Legal
Data processing agreement
The Article 28 terms under which we process personal data on your behalf. Included on every paid plan, at no extra cost and without a negotiation.
This document is a working draft published for transparency while Passura is in closed beta. It has not been reviewed by a qualified lawyer, it is not an executed agreement, and it does not yet bind either party. If you need a signed version to complete a procurement review, contact us and we will send the executed document.
- This draft must be reviewed and executed by a qualified lawyer before it is offered as the operative Article 28 agreement. Do not send this version to a customer’s legal team as final.
- Attach the Standard Contractual Clauses, and decide whether they are needed given that several sub-processors are US-established even though data stays in the EU.
- Complete a transfer impact assessment covering Cloudflare’s TLS termination on the authentication path.
- Confirm the breach-notification window against what can actually be met operationally, rather than copying a number from another vendor’s DPA.
- Confirm the audit and inspection rights clause is proportionate for a service of this size.
- Confirm the deletion and return timelines against the retention behaviour implemented in the product.
1. Roles of the parties
For personal data belonging to your end users, you are the controller and PENDING — confirm before launch is the processor. We process that data only on your documented instructions, of which your configuration of the service and your use of the API form part.
2. Subject matter and duration
Subject matter: provision of authentication services. Duration: the term of your agreement with us, plus the wind-down period in clause 8. Nature and purpose: authenticating end users, maintaining sessions, and recording security events.
Categories of data subject: your end users, and your own team members with console access. Categories of personal data: email address, display name, password hash, MFA secrets, IP address, user agent, and authentication event records. No special-category data is processed.
3. Security measures
We maintain technical and organisational measures appropriate to the risk, described in detail at passura.dev/security. These include Argon2id password hashing, refresh-token rotation with reuse detection, encryption in transit and at rest, per-tenant data isolation, and rate limiting.
4. Sub-processors
You give general authorisation for the sub-processors listed at passura.dev/sub-processors. We give 30 days’ written notice by email to every account’s registered address before a new sub-processor begins processing customer data. If you object within that window, you may terminate the affected service without penalty for the remainder of the current term.
We impose data protection obligations on each sub-processor no less protective than those in this agreement, and we remain liable to you for their performance.
5. International transfers
Customer and end-user data is stored and processed in the EU, on OVHcloud infrastructure in Gravelines, France.
Some sub-processors are established in third countries even where the data they handle remains in the EU. The applicable safeguards, and whether Standard Contractual Clauses are required for each, are pending legal review — see the outstanding items at the top of this page. This clause will not be represented as settled until that review is complete.
6. Assistance to the controller
We assist you in responding to data subject requests, and in meeting your obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to us.
7. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations. The specific notification window is pending legal and operational review.
8. Return and deletion
On termination you may retrieve your data through the API. After the wind-down period we delete the personal data we process on your behalf, except where retention is required by law. The specific timelines are pending review against the behaviour implemented in the product.
9. Audits
We make available the information necessary to demonstrate compliance with Article 28 and allow for audits, subject to reasonable notice and confidentiality. The precise scope is pending legal review.
10. Getting a signed copy
Once this document completes legal review, a signed copy will be available on request and included with every paid plan. If you need one for a procurement review now, contact PENDING — confirm before launch and we will tell you honestly where the document stands.