HomeData Processing Agreement
Data Processing Agreement
B2B data processing terms for DPRQ customers.
Last updated: 2026-09-03
1. Parties and roles
This Data Processing Agreement ("DPA") forms part of the agreement between LUNELL PROFESSIONAL LIMITED ("Processor", "DPRQ") and the Customer entity using DPRQ ("Controller").
Where Customer enters personal data relating to its products, employees, contractors, or other data subjects into DPRQ, Customer is generally the controller and DPRQ acts as processor for that Customer Content.
Where DPRQ processes account, billing, or service data for its own purposes, DPRQ may act as controller as described in the Privacy Notice.
2. Subject matter and duration
Processor processes personal data to provide the DPRQ platform, including account management, product/passport workflows, document storage, validation, publication, billing support, and security monitoring.
Processing continues for the duration of the Customer's use of DPRQ and as otherwise required by law or backup retention.
3. Nature and purpose of processing
- Storage, organisation, retrieval, and display of Customer Content
- Validation and readiness assessment of product data
- Publication of permitted passport fields to public URLs
- Document and evidence management
- User authentication and access control within Customer organisations
- Support, incident response, and service improvement limited to security/reliability
4. Categories of data subjects and data
- Customer personnel with DPRQ accounts
- Economic operator and contact details entered into product/passport records
- Any individuals whose personal data appears in uploaded documents or product fields
- Billing contacts and payment metadata linked to the Customer account
5. Documented instructions
Processor shall process personal data only on documented instructions from Controller, including through Customer use of the platform features, these Terms, this DPA, and documented support requests, unless required by Union or Member State law.
6. Confidentiality
Processor ensures persons authorised to process personal data are bound by confidentiality obligations appropriate to the nature of the processing.
7. Security measures
Processor implements appropriate technical and organisational measures, including authentication, tenant isolation, row-level security, encryption in transit, provider-managed encryption at rest, and access controls as described on the Data Protection page.
8. Subprocessors
Controller authorises Processor to use subprocessors listed at /subprocessors. Processor will maintain an up-to-date list and provide a mechanism to notify material changes.
Current subprocessors include:
Supabase, Inc.: Authentication, PostgreSQL database, object storage, row-level security hosting
Vercel, Inc.: Application hosting and content delivery
Stripe, Inc.: Payment processing and subscription billing
Resend, Inc.: Transactional email delivery
9. Data subject requests
Processor shall assist Controller, taking into account the nature of processing, with applicable data subject requests under GDPR, to the extent such requests relate to Customer Content and Processor is able to assist using available platform tools or manual support.
10. Personal data breaches
Processor shall notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Content and provide information reasonably available to assist Controller in meeting its breach obligations.
11. DPIA and prior consultation
Processor shall provide reasonable assistance with data protection impact assessments and prior consultations where required, taking into account the nature of processing and information available to Processor.
12. Deletion and return
Upon termination of services, Processor shall delete or return Customer Content in accordance with documented instructions and the Data Retention policy, except where retention is required by law or permitted backups.
Automated account deletion workflows may require separate owner-approved implementation — see Account Deletion page.
13. Audits and information
Processor shall make available information necessary to demonstrate compliance with Article 28 GDPR and allow for audits mandated by law or agreed in writing, subject to reasonable notice, confidentiality, and frequency limits.
14. International transfers
Where subprocessors transfer personal data outside the EEA, Processor shall use appropriate safeguards required by Chapter V GDPR, such as Standard Contractual Clauses offered by the relevant provider.