Data Processing Agreement (DPA)

Last updated: June 2026

1. Scope and Purpose

This Data Processing Agreement outlines the conditions under which Octiven processes Personal Data on behalf of its enterprise clients. This agreement ensures compliance with global privacy regulations including GDPR, CCPA, and HIPAA where applicable.

2. Security Measures

Octiven commits to implementing and maintaining robust technical and organizational security measures designed to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. This includes end-to-end encryption (AES-256), strict access controls, and regular external penetration testing.

3. Sub-processing

We may engage third-party sub-processors (such as AWS, Google Cloud, or Cloudflare) strictly to provide necessary infrastructure. All sub-processors are vetted for rigorous security compliance and are bound by data processing agreements at least as restrictive as this one.

4. Data Breach Notification

In the highly unlikely event of a verified data breach, Octiven will notify affected clients without undue delay (and in any event within 24 hours of becoming aware of the breach), providing all necessary information to assist clients in meeting their own regulatory reporting obligations.

5. Audits and Inspections

Clients retain the right to conduct audits, including inspections, of our data processing facilities and documentation to ensure compliance with this agreement, provided such audits are scheduled with reasonable advance notice and do not disrupt core engineering operations.