Data Processing Agreement
01Scope
This summary applies when AESTHETECH processes personal data on behalf of a client, for example, data handled while building, testing, or operating software for that client. It is summarised here; the binding DPA is signed with each client.
02Roles
The client is the controller and decides why and how data is processed. AESTHETECH is the processor and acts only on the client's documented instructions.
03Processing and sub-processors
We process the data necessary to design, build, and run the client's software. We engage sub-processors for hosting and infrastructure under equivalent obligations, and maintain an up-to-date list available on request.
04Security measures
Encryption in transit and at rest, role-based access control, secrets management, audit logging, and least-privilege access. Personnel are bound by confidentiality.
05Transfers, requests and deletion
International transfers rely on Standard Contractual Clauses. We assist the controller with data-subject requests and breach notification, and return or delete data on termination.