Legal

Data Processing Agreement.

For business and integration partners.

1. Scope

This DPA forms part of any agreement between Sharzhukov's Laboratory ("Processor") and a business partner ("Controller") that processes EU/EEA personal data. It complies with Art. 28 GDPR.

2. Processing Activities

The Processor processes personal data only on documented instructions from the Controller, for the purposes of the main agreement, in accordance with applicable data protection law.

3. Security Measures

TLS/HTTPS encryption, bcrypt password hashing, regular updates, access controls, audit logs, and incident response procedures.

4. Sub-processors

Authorised sub-processors:

• Aeza (hosting, EU)
• Cloudflare (CDN, DDoS protection)
• Resend (email delivery, EU region — Ireland)

5. Data Subject Rights

The Processor assists the Controller in responding to data subject requests within statutory timeframes.

6. Breach Notification

The Processor notifies the Controller within 48 hours of becoming aware of any personal data breach affecting the Controller's data.

7. Term

This DPA is effective for the duration of the main agreement. To sign a DPA with us, contact [email protected].