PassuraStart free

Legal

Data processing agreement

The Article 28 terms under which we process personal data on your behalf. Included on every paid plan, at no extra cost and without a negotiation.

Last updated 21 August 2026 · Processor: PENDING — confirm before launch
Draft — pending legal review

This document is a working draft published for transparency while Passura is in closed beta. It has not been reviewed by a qualified lawyer, it is not an executed agreement, and it does not yet bind either party. If you need a signed version to complete a procurement review, contact us and we will send the executed document.

Outstanding before this is binding
  • This draft must be reviewed and executed by a qualified lawyer before it is offered as the operative Article 28 agreement. Do not send this version to a customer’s legal team as final.
  • Attach the Standard Contractual Clauses, and decide whether they are needed given that several sub-processors are US-established even though data stays in the EU.
  • Complete a transfer impact assessment covering Cloudflare’s TLS termination on the authentication path.
  • Confirm the breach-notification window against what can actually be met operationally, rather than copying a number from another vendor’s DPA.
  • Confirm the audit and inspection rights clause is proportionate for a service of this size.
  • Confirm the deletion and return timelines against the retention behaviour implemented in the product.

1. Roles of the parties

For personal data belonging to your end users, you are the controller and PENDING — confirm before launch is the processor. We process that data only on your documented instructions, of which your configuration of the service and your use of the API form part.

2. Subject matter and duration

Subject matter: provision of authentication services. Duration: the term of your agreement with us, plus the wind-down period in clause 8. Nature and purpose: authenticating end users, maintaining sessions, and recording security events.

Categories of data subject: your end users, and your own team members with console access. Categories of personal data: email address, display name, password hash, MFA secrets, IP address, user agent, and authentication event records. No special-category data is processed.

3. Security measures

We maintain technical and organisational measures appropriate to the risk, described in detail at passura.dev/security. These include Argon2id password hashing, refresh-token rotation with reuse detection, encryption in transit and at rest, per-tenant data isolation, and rate limiting.

4. Sub-processors

You give general authorisation for the sub-processors listed at passura.dev/sub-processors. We give 30 days’ written notice by email to every account’s registered address before a new sub-processor begins processing customer data. If you object within that window, you may terminate the affected service without penalty for the remainder of the current term.

We impose data protection obligations on each sub-processor no less protective than those in this agreement, and we remain liable to you for their performance.

5. International transfers

Customer and end-user data is stored and processed in the EU, on OVHcloud infrastructure in Gravelines, France.

Some sub-processors are established in third countries even where the data they handle remains in the EU. The applicable safeguards, and whether Standard Contractual Clauses are required for each, are pending legal review — see the outstanding items at the top of this page. This clause will not be represented as settled until that review is complete.

6. Assistance to the controller

We assist you in responding to data subject requests, and in meeting your obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to us.

7. Personal data breaches

We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations. The specific notification window is pending legal and operational review.

8. Return and deletion

On termination you may retrieve your data through the API. After the wind-down period we delete the personal data we process on your behalf, except where retention is required by law. The specific timelines are pending review against the behaviour implemented in the product.

9. Audits

We make available the information necessary to demonstrate compliance with Article 28 and allow for audits, subject to reasonable notice and confidentiality. The precise scope is pending legal review.

10. Getting a signed copy

Once this document completes legal review, a signed copy will be available on request and included with every paid plan. If you need one for a procurement review now, contact PENDING — confirm before launch and we will tell you honestly where the document stands.