Data Processing Addendum
Effective 2026-05-28
This DPA forms part of the Terms of Service between Customer (controller) and Enginara (processor) and reflects the parties' agreement with regard to the processing of personal data under the EU/UK GDPR.
1. Definitions
Capitalised terms not defined here have the meaning given in the GDPR or the Terms of Service. "Customer Data" means personal data that Customer transmits to or stores within the Service.
2. Roles
Customer is the controller of Customer Data. Enginara is the processor and acts only on documented instructions from Customer, except where required by law.
3. Processing details
| Subject matter | Engineering metadata ingestion and report generation |
|---|---|
| Duration | Term of the Services Agreement plus retention windows in the Privacy Policy |
| Categories of data | Employee identifiers (name, email, username), activity metadata |
| Categories of data subjects | Customer's engineering staff and connected source-tool users |
| Purpose | Producing engineering intelligence reports and dashboards |
4. Sub-processors
Customer authorises the sub-processors listed at enginara.app/legal/sub-processors. We will give 30 days' notice of any addition or replacement; Customer may object on reasonable grounds, in which case the parties will work in good faith to find an alternative.
5. Security
We implement and maintain the technical and organisational measures described at enginara.app/legal/security, including encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, audit logging, and incident response.
6. Personal data breach
We will notify Customer without undue delay (and within 72 hours where feasible) of any confirmed personal data breach affecting Customer Data, including the categories of data affected, likely consequences, and mitigation measures taken.
7. Data subject requests
We will assist Customer in responding to data subject requests (access, rectification, erasure, portability, objection, restriction) via the in-app data export and deletion tools, and via support ticket where in-app tools are insufficient.
8. International transfers
Where Customer Data is transferred outside the EEA/UK, the parties agree that the Standard Contractual Clauses (Module Two, 2021/914) and the UK International Data Transfer Addendum apply and are incorporated by reference.
9. Audits
Customer may request, no more than once per year, a copy of our most recent security audit report (e.g. SOC 2 Type II when available) and our completed CAIQ. On-site audits may be requested with 30 days' notice and are subject to reasonable confidentiality and security controls.
10. Return and deletion
On termination, we will return or delete Customer Data within 90 days, subject to backup retention cycles and any legal-hold obligations. Certification of deletion is available on written request.
11. Conflict
In the event of conflict between this DPA and the Terms of Service or any signed Master Services Agreement, this DPA prevails with respect to personal-data processing.
12. Contact
DPA inquiries: dpa@enginara.app.

