[topcounter]

Data Processing Agreement (GDPR-Compliant)

Effective Date: November 03, 2025

Contact: support@theadvocacycircle.com

Purpose and Scope

This Data Processing Agreement (‘DPA’) forms part of the service agreement between The Advocacy Circle (‘Processor’) and the customer (‘Controller’) and outlines compliance with the EU General Data Protection Regulation (GDPR).

Subject Matter and Duration

TAC processes personal data solely for the purpose of providing subscribed services. This DPA remains in effect for the duration of the service agreement.

Nature and Purpose of Processing

Processing may include collection, storage, access, and analysis of user-submitted data such as educational or limited health information for service delivery and support.

Type of Personal Data

Data may include names, contact details, education records, user-generated documents, and communications.

Obligations of the Processor

TAC agrees to: (1) process data only on documented instructions; (2) implement appropriate technical and organizational measures; (3) ensure confidentiality of personnel; (4) assist the Controller in complying with GDPR obligations; (5) delete or return personal data upon request or end of contract.

Sub-Processors

TAC may engage sub-processors to support the delivery of services. All sub-processors are subject to data protection obligations equal to those in this agreement. A current list is available upon request.

International Data Transfers

If personal data is transferred outside the EEA, TAC will implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.

Data Subject Rights

TAC shall promptly notify the Controller of any data subject requests and assist in fulfilling rights to access, rectification, restriction, objection, or deletion.

Security Measure

TAC maintains physical, administrative, and technical safeguards, including encryption, access control, and monitoring, to protect personal data

Breach Notification

TAC will notify the Controller without undue delay upon becoming aware of a personal data breach.

Audit Rights

The Controller may conduct audits (or engage a third party) to ensure compliance, subject to reasonable scheduling and confidentiality obligations.

Termination

Upon termination of services, TAC will delete or return personal data unless retention is required by law.