Last updated: 18 July 2026
Data Processing Agreements
A DPA must describe the real deployment, roles, instructions, subprocessors, locations, and commercial terms. This page is an informational outline; it is not an executed DPA and does not become binding merely because someone uses the software.
1. When a DPA applies
In a managed service, Techbunk Limited may process customer-provided data on the customer's documented instructions. In a self-hosted installation where Techbunk receives no customer data, the software vendor may have no processor role. Hybrid deployments must identify every data flow before the roles can be agreed.
2. Required schedule
- Controller and processor identities and authorised contacts.
- Subject matter, duration, purpose, data categories, and data subjects.
- Documented instructions and rules for deletion or return.
- Hosting region, backup locations, external AI providers, and other subprocessors.
- Approved transfer mechanisms where data leaves its protected jurisdiction.
- Incident notification, assistance, audit, liability, and termination terms.
3. Technical controls available
The application provides encrypted provider-credential storage, scoped platform API keys, role-based access, optional TOTP MFA, audit records, retention and erasure workflows, secure-cookie support, SSRF controls, and staging/production checks for HTTPS and database TLS.
The operator must still configure secrets, access policies, regional infrastructure, monitoring, email, external providers, and encrypted offsite backups. A signed DPA should list controls actually operating in that environment, not every capability present in the source code.
4. Subprocessors and changes
There is no universal subprocessor list for every Secuvon installation. The signed schedule must name the hosting, billing, email, monitoring, and AI providers used for that customer, including processing location and change-notice terms. Self-hosted operators maintain their own list.
5. Request an agreement
Use the contact form and include the deployment model, required region, categories of data, requested providers, and contracting entity. No response time, audit right, deletion certificate, or SLA is promised until it appears in a signed agreement.