Data Processing Agreement
Last updated: 2026-07-07
Draft status: This DPA is a working draft prepared for review by counsel. Executed copies (including client-specific Annexes) are countersigned as part of the SOW — request one at legal@theunnamed.dev.
This Data Processing Agreement ("DPA") forms part of the agreement between The Unnamed Corp ("Unnamed", the "Processor") and the client identified in the applicable Statement of Work ("Client", the "Controller") and applies whenever Unnamed processes personal data on the Client's behalf in the course of providing the Services. It is written to satisfy Article 28(3) GDPR and equivalent requirements under UK GDPR, Canadian privacy law (PIPEDA), and US state privacy laws (CCPA/CPRA "service provider" terms).
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in the GDPR. "Services" means the services described in the applicable SOW. "Subprocessor" means a processor engaged by Unnamed to process Client personal data.
2. Subject matter, duration, nature, and purpose
Unnamed processes personal data solely to deliver the Services described in the applicable SOW (development, hosting, operation, support, and maintenance of software), for the duration of that SOW plus any wind-down period required for return or deletion under Section 11. The nature of processing includes collection, storage, structuring, retrieval, use, and erasure as required by the Services.
3. Types of personal data and categories of data subjects
The specific data types and data subject categories are set out in Annex I of the executed DPA for each engagement. Typically: identification and contact data (names, email addresses), account and usage data of the Client's end users, and any additional categories specified in the SOW. Data subjects typically include the Client's employees, customers, and end users. Unnamed does not require special-category data to provide the Services; if an engagement involves it, Annex I must say so explicitly.
4. Documented instructions
Unnamed will process Client personal data only on the Client's documented instructions — including with regard to transfers to third countries — as set out in this DPA, the SOW, and the Client's written instructions from time to time, unless required to process otherwise by EU or Member State law or other law applicable to Unnamed (including Canadian federal or provincial law), in which case Unnamed will inform the Client of that legal requirement before processing unless the law prohibits it. Unnamed will inform the Client immediately if, in its opinion, an instruction infringes applicable data protection law. Unnamed does not sell Client personal data, does not retain, use, or disclose it for any purpose other than providing the Services, and does not combine it with data from other sources, as those terms are defined under the CCPA/CPRA.
5. Confidentiality
Unnamed ensures that all persons authorized to process Client personal data (employees and contractors) are bound by written confidentiality obligations and process the data only as needed to deliver the Services.
6. Security (Article 32)
Unnamed implements and maintains the technical and organisational measures described in Annex II — which incorporates the practices published on our Security page: AES-256 encryption at rest, TLS 1.2+ in transit, tenant isolation, MFA-enforced access control, least-privilege IAM, immutable audit logging, and tested backups — taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing.
7. Subprocessors
The Client grants general written authorisation for Unnamed to engage the subprocessors listed on the Security page (currently AWS, Stripe, Amazon Cognito, Google, PostHog, Sentry). Unnamed will notify the Client at least 30 days before adding or replacing a subprocessor; the Client may object on reasonable data-protection grounds within that period, in which case the parties will work in good faith toward a resolution, and if none is found the Client may terminate the affected Services. Unnamed imposes data protection obligations on each subprocessor no less protective than this DPA and remains fully liable to the Client for each subprocessor's performance.
8. Assistance with data subject rights and GDPR obligations
Taking into account the nature of processing, Unnamed will assist the Client with appropriate technical and organisational measures, insofar as possible, in responding to data subject requests under Articles 15–22 (access, rectification, erasure, restriction, portability, objection). If a data subject contacts Unnamed directly, we will forward the request to the Client without undue delay and will not respond except as instructed. Unnamed will also assist the Client, insofar as information is available to it, with the Client's obligations under Articles 32–36 (security, breach notification, data protection impact assessments, and prior consultation).
9. Personal data breach notification
Unnamed will notify the Client without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client personal data, providing the information reasonably required under Article 33(3) as it becomes available, and will cooperate with the Client's remediation and notification obligations.
10. Audits
Unnamed will make available to the Client all information necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by the Client or an auditor mandated by the Client, on reasonable notice, no more than once per year absent a breach or regulator requirement, during business hours, and subject to confidentiality. Available security documentation (see Security) will be provided first to reduce audit scope.
11. Return and deletion
Upon termination or expiry of the Services, at the Client's choice, Unnamed will return all Client personal data (in a commonly used, machine-readable format) or delete it, and delete existing copies within 90 days, unless EU, Member State, or other applicable law requires continued storage. On request, Unnamed will certify deletion in writing.
12. International transfers
Client personal data is hosted on AWS in the United States (us-east-1). Where the Client transfers personal data subject to the GDPR or UK GDPR to Unnamed, the parties incorporate the European Commission's 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller-to-processor), into the executed DPA — with Annexes I–III completed per the engagement — together with the UK International Data Transfer Addendum where applicable. Onward transfers to subprocessors are covered by each subprocessor's own SCC-backed transfer terms.
13. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service or the applicable master agreement, except where applicable data protection law does not permit such limitation. If this DPA conflicts with the Terms of Service or an SOW, this DPA prevails with respect to the processing of personal data.
14. Term
This DPA takes effect on execution of the applicable SOW and remains in force as long as Unnamed processes Client personal data.
Annexes (completed per engagement in the executed copy)
- Annex I — Description of processing: subject matter, duration, nature and purpose, types of personal data, categories of data subjects, and documented instructions for the specific engagement.
- Annex II — Technical and organisational measures: the controls published on the Security page, plus any engagement-specific measures.
- Annex III — Authorised subprocessors: the list maintained on the Security page as of the execution date.
To execute this DPA for your engagement, email legal@theunnamed.dev with the subject "DPA Request" — we respond within 5 business days.