Data Processing Agreement (DPA)
Data Processing Agreement (GDPR Art. 28)
Effective Date: September 2026
This Data Processing Agreement ("DPA") governs the processing of personal data by DIGITAL GLOBAL TECHNOLOGIES LTD (UIC: 204471845, Address: Lyuben Karavelov str. 2, 3 floor, office 5, Plovdiv, 4000, Plovdiv, Bulgaria, Founder Code3 Creative: Julia Goncharova, email: hello@code3-creative.com) ("Processor" or "Company") on behalf of the customer ("Controller" or "Client") pursuant to Regulation (EU) 2016/679 (General Data Protection Regulation - "GDPR").
1. Scope and Applicability
This DPA applies to all processing of Personal Data conducted by Processor in connection with the provision of software engineering, cloud infrastructure, AI automation, and digital agency services outlined in the Master Services Agreement.
2. Processor Obligations
Documented Instructions: Processor shall process Personal Data exclusively on documented instructions from Controller, including with regard to transfers of personal data to a third country or international organization.
Confidentiality: Processor ensures that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Security of Processing (Art. 32): Processor implements state-of-the-art technical and organizational security measures, including end-to-end encryption at rest (AES-256) and in transit (TLS 1.3), automated vulnerability scanning, and strict role-based access control (RBAC).
3. Sub-processors
Controller grants general authorization to Processor to engage vetted sub-processors (cloud hosting providers, database clusters, secure transactional email relays). Processor imposes equivalent data protection obligations on any sub-processor and remains fully liable to Controller for sub-processor performance.
4. Data Subject Rights Assistance
Taking into account the nature of the processing, Processor assists Controller by appropriate technical and organizational measures to fulfill Controller's obligations to respond to requests exercising data subject rights under Chapter III GDPR.
5. Incident Management & Breach Notification
In the event of a confirmed Personal Data Breach, Processor shall notify Controller without undue delay and no later than 48 hours after becoming aware of the breach, providing comprehensive information to assist Controller in meeting regulatory notification obligations.
6. Deletion and Return of Data
Upon termination of services, Processor shall, at the choice of Controller, securely delete or return all Personal Data and delete existing copies unless applicable European Union or Member State law requires storage of the personal data.
7. Audits and Compliance
Processor shall make available to Controller all information necessary to demonstrate compliance with GDPR Article 28 and allow for and contribute to reasonable audits conducted by Controller or an independent auditor.
8. Legal Requisites & Contact
Processor: DIGITAL GLOBAL TECHNOLOGIES LTD
Founder Code3 Creative: Julia Goncharova
UIC (EIK): 204471845
Address: Lyuben Karavelov str. 2, 3 floor, office 5, Plovdiv, 4000, Plovdiv, Bulgaria
Email: hello@code3-creative.com