Data Processing Agreement
Version 1.0 · 9 August 2026
This is our standard template and has not yet been reviewed by external counsel. We would rather say so than imply a legal review that has not happened. The factual parts — what data we hold, where, and who processes it — were checked against the running system and are accurate. The legal drafting is ours. If your compliance team needs counsel-reviewed wording before you sign, tell us and we will have it reviewed rather than ask you to accept this as-is.
This agreement applies where you use GovAlert AI to monitor a register of companies you act for. It supplements our privacy policy, which describes the same processing in plainer terms.
1. Parties and roles
You are the controller. You decide which companies go into the register, why, and what you write in the notes field.
We are the processor. GovAlert AI, operating from Nicosia, Cyprus, processes that data only to provide the monitoring service described below.
2. Subject matter, duration, nature and purpose
Subject matter and purpose: comparing publicly published Cyprus government notices against your register, and alerting you when a notice concerns one of your companies.
Nature of the processing: storage, automated normalisation of company names, automated comparison against published text, generation of summaries and deadline records, and delivery of alerts to you by email and in the web application.
Duration: for as long as your account is open, plus the deletion period in clause 9.
3. Types of personal data and categories of data subject
Most of what you give us is company data, which is not personal data at all. Personal data arises in three ways, and we would rather name them than pretend the register is purely corporate:
- Company names that contain a person's name. Common in Cyprus — a company called after its founder identifies that individual.
- Anything you type into the free-text notes field. We do not inspect or restrict it, so its contents are entirely within your control.
- Your own users' account details — the email address used to sign in, the firm name, and an optional phone number.
Categories of data subject: your personnel who use the account, and any individuals identifiable from the register entries or notes you upload.
No special-category data is required by the service. The product has no field that asks for it. If you place such data in the notes field you do so on your own instruction and remain responsible for having a lawful basis to do so.
4. Our obligations (Article 28(3))
(a) Documented instructions
We process the personal data only on your documented instructions, which for these purposes are this agreement and your use of the product. If we were ever required by law to process it otherwise, we would tell you first unless that law forbids it.
(b) Confidentiality
Everyone we authorise to access the data is bound to keep it confidential. In practice today that is a very short list, and we will not pretend otherwise: GovAlert AI is a small operation and access is limited to its operator.
(c) Security (Article 32)
The measures actually in place:
- data held in the EU (AWS eu-west-1, Ireland) via Supabase;
- row-level security enabled on every table in the database, so a query cannot return another account's rows even if application code is wrong;
- encryption in transit (TLS) to the application, the database and every sub-processor;
- authentication and session handling operated by Supabase Auth;
- a separate, restricted database role for background jobs.
What we do not claim: we hold no ISO 27001 or SOC 2 certification, we have not commissioned a penetration test, and we have not appointed a Data Protection Officer. If any of those is a requirement for you, we do not currently meet it.
(d) Sub-processors
You give general authorisation for the sub-processors listed in clause 5. We will give you notice before adding or replacing one, so you have the opportunity to object. Each is bound by data protection terms no less protective than these, and we remain fully liable to you for their performance.
(e) Assisting with data subject rights
Taking into account the nature of the processing, we will help you respond to requests from data subjects to access, correct, delete, restrict, port or object. In practice: tell us what you need and we will retrieve or remove it.
(f) Assisting with Articles 32–36
We will help you meet your own obligations on security, breach notification, data protection impact assessments and prior consultation, given the information available to us.
(g) Deletion or return
See clause 9.
(h) Information and audits
We will make available the information needed to demonstrate compliance with this clause and will allow and contribute to audits or inspections you or an auditor you appoint conduct, on reasonable notice and no more than once a year unless a regulator requires otherwise.
5. Authorised sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and authentication | AWS eu-west-1, Ireland (EU) |
| Vercel | Web application hosting | United States, with EU edge delivery |
| Anthropic | Summarising public publications; the optional in-product assistant | United States |
| Outbound email delivery (SMTP) | United States / global | |
| Stripe | Payment and subscription processing | United States / Ireland |
We do not use Twilio and send no WhatsApp messages, notwithstanding the unused settings field in the application.
6. What actually leaves the EU database
Stated precisely, because a generic sub-processor list overstates exposure:
- Monitoring and matching involve no transfer. Your register is compared against downloaded publications inside the EU database. No client name is sent to any third party to perform monitoring.
- Summarisation sends no customer data. What goes to Anthropic is the government publication, which is already public.
- The assistant does transfer your data, on your action. When one of your users sends a message to the in-product assistant, we transmit that user's firm name, their alerts and deadlines, and up to 30 client names to Anthropic in the United States, to generate the reply. The feature is optional and the rest of the product functions without it.
- Alert emailspass through Google's SMTP service, and therefore contain the recipient address and the alert content.
7. International transfers
Transfers to sub-processors outside the EEA are made under the European Commission's Standard Contractual Clauses, as incorporated in those providers' own data processing terms. We have not carried out an independent transfer impact assessment; if you require one for your own records, tell us and we will co-operate.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available at the time and updates as we learn more. That is the Article 28(3)(f) and Article 33(2) standard, and it is the commitment we can actually keep.
How we would become aware, stated honestly. An earlier draft of this agreement promised notification within 48 hours of a breach. We removed that figure, because a fixed clock is only meaningful if there is something that reliably starts it, and we would rather hold a promise we can keep than a stricter one we cannot. What exists today:
- Sub-processor notification. Supabase, Vercel and Stripe are each obliged to notify us of a breach affecting data they hold, and that is the most likely route by which we would learn of one.
- Automated liveness monitoring. An independent watchdog checks hourly that the monitoring jobs are running and alerts us to crashes and stalls. It is designed to catch a job that has stopped — it is not intrusion detection.
- What we do not have. No 24/7 security monitoring, no automated intrusion or anomaly detection, no continuous audit log review, and no on-call rota. A breach originating with us, rather than with a sub-processor, might not be detected quickly.
One fixed commitment we can hold: where a sub-processor notifies us of a breach affecting your data, we will pass that on to you within 24 hours of receiving it. That clock starts on something we actually receive, so it is keepable.
If your own obligations require a guaranteed detection window, tell us before you sign. We would rather agree what it would take than have you rely on a clause we cannot honour.
9. Deletion or return on termination
On termination of your account, or on your written request at any time, we will at your choice delete or return your personal data and delete existing copies, unless we are required by law to keep it.
- We will complete deletion within 30 days of your request or of termination.
- Deletion covers your account, your client register, the matches derived from it, your deadlines and your delivery history.
- It does not cover the government publications themselves, which are public records and contain no data of yours.
- Backups are removed on their ordinary rotation. Until that completes, restored data remains subject to this agreement.
- Return is currently a manual process. There is no self-serve export yet; ask us and we will produce your data in a structured, machine-readable format.
10. Liability and governing law
This agreement is governed by the laws of the Republic of Cyprus, and the courts of Cyprus have jurisdiction. Where it conflicts with any other agreement between us on the subject of data protection, this one prevails.
11. Accepting this agreement
If you would like a counter-signed copy, or amendments your own counsel requires, email dropshipingonline81@gmail.com. We would rather negotiate the wording than have you accept a template you have not read.