowed;
  2. ensure that its staff and contractors with access to personal data are bound by confidentiality;
  3. apply the security measures in Annex A;
  4. not sell personal data or use it for its own purposes, such as advertising;
  5. keep records of processing as required by Article 30(2) GDPR.

7. Sub-processors

  1. The Customer gives general authorization for the Processor to use sub-processors. The current list is in our privacy policy and includes [Hosting provider], [Email provider] and Stripe (for billing data).
  2. The Processor will give at least [30] days' notice of a new sub-processor by [email to organization owners / update to the list]. The Customer may object on reasonable data protection grounds. If the parties cannot resolve it, the Customer may terminate the affected service and receive a refund of prepaid fees for the unused period.
  3. The Processor will impose data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible for their performance.
  4. Services that the Customer itself connects to its screens (for example web dashboards, video platforms, RSS feeds or calendar providers), and the Open-Meteo weather service called directly by screens that use the weather widget, are chosen by the Customer and are not sub-processors of the Processor.

8. Personal data breaches

  1. The Processor will notify the Customer without undue delay, and in any case within [48] hours, after becoming aware of a personal data breach affecting Customer personal data.
  2. The notice will describe, as far as known, the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed. Information may be provided in stages.
  3. The Processor will take reasonable steps to contain the breach and reduce its effects.

9. Assistance

Taking into account the nature of the processing, the Processor will reasonably assist the Customer with:

  • responding to data subject requests (much of this can be done by the Customer directly in the admin, for example editing or deleting media, users and screens);
  • data protection impact assessments and prior consultations with supervisory authorities;
  • meeting its security and breach notification obligations.

If the Processor receives a request directly from a data subject about Customer data, it will pass it to the Customer and not respond itself, unless authorized. [Assistance beyond reasonable levels may be charged at agreed rates.]

10. Deletion and return

At the end of the service, the Customer can export proof-of-play reports and request a copy of its uploaded media within [30] days. After that the Processor will delete Customer personal data from the live service. Backups are deleted on their normal cycle (currently 14 days). The Processor may keep data where the law requires, and will protect it and use it for no other purpose.

11. Audits

The Processor will make available the information reasonably needed to demonstrate compliance with this DPA, including written answers to security questionnaires. Where that is not enough, the Customer may carry out an audit, or have an independent auditor bound by confidentiality do so, no more than once a year, with at least [30] days' notice, during business hours and at the Customer's cost. [Audit terms to be reviewed by counsel.]

The Processor does not currently hold third-party security certifications.

12. International transfers

[Describe hosting location.] Where Customer personal data is transferred to a country without an adequacy decision, the parties agree that the [EU Standard Contractual Clauses (Module Two or Three) / UK International Data Transfer Addendum] apply and are incorporated by reference, with the following choices: [docking clause, governing law, supervisory authority and annexes to be completed].

13. Liability and general terms

Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Law does not allow this. This DPA is governed by the law that governs the Terms, unless the Standard Contractual Clauses require otherwise.


Annex A: Technical and organizational security measures

The following measures are in place in the service today.

Access control and separation

  • Data is scoped per organization: every record belongs to one organization and every database query is limited to it.
  • Role-based access (owner, admin, editor, viewer), checked on every route. An admin cannot reset an owner's password.
  • Optional approval workflow so editors' changes need an admin's approval before they reach screens.
  • Passwords are stored as one-way hashes. A password reset signs the account out of every session.
  • Rate limits on sign-in, screen pairing and device registration.
  • An activity log of changes, kept for 2 years by default.

Application security

  • CSRF protection on every change in the admin.
  • Content Security Policy with a per-request script nonce, and frame headers on admin pages.
  • Session cookies are HTTP-only and restricted to same-site requests; sign-in redirects are checked.
  • Layout widget settings are validated and escaped on the server.
  • Request size limits on the device API and JSON bodies.

Screens and devices

  • Each screen authenticates with its own device token, stored on the server only as a SHA-256 hash. A paired device cannot be re-registered without its token.
  • The Android app's bridge to device functions answers only the configured server's top-level page, using a per-page-load key; embedded web content cannot use it.
  • App updates are verified by SHA-256 before installation.
  • Screenshots are taken only on an authorized user's request or during live view, which stops automatically after at most 5 minutes.

Data handling

  • Uploaded files are checked by content type, and nothing in the uploads area can execute.
  • Converted pages, thumbnails and screenshots are stored at random, unguessable paths.
  • Web page access keys are never returned to the admin interface and are excluded from previews.
  • Calendar feed addresses are fetched by the server and never sent to screens.
  • Outbound requests for feeds and webhooks block private network addresses, pin DNS resolution and re-check every redirect.

Availability and resilience

  • Nightly database backups, kept for 14 days. [Off-site backup copy to be confirmed.]
  • Health checks and log rotation in production.
  • Screens cache content locally and keep playing during network or service outages.

Retention

  • Proof-of-play logs: 400 days by default.
  • Activity log: 2 years by default.
  • Unfinished screen pairings: 7 days.

Contact for this DPA: [Contact email].