Data Processing Agreement (DPA)
Last updated: 1 أكتوبر 2026 — template executed with each subscriber together with the Subscription AgreementELHASSANE STUDIO ("Processor") and the subscribing party ("Controller") enter into this agreement to implement the data-protection obligations relating to the Platform, in addition to the Terms of Service. The governing law and jurisdiction are specified in the Master Service Agreement (MSA) signed between the Platform and the Customer, and apply to each commercial agreement between them. No legal obligation arises from this clause absent an executed MSA.
1. Roles
| Party | Role | Responsibility |
|---|---|---|
| Subscriber (Customer) | Controller | Determines the purpose of processing; primarily responsible for the lawfulness of data collection. |
| ELHASSANE STUDIO | Processor | Processes data on the Customer's behalf and solely to provide the services. |
2. Purpose of processing
Provision of Platform services only (project management, tasks, expenses, workers, documents, reports). No secondary use, no use to improve services for other customers, no cross-tenant analytics.
3. Categories of data
- Account data: name, email, job title, company name, phone.
- Business data: projects, tasks, expenses, worker rosters.
- Sensitive/special: workforce data (as defined in each country's law).
- Location data: GPS coordinates, field photos, drone reports.
- Invoices and billing records.
4. Security
TLS 1.3 in transit, AES-256 encryption at rest where feasible, full cross-company isolation (multi-tenant), role-based permissions, audit logs, encrypted backups. The Processor maintains these measures for the term of the agreement.
5. Transfers and sub-processors
No sale of data and no sharing with third parties without the Controller's written consent. Any sub-processor (hosting, email, analytics) is bound by a data-protection agreement no less protective than this one. Data is not transferred outside Morocco without prior notice.
6. Retention and deletion
Controller data is permanently deleted within 30 days of the end of the agreement or a deletion request, and backups are purged within the same period after purging safeguards.
7. Data breach
The Processor notifies the Controller within 72 hours of becoming aware of any suspected breach, provides initial details and a containment plan, and cooperates to support notifications to authorities and individuals as required by applicable law (PDPL / GDPR as applicable to each party).
8. Liability
Each party bears liability according to its role and the law governing its contract with the other party. The Processor is not liable for the Controller's commercial or legal decisions.
Name: ____________
Date: ____________
Signature: ____________
Name: ____________
Date: ____________
Signature: ____________
To request a signed PDF tailored to your needs: elhassane.opencode@gmail.com.
← Back to home