Data Processing Agreement

For Hulby's B2B customers, I would have a separate DPA.

The basic structure should be:

Controller: Customer
Processor: Hulby

Hulby processes personal data only on the documented instructions of the customer where Hulby acts as processor.

The DPA should cover:

subject matter and duration;

nature and purpose of processing;

categories of personal data;

categories of data subjects;

confidentiality;

security measures;

subprocessors;

international transfers;

assistance with data subject requests;

data breach notification;

deletion/return of data;

audits;

subprocessor changes; and

liability.

You should specifically list your actual subprocessors, for example your hosting provider, database provider, AI providers, email provider and payment provider, rather than saying “third-party providers” generically.