Home/Data Processing Agreement
>_LEGAL · DATA PROCESSING AGREEMENT

Our processor commitments under GDPR.

This DPA template summarizes the data processing obligations TuniReach accepts as a processor of your customer data. Enterprise customers sign a countersigned version in their Master Service Agreement.

In force · last updated 2026-04-22
SECTIONS
5
on this page
OTHER POLICIES
4
cross-linked
LAST UPDATED
Apr 22
2026
CONTACT
open any time
01

Roles

You are the controller of personal data you process through the service. We act as a processor and process personal data only on your documented instructions.

02

Subprocessors

We maintain a public list of subprocessors and notify customers 30 days before adding a new one. You may object in good faith within that window.

03

Security measures

Encryption in transit and at rest, strict access control, audit logging, security monitoring, incident response, and annual penetration testing.

04

Sub processing of special categories

We do not intentionally process special categories of personal data. If your use case requires it, contact us for a dedicated agreement.

05

Breach notification

We will notify the controller without undue delay and within 72 hours of becoming aware of a personal data breach that affects its data.

Questions about this policy? Email contact@tunireach.com.