DPRQ
Language
Log inCreate DPP

HomeData Processing Agreement

Data Processing Agreement

B2B data processing terms for DPRQ customers.

Last updated: 2026-09-03

1. Parties and roles

This Data Processing Agreement ("DPA") forms part of the agreement between LUNELL PROFESSIONAL LIMITED ("Processor", "DPRQ") and the Customer entity using DPRQ ("Controller").

Where Customer enters personal data relating to its products, employees, contractors, or other data subjects into DPRQ, Customer is generally the controller and DPRQ acts as processor for that Customer Content.

Where DPRQ processes account, billing, or service data for its own purposes, DPRQ may act as controller as described in the Privacy Notice.

2. Subject matter and duration

Processor processes personal data to provide the DPRQ platform, including account management, product/passport workflows, document storage, validation, publication, billing support, and security monitoring.

Processing continues for the duration of the Customer's use of DPRQ and as otherwise required by law or backup retention.

3. Nature and purpose of processing

  • Storage, organisation, retrieval, and display of Customer Content
  • Validation and readiness assessment of product data
  • Publication of permitted passport fields to public URLs
  • Document and evidence management
  • User authentication and access control within Customer organisations
  • Support, incident response, and service improvement limited to security/reliability

4. Categories of data subjects and data

  • Customer personnel with DPRQ accounts
  • Economic operator and contact details entered into product/passport records
  • Any individuals whose personal data appears in uploaded documents or product fields
  • Billing contacts and payment metadata linked to the Customer account

5. Documented instructions

Processor shall process personal data only on documented instructions from Controller, including through Customer use of the platform features, these Terms, this DPA, and documented support requests, unless required by Union or Member State law.

6. Confidentiality

Processor ensures persons authorised to process personal data are bound by confidentiality obligations appropriate to the nature of the processing.

7. Security measures

Processor implements appropriate technical and organisational measures, including authentication, tenant isolation, row-level security, encryption in transit, provider-managed encryption at rest, and access controls as described on the Data Protection page.

8. Subprocessors

Controller authorises Processor to use subprocessors listed at /subprocessors. Processor will maintain an up-to-date list and provide a mechanism to notify material changes.

Current subprocessors include:

Supabase, Inc.: Authentication, PostgreSQL database, object storage, row-level security hosting

Vercel, Inc.: Application hosting and content delivery

Stripe, Inc.: Payment processing and subscription billing

Resend, Inc.: Transactional email delivery

9. Data subject requests

Processor shall assist Controller, taking into account the nature of processing, with applicable data subject requests under GDPR, to the extent such requests relate to Customer Content and Processor is able to assist using available platform tools or manual support.

10. Personal data breaches

Processor shall notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Content and provide information reasonably available to assist Controller in meeting its breach obligations.

11. DPIA and prior consultation

Processor shall provide reasonable assistance with data protection impact assessments and prior consultations where required, taking into account the nature of processing and information available to Processor.

12. Deletion and return

Upon termination of services, Processor shall delete or return Customer Content in accordance with documented instructions and the Data Retention policy, except where retention is required by law or permitted backups.

Automated account deletion workflows may require separate owner-approved implementation — see Account Deletion page.

13. Audits and information

Processor shall make available information necessary to demonstrate compliance with Article 28 GDPR and allow for audits mandated by law or agreed in writing, subject to reasonable notice, confidentiality, and frequency limits.

14. International transfers

Where subprocessors transfer personal data outside the EEA, Processor shall use appropriate safeguards required by Chapter V GDPR, such as Standard Contractual Clauses offered by the relevant provider.

Cookies and storage

DPRQ uses necessary cookies for secure login and consent storage. We use a preferences cookie to remember your language. We do not use analytics or marketing cookies. See our Cookie Policy and Privacy Notice.

Cookie Settings

Choose which optional storage categories you allow. Necessary cookies cannot be disabled.

Necessary
Preferences
Analytics

Not used by DPRQ.

Marketing

Not used by DPRQ.