This template applies when reform processes customer personal data on behalf of a business customer that acts as controller or business.
1. Parties and role split
Customer role. The customer determines the purposes and means of the customer data it submits to reform and acts as the controller or business for that data.
Provider role. Stefano Pompei, located at Carrer Beat Nicolas Factor 11, 46007 Valencia, ES provides reform and acts as processor or service provider only for customer data processed on the customer’s documented instructions under this DPA and the main services agreement.
Formal notices about this DPA should be sent to legal@paqu.io.
Provider tax identifier. Y7554839C.
2. Scope and processing details
This DPA covers customer-submitted workspace content, records, files, audit trails, and account-administration data processed for business-to-business service delivery.
The high-level privacy notice remains available at Privacy Notice. Processing details for Annex A should be completed from the customer’s use of the service and the applicable order form.
Subject matter. Provision of the reform product and related support services.
Duration. For the term of the services agreement plus any limited post-termination return or deletion period described below.
Nature of processing. Hosting, storage, organization, retrieval, transmission, support, security monitoring, and deletion or return of customer data.
Categories of data subjects. Customer personnel, customer end users, and any other individuals whose personal data the customer chooses to submit through the service.
Categories of personal data. Account identifiers, workspace metadata, record content, uploaded files, communication metadata, and other categories determined by the customer’s configuration and use.
3. Customer instructions and compliance
Documented instructions only. reform will process customer data only on documented instructions from the customer, including the customer’s configuration and ordinary use of the service, unless applicable law requires otherwise.
Instruction review. If a requested instruction appears to violate applicable data-protection law, reform may suspend the instruction until the customer confirms or modifies it.
Confidentiality. Personnel with access to customer data must be bound by confidentiality obligations and limited to those with a need to know.
4. Security measures
reform maintains technical and organizational measures appropriate to the risk. A current public-facing summary is supported by the internal controls inventory and the subprocessors disclosure.
Access controls. Role-based access, scoped service permissions, credential management, and restricted administrative access.
Encryption. Encryption in transit, encryption at rest through infrastructure providers, and protected storage paths for uploaded assets and exports.
Logging and monitoring. Security-relevant audit trails, backend monitoring, and incident-response procedures.
The current public subprocessor inventory is published at Subprocessors.
Authorization model. The customer authorizes the subprocessors listed in the public inventory and any later replacements or additions disclosed through the same channel.
Flow-down terms. reform will impose written data-protection obligations on subprocessors that are no less protective than the obligations applicable to reform under this DPA for the relevant processing.
Objection process. A customer with reasonable data-protection concerns about a new subprocessor may contact the provider notice contact and the parties will work in good faith on a commercially reasonable solution.
6. Assistance and cooperation
Rights requests. reform will provide reasonable assistance so the customer can respond to access, deletion, correction, restriction, portability, or objection requests concerning customer data.
Security incidents. reform will notify the customer without undue delay after confirming a security incident affecting customer data and will provide information reasonably needed for containment, impact assessment, and customer notifications.
Security and privacy contact. Questions about privacy review, security review, or incident handling can be sent to support@paqu.io.
DPIAs and regulator inquiries. reform will provide reasonable information about the service and the relevant processing to support data-protection impact assessments, transfer assessments, or regulator inquiries related to the service.
7. Return and deletion
Customer-directed export. During the active service term, the customer may export available customer data using the product, support, or other agreed service-delivery mechanisms.
Deletion after termination. After service termination and any short operational wind-down needed for export, reform will delete or return customer data unless applicable law requires continued retention.
Limited retained copies. Backup or security-retained copies may persist for limited periods until overwritten or expired under the provider’s retention controls, but will remain protected and isolated from active use.
8. International transfers
reform intends to keep core service data within European-region deployments where those options are available. If reform or a subprocessor nevertheless transfers customer personal data outside the customer’s permitted region, the parties will rely on an appropriate transfer mechanism, such as the European Commission Standard Contractual Clauses or a UK addendum, where required.
The specific transfer appendix should be completed with Stefano Pompei and the relevant subprocessor or affiliate details before production use where cross-border transfers require it.
9. Audit and information rights
For self-serve SaaS v1, the default audit model is documentation-first rather than unrestricted onsite inspection.
Baseline materials. reform will make available reasonable security and compliance information, such as policy summaries, control descriptions, or third-party evidence where available and appropriate.
Follow-up questions. Customers may submit reasonable written follow-up questions related to the service’s data-protection controls.
Escalated review. If a material, regulator-driven, or contractually required concern remains unresolved, the parties may discuss a narrower supplemental review subject to confidentiality, scope limits, and protection of other customers and system security.
No sale or sharing. reform will not sell or share customer personal information as those terms are used in the CPRA when acting as a service provider or contractor for the customer.
Limited business purpose use. reform will retain, use, or disclose customer personal information only for the business purposes and service-provider purposes permitted by the services agreement, this DPA, and applicable law.
No unrelated combination. reform will not combine customer personal information with personal information received from other sources except as permitted for a service provider or contractor under applicable law.
Subcontractor restrictions. Subprocessors handling CPRA-covered information must be bound by equivalent written restrictions.
Annex A. Processing details to complete
Provider legal name. Stefano Pompei
Provider address. Carrer Beat Nicolas Factor 11, 46007 Valencia, ES
Governing law and venue. Spanish law governs. Valencia, ES is the agreed B2B venue where enforceable. Consumers retain mandatory habitual-residence law and competent courts.
Customer description. Insert the customer legal name, service plan, tenant or workspace context, and a short description of the intended processing.