Data Processing Agreement

    Template version 1.0. Last updated: May 21, 2026.

    This Data Processing Agreement ("DPA") is the template offered by Ibrave Software Engineering ("Processor", "we", "our") to any client ("Controller") whose engagement with us involves the processing of personal data on the Controller's behalf. The DPA is entered into as part of, and forms an integral attachment to, the Master Services Agreement (MSA) or Statement of Work (SOW) signed between the parties.

    This template is designed to satisfy the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR. To execute a DPA, contact us at hello@ibrave.co with your entity details, and we will provide a counter-signed copy scoped to your engagement.

    1. Definitions

    Capitalised terms used but not defined in this DPA have the meanings given to them in the applicable Data Protection Law. For the purposes of this DPA:

    • Data Protection Law means the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the UK GDPR as defined in section 3 of the Data Protection Act 2018, and any other applicable law concerning the processing of personal data.
    • Personal Data, Processing, Controller, Processor, Data Subject, and Supervisory Authority have the meanings given in the GDPR.
    • Sub-processor means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
    • SCCs means the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries, adopted by Implementing Decision (EU) 2021/914 of 4 June 2021.
    • UK IDTA means the United Kingdom International Data Transfer Addendum to the EU Commission SCCs, issued under section 119A of the Data Protection Act 2018.

    2. Scope and roles

    The Controller appoints the Processor to process Personal Data on its behalf in connection with the services described in the MSA or SOW. With respect to that processing, the Controller is the Controller and the Processor is the Processor.

    3. Subject matter, nature, purpose, and duration

    The subject matter, nature, purpose, duration, categories of Personal Data, and categories of Data Subjects are set out in Schedule 1.

    4. Processor obligations

    The Processor will:

    1. Process Personal Data only on the documented instructions of the Controller, including with regard to transfers, unless required to do otherwise by applicable law (in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest).
    2. Ensure that personnel authorised to process Personal Data are bound by a duty of confidentiality.
    3. Implement the technical and organisational measures set out in Schedule 4 to ensure a level of security appropriate to the risk, in line with Article 32 GDPR.
    4. Engage Sub-processors only in accordance with Section 5 below.
    5. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests for exercising Data Subject rights (Articles 12 to 23 GDPR).
    6. Assist the Controller in ensuring compliance with the Controller's obligations under Articles 32 to 36 GDPR (security of processing, breach notification, Data Protection Impact Assessments, and prior consultation with Supervisory Authorities), taking into account the nature of the processing and the information available to the Processor.
    7. At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies, unless applicable law requires storage of the Personal Data.
    8. Make available to the Controller all information necessary to demonstrate compliance with this DPA and Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable notice and confidentiality undertakings.

    5. Sub-processors

    The Controller grants the Processor general authorisation to engage the Sub-processors listed in Schedule 2. The Processor will notify the Controller of any intended addition or replacement of Sub-processors at least fourteen (14) days in advance, thereby giving the Controller the opportunity to object on reasonable grounds. The Processor will impose, by contract, data protection obligations on each Sub-processor that are no less protective than those set out in this DPA.

    6. International transfers

    Where the Processor or a Sub-processor processes Personal Data outside the European Economic Area (EEA) or the United Kingdom, the parties will rely on an appropriate transfer mechanism under Chapter V GDPR. Where required, the SCCs (Module Two: Controller-to-Processor) are incorporated into this DPA by reference and apply to such transfers. Transfers to or from the United Kingdom are additionally governed by the UK IDTA. A summary of transfer destinations is given in Schedule 3.

    7. Security

    The Processor will maintain the technical and organisational measures described in Schedule 4. These measures are reviewed periodically and updated to reflect changes in risk, technology, and applicable guidance.

    8. Personal data breach

    The Processor will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting the Controller's Personal Data. The notification will include, to the extent known at the time, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.

    9. Liability

    Each party's liability arising out of or in connection with this DPA is governed by the liability and indemnification provisions of the MSA, except that nothing in those provisions limits or excludes either party's liability for a breach of this DPA where applicable law does not permit such limitation, including without limitation Article 82 GDPR.

    10. Term and termination

    This DPA takes effect on the date the MSA or SOW is signed by both parties and remains in force for the term of the MSA or SOW. The Processor's obligations under Sections 4(g) and 4(h) survive termination.

    11. Order of precedence

    In the event of any conflict between this DPA and the MSA or SOW with respect to the processing of Personal Data, this DPA prevails. The SCCs and the UK IDTA, where they apply, prevail over conflicting terms in this DPA.

    12. Governing law

    This DPA is governed by the law specified in the MSA. Disputes are subject to the jurisdiction specified in the MSA.

    Schedule 1. Processing details

    • Subject matter and duration: as set out in the MSA or SOW, for the term of the engagement.
    • Nature and purpose of processing: performance of the services described in the MSA or SOW, including development, testing, deployment, support, and operation of software systems on behalf of the Controller.
    • Categories of Personal Data: identification data (names, email addresses, telephone numbers), professional data (job titles, employer), authentication credentials where applicable, and any further categories of Personal Data the Controller chooses to process through the services. Special categories of Personal Data (Article 9 GDPR) are not processed unless expressly agreed in the MSA or SOW.
    • Categories of Data Subjects: the Controller's end users, customers, employees, contractors, and any other individuals whose Personal Data is processed through the services.

    Schedule 2. Sub-processors

    The current list of authorised Sub-processors used to deliver our services is:

    • Vercel Inc. (United States): website and API hosting, request routing, edge functions.
    • Resend, Inc. (United States): transactional email delivery for contact-form submissions and notifications.
    • Supabase, Inc. (United States / EU regions): database, authentication, and storage where used by the engagement.

    Engagement-specific Sub-processors (for example a cloud provider or analytics tool requested by the Controller) are listed in the relevant SOW. The Processor will keep this Schedule up-to-date and notify the Controller of changes as set out in Section 5.

    Schedule 3. International transfers

    The Processor operates from a single office in Addis Ababa, Ethiopia. Sub-processors listed in Schedule 2 are established in the United States and may store or process Personal Data in the United States, the European Union, or other jurisdictions depending on the region selected for the engagement.

    For transfers from the EEA, the SCCs (Module Two) apply. For transfers from the United Kingdom, the UK IDTA applies. For transfers to or processing in jurisdictions that benefit from an EU adequacy decision, the adequacy decision applies and the SCCs are not required.

    Schedule 4. Technical and organisational measures

    The Processor maintains the following measures, reviewed and updated as the engagement evolves:

    • Transport encryption: all data transmitted between systems is encrypted using HTTPS / TLS.
    • Access controls: role-based access control applied on the principle of least privilege; access reviewed periodically and revoked on personnel changes.
    • Authentication: multi-factor authentication required for administrative access to systems holding Personal Data.
    • Audit logging: system and application logs recording security-relevant events, retained for a period proportionate to the risk.
    • Managed cloud infrastructure: services hosted with established cloud providers that maintain industry certifications appropriate to the workload.
    • Software supply chain: dependency scanning and timely application of security updates.
    • Confidentiality: all personnel with access to Personal Data are bound by written confidentiality obligations.
    • Incident response: documented procedure for detection, containment, remediation, and notification of security incidents.

    To execute this DPA against your engagement, email hello@ibrave.co with your entity name, registered address, and the relevant MSA or SOW reference. We will return a counter-signed copy and a completed Schedule 2 scoped to your engagement.