This document is a proposed draft, not an effective agreement or a statement of verified practices. It does not replace Darwin’s existing Terms, Privacy Policy, or a signed agreement. Legal and operational review is required before publication as an effective policy.
This proposed Data Processing Agreement describes terms for personal data Darwin Technologies, Inc. processes on a customer’s behalf. It requires legal review, completed processing schedules, and agreement by the parties before it can take effect. It does not appoint Darwin to a particular legal role or replace an existing signed agreement.
1. Scope and roles
The parties should identify the services, applicable data protection laws, and their roles for each processing activity. Where the customer determines the purposes and means of processing and Darwin acts on its behalf, the customer acts as controller and Darwin as processor. Different roles may apply to account administration, fraud prevention, or other independently determined activities.
Darwin’s Privacy Policy separately describes its existing privacy practices.
2. Customer instructions
Proposed term: Darwin will process covered personal data only on the customer’s documented lawful instructions, including instructions in the signed agreement and configured service, except where law requires otherwise. If an instruction appears to violate applicable data protection law, Darwin will inform the customer and pause the affected processing while the parties resolve it.
The customer is responsible for its lawful basis, notices, permissions, and authority to provide personal data, including data provided through an agent or integration. An agent’s instructions do not expand the customer’s legal authority.
3. Confidentiality and security
Proposed term: personnel authorized to process covered data will be bound by confidentiality obligations. Darwin will maintain technical and organizational measures appropriate to the agreed processing and risk. The parties must document verified measures in Schedule 2 rather than rely on an unsupported certification or general security claim.
4. Subprocessors
Proposed term: Darwin may engage subprocessors under the authorization mechanism selected in the signed agreement. It will maintain the agreed subprocessor information, impose appropriate contractual data protection obligations, and remain responsible for their performance of the delegated processing duties. The notification period, objection procedure, and remedy for unresolved objections must be agreed before this document takes effect.
5. Assistance and individual rights
Proposed term: taking into account the nature of processing and information available, Darwin will provide reasonable assistance with requests from individuals, impact assessments, and consultations required by applicable law. Requests received directly concerning customer-controlled data will be referred to the customer unless law requires a direct response. The parties should agree on request channels and costs.
6. Personal data breaches
Proposed term: Darwin will notify the customer without undue delay after becoming aware of a personal data breach affecting covered data, provide available information needed to assess the incident, and cooperate on mitigation. Information may be provided in stages as an investigation proceeds. Notification contacts and any additional deadline must be documented in the signed agreement.
7. International transfers
The parties must identify processing locations and determine whether a restricted international transfer occurs. Where a transfer safeguard is required, the applicable mechanism, modules, annexes, and any supplementary measures must be completed before the transfer. This draft alone does not execute Standard Contractual Clauses or establish that any transfer mechanism is applicable.
8. Return and deletion
Proposed term: at the end of the covered services, Darwin will return or delete covered data according to the customer’s documented choice, unless retention is legally required. The final schedule must specify export arrangements, deletion timing, backup handling, and any legally required retention, with continued protections while retained data remains in scope.
9. Accountability and review
Proposed term: Darwin will make information reasonably necessary to demonstrate compliance available and support audits required by applicable law, subject to agreed safeguards for confidentiality, security, and other customers. The parties must agree on process and scope without restricting mandatory legal rights.
10. Relationship to the services agreement
The final agreement must identify the contracting parties, effective date, governing services agreement, and order of precedence. Liability and remedies require legal review alongside that agreement. Nothing in this draft modifies the currently effective Terms and conditions.
Schedule 1. Processing details
- Customer identity, contact details, and controller or processor roles.
- Services, purposes, nature, frequency, and duration of processing.
- Categories of individuals and personal data, including any sensitive data.
- Processing locations, authorized recipients, and approved subprocessors.
- Retention, export, deletion, and applicable transfer safeguards.
Schedule 2. Security measures
Complete with verified controls for access, confidentiality, transmission and storage, resilience, recovery, testing, incident response, and deletion. This schedule is not yet completed and makes no claim of certification or audit status.
Contact legal@darwin.so to discuss an executable agreement.