Let's chat
30-min free call
Sufyaan Studio
  • Home
  • Services
  • Pricing
  • About
  • Contact
  1. Data Processing Addendum

Legal

Data Processing Addendum

The data-processing terms that govern every Sufyaan Studio engagement, in compliance with GDPR Art. 28, the UK GDPR, India's DPDP Act, and the CCPA/CPRA. Incorporated by default into every proposal.

Effective: 2026-06-05Last updated: 2026-06-05Version: 1.0Read time: ~14 minutes

On this page

  1. Background and incorporation
  2. Definitions
  3. Subject matter, duration, nature, and purpose
  4. Processor obligations (GDPR Art. 28(3))
  5. Controller obligations
  6. Sub-processors
  7. International data transfers
  8. Technical and organisational measures (TOMs)
  9. Audit rights
  10. Data Subject rights
  11. Return and deletion of Personal Data
  12. Liability
  13. Order of precedence
  14. Signatures and acceptance
  15. Contact for data-protection matters
  16. Current sub-processor list

1. Background and incorporation

This Data Processing Addendum (the "DPA") forms part of, and is incorporated by reference into, the Terms of Service and any Engagement, proposal, or statement of work entered into between you ("Controller") and Sufyaan Studio ("Processor" or "the Studio"). It sets out the parties' respective obligations in respect of the Processing of Personal Data under the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the India Digital Personal Data Protection Act, 2023 ("DPDP"), the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), and any other applicable data-protection law (the "Data Protection Law").

In the event of any conflict between this DPA and the Terms, this DPA shall prevail with respect to the Processing of Personal Data.

2. Definitions

Capitalised terms not defined here have the meaning given in the GDPR. The following definitions apply:

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" has the meaning given in Article 4(2) GDPR, including any operation performed on Personal Data.
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
  • "Sub-processor" means any natural or legal person engaged by the Processor to Process Personal Data on behalf of the Controller.
  • "SCCs" means the Standard Contractual Clauses adopted by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, including the UK International Data Transfer Addendum where applicable.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.

3. Subject matter, duration, nature, and purpose

Subject matter: the Processing of Personal Data as required to deliver the Services described in the underlying Engagement.

Duration: the term of the Engagement plus a reasonable handover and deletion period not exceeding 90 days after termination, unless otherwise required by law.

Nature: the Studio typically Processes Personal Data in the following ways: (a) receiving and storing brief / contact form submissions, (b) hosting and operating websites and applications on behalf of the Controller, (c) providing analytics, SEO, and performance services, (d) maintaining communications, and (e) issuing and storing invoices.

Purpose: Processing is performed solely for the purposes set out in the Engagement and as further documented in this DPA. The Studio shall not Process Personal Data for any other purpose, including its own purposes, and shall not sell, rent, or trade Personal Data.

Categories of Data Subjects: typically include the Controller's end-users, prospects, customers, employees, contractors, and any other individuals whose Personal Data is contained in materials provided to the Studio in the course of the Engagement.

Categories of Personal Data: typically include identity and contact data (name, email, phone, address), professional data (role, company), technical data (IP address, device, browser, usage), and content provided by the Data Subject (form submissions, comments, files). Special categories of data (Art. 9 GDPR) are Processed only with the Controller's documented instruction and on a project-by-project basis.

4. Processor obligations (GDPR Art. 28(3))

The Studio shall:

  1. Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by Union or Member State law to which the Studio is subject.
  2. Ensure that persons authorised to Process Personal Data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Section 8 (TOMs).
  4. Engage Sub-processors only with the prior specific or general written authorisation of the Controller, and inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Controller the opportunity to object.
  5. Taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights (Chapter III GDPR).
  6. Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, DPIA, prior consultation), taking into account the nature of the Processing and the information available to the Studio.
  7. At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services relating to Processing, and delete existing copies unless Union or Member State law requires storage.
  8. Make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
  9. Notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach, providing the Controller with sufficient information to allow the Controller to meet its obligations under Articles 33 and 34 GDPR.

5. Controller obligations

The Controller warrants and undertakes that:

  • It has a valid legal basis under Article 6 GDPR (and Article 9 where special-category data is involved) for the Processing instructions it issues to the Studio.
  • It has provided all required privacy notices to Data Subjects and obtained any necessary consents.
  • The Personal Data provided to the Studio has been collected lawfully, fairly, and in a transparent manner.
  • Its instructions to the Studio comply with applicable Data Protection Law.

6. Sub-processors

The Controller provides a general authorisation for the Studio to engage the Sub-processors listed below. The Studio will notify the Controller in writing at least 30 days in advance of any intended addition or replacement of a Sub-processor, and the Controller may object on reasonable grounds related to data protection. The current Sub-processor list is also maintained and published at #sub-processor-list on this page.

