Data Processing Agreement
For Hulby's B2B customers, I would have a separate DPA.
The basic structure should be:
Controller: Customer
Processor: Hulby
Hulby processes personal data only on the documented instructions of the customer where Hulby acts as processor.
The DPA should cover:
subject matter and duration;
nature and purpose of processing;
categories of personal data;
categories of data subjects;
confidentiality;
security measures;
subprocessors;
international transfers;
assistance with data subject requests;
data breach notification;
deletion/return of data;
audits;
subprocessor changes; and
liability.
You should specifically list your actual subprocessors, for example your hosting provider, database provider, AI providers, email provider and payment provider, rather than saying “third-party providers” generically.
