Agreement for Data Processing (DPA)
Threada im standard Data Processing Agreement wey cover GDPR, CCPA, and other data protection obligation wey apply.
Scope and where e dey apply
Dis DPA dey apply to all processing of personal data wey Threada dey do on behalf of di customer for di Threada platform. E dey add to di Terms of Service and e dey govern data handling, security measure, and breach notification procedure.
Role dem and responsibility
Di customer dey act as di data controller. Threada dey act as data processor, e dey process personal data only as di customer instruct and as e necessary take deliver di service.
Technical and organisational measure dem
- Encryption when data dey move and when e dey rest through managed provider encryption (GCP, MongoDB Atlas), with field-level encryption for sensitive field dem
- Data isolation wey dem scope to tenant — no cross-tenant access at all
- Role-based access control dem with audit logging
- Automated dependency and advisory vulnerability scanning, plus threat model wey dem dey maintain
- Incident response procedure dem with breach notification without undue delay (di exact timeline na inside di DPA wey dem don execute dem dey agree am)
Subprocessor dem
Threada dey keep current list of subprocessor. Dem dey notify customer dem for material change. See di subprocessor page for di full list.
Right dem of data subject
Threada dey support customer dem to answer data subject request for access, correction, deletion, and portability, through platform tool and operational process.
How we dey keep and delete data
Data retention policy dem na configurable per workspace. When contract terminate, dem go delete customer data within 90 days unless law demand say make dem keep am longer.