The Studio enters into a written contract with each Sub-processor that imposes data-protection terms no less protective than those set out in this DPA. The Studio remains fully liable to the Controller for the performance of the Sub-processor's obligations.

7. International data transfers

Where Personal Data is transferred outside the European Economic Area, the United Kingdom, or India to a country not covered by an adequacy decision, the parties shall rely on the EU Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, or other lawful safeguards, and the Studio shall conduct a transfer impact assessment.

The Module Two (Controller-to-Processor) clauses apply to transfers from a Controller in the EEA to the Studio as Processor. The Module Three (Processor-to-Processor) clauses apply to onward transfers from the Studio to its Sub-processors.

For transfers from the UK, the UK Addendum to the SCCs applies. For transfers from India, the parties shall rely on any cross-border transfer rules issued by the Central Government under Section 16 of the DPDP Act and the contractual safeguards above.

8. Technical and organisational measures (TOMs)

The Studio maintains the following TOMs, which are reviewed and updated at least annually:

Confidentiality

  • All personnel with access to client data are bound by written confidentiality obligations.
  • Two-factor authentication is mandatory on every production system.
  • Access to client source code is scoped per engagement and revoked within 24 hours of off-boarding.

Integrity and availability

  • Daily off-site encrypted backups with 30-day retention; quarterly restore drills.
  • 99.9% uptime target on production workloads (Vercel Enterprise-grade infrastructure).
  • Version control on every artefact, with cryptographic signing on release tags.

Resilience and recovery

  • Documented incident response plan with 24/7 on-call for retainer clients.
  • Recovery Time Objective (RTO) of 4 hours; Recovery Point Objective (RPO) of 24 hours.
  • Annual disaster-recovery exercise with written post-mortem shared with affected clients.

Access control

  • Principle of least privilege; role-based access control (RBAC) on every platform.
  • Quarterly access reviews and immediate revocation on personnel change.
  • Audit logs retained for 30 days minimum, with alerting on anomalous activity.

Encryption

  • TLS 1.3 in transit; AES-256 at rest for all client data stores.
  • Scoped API keys with rotation every 90 days for production systems.
  • End-to-end encryption for any project that requires it (e.g. PII-heavy SaaS).

Sub-processor management

  • Sub-processors are assessed for security and GDPR compliance before onboarding.
  • All sub-processors are bound by DPAs aligned with this Addendum.
  • Material sub-processor changes are notified to clients at least 30 days in advance.

Privacy by design

  • Data minimisation by default; only the data needed for the purpose is collected.
  • Privacy impact assessments (PIAs) performed for high-risk processing.
  • Default-deny firewall rules; least-privilege IAM policies from day one.

Regular testing and audit

  • Annual third-party penetration test on all client-facing production workloads.
  • Internal vulnerability scans weekly; dependency scanning on every commit.
  • SOC 2 Type II readiness maintained; on request, audit reports shared under NDA.

9. Audit rights

The Controller may audit the Studio's compliance with this DPA no more than once per calendar year, on at least 30 days' prior written notice, during normal business hours, and in a manner that does not unreasonably interfere with the Studio's operations. The Studio may satisfy audit requests by providing a current SOC 2 Type II report, ISO 27001 certification, or equivalent independent third-party assessment. The Controller shall bear its own audit costs unless the audit reveals material non-compliance, in which case the Studio shall reimburse reasonable audit costs.

10. Data Subject rights

The Studio shall, taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests for exercising Data Subject rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection, automated decision-making). If the Studio receives a request directly from a Data Subject relating to the Controller's Personal Data, the Studio shall forward the request to the Controller without undue delay and shall not respond directly.

11. Return and deletion of Personal Data

On termination of the Engagement, the Studio shall, at the Controller's written choice, return all Personal Data to the Controller or delete it, and delete any existing copies, unless Union, Member State, UK, Indian, or other applicable law requires storage. The Studio will confirm deletion in writing within 30 days. A reasonable extension may be agreed in writing for ongoing warranty, audit, or legal-hold purposes, not exceeding 12 months in total.

12. Liability

The parties' liability under this DPA is subject to the limitation of liability set out in the Terms, except that the parties' aggregate liability for fines issued by a competent supervisory authority and payable by either party shall be determined in accordance with the GDPR and any applicable local law. Nothing in this clause limits either party's liability for damages incurred by a Data Subject under Article 82 GDPR.

