Data Processing Agreement (DPA)
Last updated: June 2026
1. Scope and Purpose
This Data Processing Agreement outlines the conditions under which Octiven processes Personal Data on behalf of its enterprise clients. This agreement ensures compliance with global privacy regulations including GDPR, CCPA, and HIPAA where applicable.
2. Security Measures
Octiven commits to implementing and maintaining robust technical and organizational security measures designed to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. This includes end-to-end encryption (AES-256), strict access controls, and regular external penetration testing.
3. Sub-processing
We may engage third-party sub-processors (such as AWS, Google Cloud, or Cloudflare) strictly to provide necessary infrastructure. All sub-processors are vetted for rigorous security compliance and are bound by data processing agreements at least as restrictive as this one.
4. Data Breach Notification
In the highly unlikely event of a verified data breach, Octiven will notify affected clients without undue delay (and in any event within 24 hours of becoming aware of the breach), providing all necessary information to assist clients in meeting their own regulatory reporting obligations.
5. Audits and Inspections
Clients retain the right to conduct audits, including inspections, of our data processing facilities and documentation to ensure compliance with this agreement, provided such audits are scheduled with reasonable advance notice and do not disrupt core engineering operations.
