Data Processing Agreement (GDPR-Compliant)
- Home
- Data Processing Agreement (GDPR-Compliant)
Effective Date: November 03, 2025
Contact: support@theadvocacycircle.com
Purpose and Scope
This Data Processing Agreement (‘DPA’) forms part of the service agreement between The Advocacy Circle (‘Processor’) and the customer (‘Controller’) and outlines compliance with the EU General Data Protection Regulation (GDPR).
Subject Matter and Duration
TAC processes personal data solely for the purpose of providing subscribed services. This DPA remains in effect for the duration of the service agreement.
Nature and Purpose of Processing
Processing may include collection, storage, access, and analysis of user-submitted data such as educational or limited health information for service delivery and support.
Type of Personal Data
Data may include names, contact details, education records, user-generated documents, and communications.
Obligations of the Processor
TAC agrees to: (1) process data only on documented instructions; (2) implement appropriate technical and organizational measures; (3) ensure confidentiality of personnel; (4) assist the Controller in complying with GDPR obligations; (5) delete or return personal data upon request or end of contract.
Sub-Processors
TAC may engage sub-processors to support the delivery of services. All sub-processors are subject to data protection obligations equal to those in this agreement. A current list is available upon request.
International Data Transfers
If personal data is transferred outside the EEA, TAC will implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
Data Subject Rights
TAC shall promptly notify the Controller of any data subject requests and assist in fulfilling rights to access, rectification, restriction, objection, or deletion.
Security Measure
TAC maintains physical, administrative, and technical safeguards, including encryption, access control, and monitoring, to protect personal data
Breach Notification
TAC will notify the Controller without undue delay upon becoming aware of a personal data breach.
Audit Rights
The Controller may conduct audits (or engage a third party) to ensure compliance, subject to reasonable scheduling and confidentiality obligations.
Termination
Upon termination of services, TAC will delete or return personal data unless retention is required by law.