13. Order of precedence

In the event of any conflict between this DPA, the Terms, and any executed proposal, the following order of precedence applies with respect to the Processing of Personal Data: (1) the executed proposal or statement of work, (2) this DPA, and (3) the Terms of Service. For matters not addressed in this DPA, the SCCs (where applicable) and the Terms shall apply.

14. Signatures and acceptance

This DPA is deemed accepted by both parties upon execution of an Engagement that incorporates it by reference, and may be countersigned (in counterpart or via electronic signature) at the Controller's request. Standard signature blocks:

Controller

_______________________________

Name, title, company, date

Processor

Sufyaan

Lead Full-Stack Engineer & Founder, Sufyaan Studio

15. Contact for data-protection matters

For any data-protection question, request, or notification under this DPA, contact:

Sufyaan Studio — Data Protection
Email: dev.sufyaan@gmail.com
Subject line: "Data protection"

Current sub-processor list

The Studio engages the following Sub-processors as of the Last updated date. We will notify the Controller in writing at least 30 days before adding or replacing any Sub-processor.

Sub-processorPurposeRegionSafeguards
Vercel Inc.Website hosting, edge functions, analytics, SSL/TLS termination.United States, Ireland (edge PoPs worldwide).EU SCCs (Decision 2021/914); DPA in place.
Cloudflare, Inc.DNS, CDN, DDoS protection, WAF.Global edge network; data centres in EU, US, APAC.EU SCCs; GDPR-compliant DPA.
FormSubmit Co.Serverless email delivery for website form submissions.United States.Privacy Shield successor; SCCs on request.
Cal.com Inc.Scheduling and calendar bookings for free consultations.United States / Germany (self-host available).GDPR-compliant DPA; data minimisation.
Google LLCGoogle Analytics 4, Google Search Console, Google Workspace.Worldwide; GA4 with IP anonymisation enabled.EU SCCs; DPA in place; GA4 retention 14 months.
WhatsApp (Meta Platforms, Inc.)Conversational messaging with prospective and active clients.Worldwide; messages routed through Meta infrastructure.Meta DPA; data minimisation; no marketing pixels.
Stripe, Inc.Payment processing for invoices and retainers.United States / Europe (Stripe Payments Europe Ltd).EU SCCs; PCI-DSS Level 1 certified.
Wise (TransferWise Ltd)Cross-border payouts to the Studio and select client refunds.United Kingdom, Europe, US.FCA-regulated; GDPR-compliant.
GitHub, Inc.Source-code repositories, issue tracking, CI/CD.United States (with EU data residency add-on for Enterprise).EU SCCs; DPA in place.
Resend, Inc.Transactional email (project updates, invoices, deliverable notifications).United States.EU SCCs; GDPR-aware.

Need a signed, countersigned DPA for procurement?

We sign mutual NDAs and countersigned DPAs on request. Allow 2 business days for a custom DPA; the standard form above is accepted as-is by most procurement teams.

Book a Free Call

30-minute free call · no pitch · no obligation

Ready to start your next project?

Custom web development, software engineering and Shopify services for ambitious brands worldwide. Direct access, fixed milestones, no ghosting.

Sufyaan Studio

Global custom web development, software engineering and Shopify agency. Solo-led since 2020. 40+ shipped projects, 5 continents.

Services

  • Custom Web Development
  • Shopify Development
  • Custom Software
  • SaaS Development
  • SEO & GEO
  • Brand & UI/UX
  • Performance Optimization
  • Maintenance & Support

Industries

  • E-Commerce & DTC
  • SaaS & B2B Software
  • Healthcare & Wellness
  • FinTech
  • Real Estate & PropTech
  • Hospitality
  • Professional Services
  • Education & EdTech

Locations

  • United States
  • United Kingdom
  • United Arab Emirates
  • India
  • Australia
  • Canada
  • Singapore
  • Europe

Company

  • About
  • Our Process
  • Pricing
  • Selected Work
  • Blog
  • FAQ
  • Directory
  • Contact

Resources

  • GEO Guide
  • How to Rank in ChatGPT
  • Shopify SEO Checklist
  • SaaS MVP Guide
  • Headless Shopify Guide
  • Web Dev Cost Guide

Legal

  • Privacy Policy
  • Terms of Service
  • Imprint
  • Data Processing Addendum

Contact

dev.sufyaan@gmail.com+91 93184 41197WhatsApp us

Hours

Mon–Fri, 9:00 AM – 6:00 PM ISTSat, 10:00 AM – 2:00 PM ISTSun — Closed

Status

Accepting Q2 2026 projects
Limited spots. We work with a small number of clients at a time.

© 2026 Sufyaan Studio. All rights reserved.

PrivacyTermsImprintDPADirectoryllms.txt