This Data Processing Agreement ("DPA") supplements our Terms of Service and applies where we process personal data on your behalf in the course of providing the Services, and where data protection laws such as the EU/UK GDPR apply. If you require a signed copy, contact [email protected].
1. Parties and roles
Where you use Prapl to process personal data of your own users, customers or staff, you are the data controller and Hyperledger IT Pvt Ltd is the data processor. Each party will comply with its obligations under applicable data protection law.
2. Subject matter and scope
We process personal data only to provide the Services and on your documented instructions (including as set out in the Terms and product configuration). The subject matter, duration, nature and purpose of processing, and the types of personal data and categories of data subjects, are determined by your use of the Services. Given our local-first design, for many tools personal data remains on your systems and is not disclosed to us.
3. Our obligations as processor
- Process personal data only on your documented instructions, unless required by law.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures.
- Assist you, taking into account the nature of processing, with data subject requests and with your security, breach-notification and impact-assessment obligations.
4. Your obligations as controller
You are responsible for the lawfulness of the data you process using the Services, for having a valid legal basis and any required notices or consents, and for the accuracy of your instructions.
5. Sub-processors
You authorise us to engage sub-processors (such as hosting, payment and support providers) to help deliver the Services. We impose data-protection obligations on them no less protective than this DPA, and we remain responsible for their performance. We will inform you of changes to material sub-processors and give you a chance to object on reasonable data-protection grounds.
6. Security measures
We maintain measures appropriate to the risk, including encryption in transit, access controls, least-privilege, logging, and regular review. See our Security page for more.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your notification obligations.
8. Data subject rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under applicable law.
9. International transfers
Where processing involves transferring personal data out of the EEA or UK, we rely on a lawful transfer mechanism such as the Standard Contractual Clauses, which are incorporated into this DPA by reference where applicable.
10. Return and deletion of data
On termination of the Services, and at your choice, we will delete or return the personal data we process on your behalf, and delete existing copies unless law requires storage. For local-first tools, this data typically already resides only on your systems.
11. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice, confidentiality, and limits to protect other customers' data and our security.
12. Contact us
For DPA requests or a signed copy, email [email protected].