Data Processing Agreement (DPA)
Last updated: May 22, 2026
This DPA governs how Komplian processes personal data on behalf of customers when we act as a data processor while providing the platform.
1. Scope and term
The DPA forms part of the service agreement and becomes effective when an account is contracted or activated. It remains in force during the contractual relationship and for any legally required retention period.
2. Roles of the parties
- Customer: data controller for the data it chooses to upload or process.
- Komplian: data processor acting under documented customer instructions.
3. Processing purpose
We process personal data to deliver product functionality, technical support, operational security, and service improvement within contractual and legal boundaries.
4. Security measures
We apply appropriate technical and organizational safeguards, including access controls, encryption in transit, secret protection, audit logging, and recurring security reviews.
5. Subprocessors
We may use subprocessors for infrastructure, storage, analytics, or other services required to operate the platform. We require contractual privacy and security obligations aligned with our commitments to customers.
6. Data subject rights and assistance
We assist customers, where applicable, with data subject rights requests and compliance obligations related to data protection laws.
7. Security incidents
If we identify a security incident affecting personal data processed for a customer, we provide notice without undue delay and share relevant information to support regulatory and operational response.
8. Retention, return, and deletion
At the end of the contract, we delete or return customer personal data according to contractual terms and applicable laws, unless legal retention obligations apply.
9. Signed DPA request
To request the full DPA or a signed copy, contact team@komplian.com and include your company details and workspace domain.