Data Processing Agreement (outline)
Status: Draft outline for Art. 28 GDPR discussions. Not a signed DPA. Counsel must issue the executable agreement for each customer.
Roles
| Role | Party |
|---|---|
| Controller | Customer (tenant organisation) |
| Processor | Beneke Consulting / Evitrus (see Company) |
Subject matter
Processing of Evidence Events and related tenant identity/organisation data that the Customer pushes to or creates in the Evitrus managed cloud, for the purpose of change correlation, incident investigation, and compliance evidence.
Categories of data
- Engineering evidence (deploy/config/IAM-style events, digests, commit SHAs, service names, optional actor displays)
- Account data (user emails, names, roles, API key metadata)
- Organisation audit log (admin actions)
Customers control what exporters send. Evitrus does not require end-user PII beyond account emails for login.
Location
The managed cloud is hosted in the European Union for Evidence Events, identity data, organisation audit logs, and transactional email (see Subprocessors). See also the Security whitepaper and Security & residency.
Retention
Plan-based retention (free: 14 days; paid: 730 days by default). See Organisation → Usage and Scale & SLOs.
Subprocessors
Listed at Subprocessors. Material changes are notified as agreed in the executable DPA.
Security measures
Summarised in the Security whitepaper. Technical measures include TLS, tenant isolation, RBAC, an append-only evidence store, and provider-managed encryption at rest.
Customer rights / assistance
Export of Evidence Events: Data portability. Deletion and account closure are handled via the organisation admin and operator support.