TorqueX.ai torqueX.ai
// LEGAL · DPA FOR ENTERPRISE CUSTOMERS

Data Processing Addendum

For Enterprise customers. Most won't sign your generic terms — they want their own DPA or yours-with-their-mods. Here's the baseline so sales can move.

DPA v1.0 · 2026-06 · 184 KB · PDF

Standard TorqueX DPA

Includes SCCs for EU→US transfers, UK addendum, sub-processor list, and security exhibit. Customer-papered DPAs reviewed on standard SLA.

// WHAT THE DPA COVERS
01

Definitions

Controller, Processor, Personal Data, Subprocessor — matching GDPR Article 4.

02

Scope and duration

Duration of MSA, plus retention obligations that survive termination.

03

Processing instructions

What we process, for whom, for what purpose, and the categories of data and data subjects.

04

Subprocessor list

Mirrors the Privacy Policy §3 table. 30 days notice before any addition, with right to object.

05

International transfers

SCCs included as Annex, UK addendum, and India transfer conditions where applicable.

06

Security measures

Cross-references the Trust Centre at /legal/security and the Technical and Organisational Measures annex.

07

Breach notification

Notice to Customer within 72 hours of awareness, with what the notice will include.

08

Audits

Annual SOC 2 report shared under NDA, plus on-site audit on reasonable notice with cost-recovery for engineering time.

09

Data-subject requests

Forwarded to Customer within 5 business days; Customer remains the controller.

10

Return / deletion

Aligned with Privacy §5 timeline; certificate of destruction available on request.

11

Liability

Mirrors the limits in the Master Services Agreement.

12

Annexes

Subprocessors list, SCCs, Technical and Organisational Measures, and Customer affiliates.

// Negotiated DPAs available on request via enterprise@torquex.ai. Customer-papered DPAs reviewed within 5 business days.