Legal
Data Processing Agreement.
For business and integration partners.
1. Scope
This DPA forms part of any agreement between Sharzhukov's Laboratory ("Processor") and a business partner ("Controller") that processes EU/EEA personal data. It complies with Art. 28 GDPR.
2. Processing Activities
The Processor processes personal data only on documented instructions from the Controller, for the purposes of the main agreement, in accordance with applicable data protection law.
3. Security Measures
TLS/HTTPS encryption, bcrypt password hashing, regular updates, access controls, audit logs, and incident response procedures.
4. Sub-processors
Authorised sub-processors:
• Aeza (hosting, EU)
• Cloudflare (CDN, DDoS protection)
• Resend (email delivery, EU region — Ireland)
• Aeza (hosting, EU)
• Cloudflare (CDN, DDoS protection)
• Resend (email delivery, EU region — Ireland)
5. Data Subject Rights
The Processor assists the Controller in responding to data subject requests within statutory timeframes.
6. Breach Notification
The Processor notifies the Controller within 48 hours of becoming aware of any personal data breach affecting the Controller's data.
7. Term
This DPA is effective for the duration of the main agreement. To sign a DPA with us, contact [email protected].