1. Overview
This Data Processing Agreement (“DPA”) is entered into between ChromaParse (the “Processor”) and the enterprise customer (the “Controller”) to ensure compliance with GDPR, PIPL, and other applicable data protection laws.
This DPA supplements the Terms of Service and applies to enterprise customers, Team plan customers, and on-premise customers. If this DPA conflicts with the Terms, this DPA prevails.
2. Scope and purpose
The Processor processes the following personal data on the Controller’s instructions:
- Controller user account information (name, email, organization)
- Personal data potentially contained in PDF files uploaded by Controller users
- Usage logs of Controller users
Purpose: solely to provide ChromaParse services to the Controller, including PDF data extraction, user management, credit billing, and security monitoring.
Duration: ongoing during the contract term. After termination, data is deleted or returned per the Controller’s instruction, except where retention is legally required.
3. Processor obligations
- Process personal data only on the Controller’s written instructions
- Ensure personnel authorized to process personal data are committed to confidentiality
- Implement appropriate technical and organizational measures to ensure data security
- Assist the Controller in fulfilling its obligations under GDPR/PIPL, including data subject rights requests
- On contract termination, delete or return data per the Controller’s instructions
4. Security measures
Technical: TLS 1.3 in transit, AES-256 at rest, auto-deletion (7-day default), per-tenant key isolation, role-based access control (RBAC), audit logs for all data access, container-sandboxed processing workers, network segmentation, quarterly third-party penetration testing.
Organizational: employee data protection training, principle of least privilege, periodic security reviews, designated data protection responsible person.
5. Subprocessors
The Processor uses the following subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Aliyun | Server hosting and data storage | China (cn-shanghai) |
| AWS | International customer servers (optional) | Singapore (ap-southeast-1) |
| SendGrid | Email notifications | United States |
| Sentry | Error monitoring (excludes uploaded file content) | United States |
| WeChat Pay / Alipay | Paid transaction processing | China |
The Processor will give the Controller 30 days advance notice of replacement or addition of subprocessors, with a reasonable opportunity to object.
6. Cross-border data transfer
Where cross-border transfer is involved:
- Within China: complies with the Data Security Law and Personal Information Protection Law
- Cross-border: uses EU Standard Contractual Clauses (SCCs) or explicit Controller consent
7. Data subject rights
The Processor will assist the Controller in responding to data subject rights requests, including: access, rectification, deletion, restriction of processing, data portability, and objection to processing. Response timelines meet GDPR (30 days) and PIPL (15 business days).
8. Breach notification
In the event of a data breach:
- The Processor will notify the Controller within 24 hours of discovery
- Provide details of the nature of the incident, types of data involved, potential consequences, and measures taken
- Assist the Controller in notifying data subjects and supervisory authorities
9. Audit rights
The Controller has the right to:
- Conduct one written audit per year
- Conduct additional audits after material changes or security incidents
- Obtain the latest security certification reports (where applicable)
Audits require 30 days advance notice, occur during business hours, and must not unreasonably impact the Processor’s operations.
10. Termination and data deletion
After contract termination:
- The Controller may export all data within 30 days
- After 30 days, the Processor will permanently delete all customer data, except where retention is legally required
- After deletion, the Processor will provide written confirmation to the Controller
11. Governing law and disputes
This DPA is governed by the laws of the People’s Republic of China. Where EU data subjects are involved, GDPR applies. Disputes are resolved through friendly negotiation; failing that, by the court with jurisdiction.
12. Contact
DPA requests and execution: [email protected] Data Protection Officer (DPO): [email protected]
This DPA is a template. The version actually executed may be adjusted based on negotiation. Enterprise customers may request custom terms.